Ledger is a cryptocurrency hardware wallet company developing security and infrastructure solutions for cryptocurrencies and blockchain applications for individuals and companies, using its own unique technology.
Odaily News: The latest software version 3.3.0 of XRP Ledger (XRPL) introduces several upgrade proposals, including Confidential Transfers. This feature is designed for institutional users, supporting encrypted token balances and transfer amounts while preserving the visibility of accounts and token types. It is primarily applied to Multi-Purpose Tokens (MPT) on XRPL, including tokenized financial assets such as funds and bonds. Through cryptographic technologies like zero-knowledge proofs, the network can verify transaction validity without disclosing specific amounts. XRPL currently holds approximately $1.38 billion in on-chain real-world assets (RWA), including about $845.7 million in RLUSD. In addition to RLUSD, there are over $530 million in tokenized assets on XRPL, involving issuers such as Ondo, VERT Capital, Archax, and Societe Generale. XRPL 3.3.0 also includes five proposals—Batch, Sponsor, Permission Delegation, and Dynamic MPT—addressing institutional needs such as batch transactions, fee sponsorship, permission management, and dynamic adjustments to token attributes. The aforementioned upgrades have not yet been officially launched and will only be activated after receiving support from more than 80% of XRPL's trusted validator nodes for two consecutive weeks.
Ripple announced strategic investments in UK fund technology company ZILO and FCA-regulated tokenized trading platform Licuido, integrating regulated digital transfer agency, asset issuance, and collateral liquidity capabilities into the XRP Ledger. Ripple stated that the relevant infrastructure will support tokenized funds as collateral from the issuance stage and enable atomic settlement via XRPL, while RLUSD can serve as the regulated cash leg in delivery versus payment transactions. The investment amount was not disclosed.
Odaily News: Ripple announced strategic investments in ZILO and Licuido, stating that these deals will bring regulated transfer agency, securities issuance, and collateral liquidity features to its XRP Ledger-based infrastructure.
Ripple is advancing the addition of a lending infrastructure layer on the XRP Ledger (XRPL), enabling institutions to raise funds using on-chain tokenized assets as collateral. The protocol will automatically execute loan terms, while credit evaluation and lending decisions remain handled by off-chain institutions.According to disclosures, the proposal is named the XRPL Lending Protocol (corresponding to XLS-65 and XLS-66 standards). It is currently in the technical draft stage and will require approval through validator voting before launching on the mainnet, but developer testing has already been opened on the test network.The protocol’s design splits the lending process into two parts: on-chain management of liquidity pools, interest calculation, repayment execution, and default handling; while borrower credit assessment and loan term setting remain with traditional financial institutions to meet compliance requirements across different jurisdictions.Ripple states that the mechanism is primarily aimed at institutional short-term liquidity needs. For example, in cross-border payment scenarios, temporary financing through stablecoins or collateral assets can be obtained before settlement is completed, thereby improving capital efficiency.Analysts believe that while the plan attempts to introduce a “rule-enforced lending infrastructure” similar to traditional finance while maintaining XRPL's open network attributes, it will still face competition from established on-chain lending protocols such as Aave, Compound, and Maple. (CoinDesk)
According to CoinDesk, Goldman Sachs stated that U.S. IPO activity in 2026 doubled year-on-year, with approximately 50 companies having gone public and issuance volume reaching about $120 billion in dollar terms—matching the full-year record set in 2021. Ben Snider, Goldman Sachs’ Chief U.S. Equity Strategist, noted that this recovery is primarily driven by a wave of large-cap listings and financing demand tied to AI development—a “normal recovery” that remains fundamentally distinct from the speculative frenzy seen during the dot-com bubble. Currently, the average annual number of IPOs stands at roughly 100, far below the 250 IPOs in 2021 and the nearly 400 IPOs recorded at the peak of the 1999 bubble. Notably, crypto firms—including Payward (Kraken’s parent company), Consensys, Ledger, and Grayscale—have postponed or suspended their IPO plans amid market volatility and underwhelming post-listing performance. Meanwhile, high-profile AI- and tech-related IPOs such as SpaceX have successfully listed, drawing institutional capital away from the crypto market and into other sectors—exerting downward pressure on tokens and crypto-related stocks.
