Online discussions continue to swirl around Ledger’s new firmware update for its crypto hardware wallet, which experts have claimed could put users’ private keys at risk.
Ledger published a Twitter thread on Wednesday attempting to alleviate concerns around the safety of users’ assets, but published a self-contradictory and confusing tweet that stoked the flames of controversy even further.
Ledger’s Worrying Tweet
In a now-deleted tweet, Ledger support verified criticisms from Wednesday exposing a troublesome reality of using their product: the manufacturer could, technically, release firmware that extracts users’ private keys from their wallets.
“You have always trusted Ledger not to deploy such firmware whether you knew it or not,” wrote the company.
Ledger’s Deleted Tweet. 05/17/23
This contradicts a claim from the company’s main account last November, in which Ledger claimed that user private keys cannot be extracted from a wallet’s secure element chip through a firmware update.
At the time, Ledger and other wallet manufacturers were recording record sales in the aftermath of FTX’s collapse, as crypto investors sought the security of self-custody and cold storage for their crypto assets.
On Thursday, Ledger said that it decided to delete its Wednesday tweet due to its “confusing wording.” However, Ledger’s CTO Charles Guillemet published a follow-up thread explaining that wallets, in general, have “many ways” to implement a backdoor, and that some level of trust is required with any third-party wallet purchase.
22/ If you want to be completely trustless, you’ll have to learn electronics to build your computer, learn ASM to build your compiler, then build a wallet stack, your own node and synchronizer, you’ll have to learn cryptography to build your own signature stack.
— Charles Guillemet (@P3b7_) May 18, 2023
“Open source doesn’t really solve this,” he added. “It’s impossible to have guarantees that the electronic itself is not backdoored, nor that the firmware that runs inside the wallet is the one you audited.”
Ledger Recover
Criticism around Ledger swelled on Wednesday after the company announced its new hardware wallet service “Ledger Recover.” With user permission, the service breaks a wallet’s private keys into three shards, encrypts them, and stores them with three separate centralized providers – one of which is Ledger.
The subscription service requires users to provide personal identifying information before using it. In return, users are granted a method of recovering their private keys in case they lose both their hardware device and seed phrase paper backup.
The crypto community blasted the service and its associated firmware update for adding a code path that can send private keys to third parties. Many experts including developer and auditor “foobar” recommended that followers stop using the company’s devices.
If you have a ledger, your keys are not compromised (yet). But if you upgrade to the latest firmware, it’ll stick in a code path that can send your private key to third parties. Given ledger doxxed their own customers in the past, it’s unlikely that they’ll keep this info safe
— foobar (@0xfoobar) May 16, 2023
The post Ledger Responds to Customer Fears On Wallet Safety, But Deletes “Confusing” Tweet appeared first on CryptoPotato.
CRV – the native token of the DeFi exchange Curve Finance – has plunged over 12% following the recent exploit on several stable pools of the project. However, the token’s price took a somewhat interesting trajectory on the leading South Korean cryptocurrency exchanges Bithumb and CoinOne, currently trading at a 510% and a 220% premium,…
Donald Trump’s crypto project, World Liberty Financial (WLF), has submitted a proposal to the Aave governance forum. The former president and his business partners plan to use the platform for their cryptocurrency offering. The submission aims to establish WLF’s services as an instance on Aave, with the protocol providing the necessary underlying infrastructure. In return
Vitalik Buterin, the co-founder of the second-largest blockchain, Ethereum, had his X account hacked to portray a phishing site that reportedly drained over $800,000. The fraudulent post has been deleted since, and the account has been restored. The blockchain security resource PeckShield was among the first to alert about the ongoing hack later last night
[PRESS RELEASE – Halifax, Canada, January 14th, 2025] Koii Network ($KOII), following a successful mainnet launch and multiple oversubscribed launchpad sales, begins trading on Gate.io and MEXC, bringing the World’s Biggest Supercomputer to the global market. With over 100,000 active nodes, Koii Network plays a significant role in decentralized infrastructure, efficiently processing 185.1 terabytes of
The legal battle between Ripple and the United States Securities and Exchange Commission (SEC) remains a trend in the crypto space. Both entities have fired multiple shots at each other in the past three years, with the crypto company currently having the upper hand. In this article, we will observe the most recent developments around
The cryptocurrency markets are in shambles over the past couple of days, and bitcoin’s price dropped to levels not seen since December 2020. Data shows that the monthly relative strength index (RSI) is at its lowest point… ever. Popular BTC analyst and creator of the Bitcoin Stock-to-Flow (S2F) model, PlanB, reiterated the current bearish sentiment,…
ETH/USD – Ether Forms Symmetrical Triangle Key Support Levels: $3150, $2985, $2890. Key Resistance Levels: $3350, $3540, $3700. Since surging from $1800 at the end of July to meet resistance at $3350 in the first half of August, Ethereum has been consolidating inside a symmetrical triangle pattern. It has made over four attempts to break…
[PRESS RELEASE – Grundsheim, Germany, April 29th, 2024] Today marks an important date in the world of realistic simulation and virtual racing as Simugaze, the highly awaited cryptocurrency-powered ecosystem, officially launches. The SimuGaze ecosystem aims to transform the virtual gaming industry and realistic simulation by offering dynamic, immersive engagement to its users and investors and
[PRESS RELEASE – London, UK, August 12th, 2023] Binance Labs, the venture capital and incubation arm of Binance, has committed 10 Million USD to Helio Protocol, a project combining over-collateralized lending of its native decentralized stablecoin, HAY, with staking-as-a-service (StaaS) and LSDfi infrastructure, with approximately combined 300 million USD in TVL, of which 260 million…