: Due to weak trading volumes and macro pressures weighing on valuations, crypto companies are pausing their long-awaited IPO plans. Hardware wallet manufacturer Ledger and MetaMask developer ConsenSys are among the companies that have delayed their IPOs. Ledger had previously planned to list on the New York Stock Exchange with a valuation of $4 billion.Sean Farrell, Head of Digital Asset Strategy at Fundstrat, stated that crypto trading volumes have fallen by approximately 75% year-to-date, putting pressure on the valuations of publicly listed crypto companies. In contrast, demand for IPOs from tech companies related to AI remains strong.Additionally, Bitcoin miners pivoting to AI infrastructure have become one of the better-performing segments in the crypto market. Sean Farrell also pointed out that Hyperliquid is one of the standout crypto ecosystems in 2026, generating approximately $850 million in revenue over the past 12 months. Its recent partnership with Coinbase has made USDC the canonical stablecoin on the platform. (coindesk)
Odaily News: Sparrow Wallet v2.5.4 has been released following an extensive AI-assisted review, featuring multiple security hardening updates aimed at reducing users' reliance on external servers such as Electrum.Additionally, this version strengthens Ledger, Keycard, Trezor, Payjoin, PSBT, and multi-signature handling, removes Bitcoin Core credentials and other sensitive information from debug logs, restricts permissions for existing wallet and backup directories to owner-only access, closes residual local DNS resolution leaks when using Tor, and reinforces validation for wallet import, signing, downloads, and server responses. The update expands Sparrow Wallet's scope of independent verification for transaction data, hardware devices, and other inputs, reducing dependence on data provided by external servers. (Bitcoin News)
Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)
Odaily News Rapid7, a cybersecurity firm, has disclosed a crypto phishing campaign named Operation Asterix that targets approximately 885,000 phone numbers across multiple countries, redirecting victims to fraudulent wallet service websites. A total of 5,576 phone numbers have been matched with Binance user accounts and placed on the attack queue.The attackers steal seed phrases through fake apps impersonating Ledger, Trezor, and Exodus, while also contacting victims via fraudulent customer support emails and phone calls. Rapid7 also found that among over 316,000 phone numbers in Germany, 43,066 were matched with crypto trading accounts, representing a hit rate of approximately 13.6%.The related attacks also include a bulk phone number verification tool targeting Kraken accounts, and the investigation revealed that AI tools are being widely used in phishing operations. According to data from blockchain security firm Hacken, phishing attacks and social engineering scams caused $306 million in losses in the first quarter of this year, accounting for the majority of the $482 million total losses in the crypto industry. (Cointelegraph)
Odaily News: Standard Chartered and HSBC have completed the first real-time cross-border transaction executed via the Society for Worldwide Interbank Financial Telecommunication (SWIFT) blockchain ledger. The transaction exchanged payment messages through the SWIFT ledger, with the corresponding debts recorded respectively on HSBC's Tokenised Deposit Service and Standard Chartered's tokenised deposit infrastructure.The SWIFT ledger matches and nets off the debts of both parties before final settlement, with the ultimate settlement still completed through existing payment systems. The ledger is designed to connect tokenised deposits issued across different banking infrastructures, supporting round-the-clock cross-border payments while retaining existing settlement, compliance, and risk control mechanisms. (Cointelegraph)
Odaily News: Since the launch of Sui's Hashi Bitcoin lending protocol testnet on July 22, it has processed over 1.1 million Bitcoin deposits and 165,000 withdrawals within three weeks. As of last week, more than 25 institutions had participated in the system's stress testing. Participating institutions include digital asset custodian BitGo, trading firm Cumberland, as well as Swissborg, Fluid, and Ledger, covering areas such as trading, custody infrastructure, and wealth management platforms. Hashi allows users to deposit native Bitcoin, which is confirmed by Sui validators before minting hBTC for on-chain lending and stablecoin borrowing. Deposits utilize a 2-of-2 multi-signature mechanism with MPC validator signatures, while withdrawals require review by the Guardian Layer; the project team will proceed with the 2026 mainnet launch only after this security layer completes its security audit. (Bitcoin.com News)
据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。
According to Bitcoin.com News, Ripple’s stablecoin RLUSD reached a historical high of $2.442 billion in supply this week, up approximately 41% from $1.72 billion a month ago. Notably, the new supply has primarily flowed into Ethereum rather than the XRP Ledger. Ethereum currently holds $1.37 billion compared to the XRP Ledger’s $1.05 billion, marking a complete reversal from July when the XRP Ledger accounted for 58.9% of the total. Of the roughly $840 million in new supply added since July, Ethereum absorbed the vast majority.
Odaily News, lawyer Ariel Givner stated that hardware wallet manufacturer Ledger is facing a class action lawsuit in New York. The complaint alleges that a security incident in December 2023 exposed customers' personally identifiable information such as names, email addresses, and phone numbers, and that the company failed to disclose the breach in a timely and complete manner. Hackers subsequently used the contact information to impersonate official representatives, tricking customers into approving fraudulent transactions and stealing crypto assets. The compromised information was also circulated on the dark web.
Odaily News: Payment app Cash App is expanding its cryptocurrency services through crypto payment platform MoonPay, allowing 50 million users to purchase tokens such as ETH, SOL, XRP, and USDT. Additionally, users can top up major wallets like Ledger, BitPay, Trust Wallet, MetaMask, and Uniswap through Cash App. Previously, Cash App's crypto services only supported Bitcoin, with USDC support added earlier this year. (CoinDesk)
Odaily News: Since the launch of Sui's Hashi Bitcoin lending protocol testnet on July 22, it has processed over 1.1 million Bitcoin deposits and 165,000 withdrawals within three weeks. As of last week, more than 25 institutions had participated in the system's stress testing. Participating institutions include digital asset custodian BitGo, trading firm Cumberland, as well as Swissborg, Fluid, and Ledger, covering areas such as trading, custody infrastructure, and wealth management platforms. Hashi allows users to deposit native Bitcoin, which is confirmed by Sui validators before minting hBTC for on-chain lending and stablecoin borrowing. Deposits utilize a 2-of-2 multi-signature mechanism with MPC validator signatures, while withdrawals require review by the Guardian Layer; the project team will proceed with the 2026 mainnet launch only after this security layer completes its security audit. (Bitcoin.com News)
Odaily News: After a firmware vulnerability in Coldcard hardware wallets was exploited, approximately 2,100 Bitcoin were stolen, with losses nearing $130 million. On-chain data shows that in the days surrounding the incident, wallets held by long-term holders transferred out approximately 233,000 Bitcoin, valued at around $15 billion. Casa CEO Nick Neuman stated that some of the transferred funds came from Coldcard users migrating to multi-signature wallets, with Ledger and Trezor users also taking similar measures after the event. During the same period, approximately 22,000 Bitcoin were transferred into exchanges. Coinkite has advised users who generated seed phrases using firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and immediately migrate to new seed phrases. These versions cover the period from March 2021 to July 2026. (Decrypt)
硬件钱包厂商 Ledger 就 BIP-110 分叉发布安全提醒称,BIP-110 是一项未内置重放保护(replay protection)的比特币软分叉方案,如果形成独立链,BTC 持有者可能在新链获得相同数量的对应资产,但两条链初期可能接受相同签名交易。 用户若尝试转移或出售 BIP-110 链上的资产,相关交易可能被“重放”至比特币主链,导致对应 BTC 同时被转出。
According to Bloomberg, crypto hardware wallet manufacturer Ledger SAS has announced the hiring of Oded Blatman as Chief Information Officer (CIO) and Chief Security Officer (CSO), consolidating internal technology systems and security functions under a single executive lead. Previously with blockchain company Fireblocks, Blatman will oversee network and infrastructure security, product security, physical and workplace safety, internal IT, and enterprise risk management.
Odaily News, lawyer Ariel Givner stated that hardware wallet manufacturer Ledger is facing a class action lawsuit in New York. The complaint alleges that a security incident in December 2023 exposed customers' personally identifiable information such as names, email addresses, and phone numbers, and that the company failed to disclose the breach in a timely and complete manner. Hackers subsequently used the contact information to impersonate official representatives, tricking customers into approving fraudulent transactions and stealing crypto assets. The compromised information was also circulated on the dark web.
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.
According to Cointelegraph, open-source wallet provider OneKey stated that its security team successfully reproduced a "transaction replacement attack" targeting the legacy Ledger Ethereum app version 1.22.1 in a laboratory environment. This vulnerability could allow attackers to replace transactions awaiting signature while users review legitimate ones, though successful exploitation requires controlling communication between the device and the host, such as through malware, compromised wallet software, or malicious websites.
Odaily News: OneKey Anzen has reproduced the Ledger vulnerability and discovered that Ledger Ethereum app version 1.22.1 contains a transaction replacement vulnerability. When an affected user is attacked, the hardware screen still displays transaction A under review, but the device may sign transaction B, which the user never viewed. OneKey Anzen stated that the issue stems from a race condition between the transaction display logic and the underlying buffer, with the attack requiring the host side to already be compromised by a malicious DApp or intermediary software. Ledger's CTO previously responded that a fix had been rolled out approximately two weeks ago, and users simply needed to update the app. Public information shows that the official tag for version 1.22.2 on Ledger's GitHub appeared on August 24. Ledger's official website states that the issue has been fixed through app-level checksums and SDK-layer patches, with Ledger Secure SDK v26.6.1 released on August 21, and the related apps have been rebuilt and republished. Users need to update the app via Ledger Live — updating only the device firmware will not complete the fix. Ledger stated that there is currently no evidence that this vulnerability has been actively exploited.
Odaily News: Ledger Chief Technology Officer Charles Guillemet stated that a smart contract security company recently claimed to have discovered a vulnerability in the Ledger Ethereum app. The Ledger Ethereum app did previously contain a vulnerability related to certain Clear Signing processes, but it was identified by Ledger's in-house security research team, Donjon, using an AI-driven vulnerability research tool, and was fixed and deployed two weeks ago. The security company in question only contacted Ledger's bug bounty program after the fix had already been completed, failing to follow responsible disclosure procedures and without communicating with the bug bounty team, then published content implying that the issue remained unresolved. Guillemet stated that users who promptly update their Ledger device firmware, Ledger apps, and related software will receive the latest security fixes.
According to BIS Working Paper 1374 released by the Bank for International Settlements (BIS), the BIS, together with several researchers, has proposed a verifiable framework that binds official statistical data to the blockchain. The solution computes cryptographic fingerprints for SDMX datasets and anchors the digest values to the XRP Ledger, enabling independent verification of data provenance and integrity while leaving existing data publication workflows unaffected. Prototype tests show a data publication latency of approximately 3–5 seconds and a verification latency of approximately 1–2 seconds, meeting the requirements for real-time interactions and automated systems. Since only fingerprints, rather than raw data, are stored on-chain, data confidentiality is preserved. Cost modeling indicates that on-chain fees become negligible after batch processing, with a single ledger record capable of covering thousands of datasets. The study also provides an open-source reference implementation and reserves capacity for future integration of zero-knowledge proofs and AI-driven automated verification.
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.
Ripple stated that it is developing a long-term upgrade plan for the XRP Ledger to address the threat of quantum computing, aiming to prevent future quantum computers from potentially breaking existing cryptographic mechanisms and exposing private keys. The plan consists of four phases, including assessing network risks, testing post-quantum cryptography solutions, running existing security mechanisms alongside post-quantum alternatives in parallel, and initiating a complete network migration when necessary.
Odaily News: OneKey Anzen has reproduced the Ledger vulnerability and discovered that Ledger Ethereum app version 1.22.1 contains a transaction replacement vulnerability. When an affected user is attacked, the hardware screen still displays transaction A under review, but the device may sign transaction B, which the user never viewed. OneKey Anzen stated that the issue stems from a race condition between the transaction display logic and the underlying buffer, with the attack requiring the host side to already be compromised by a malicious DApp or intermediary software. Ledger's CTO previously responded that a fix had been rolled out approximately two weeks ago, and users simply needed to update the app. Public information shows that the official tag for version 1.22.2 on Ledger's GitHub appeared on August 24. Ledger's official website states that the issue has been fixed through app-level checksums and SDK-layer patches, with Ledger Secure SDK v26.6.1 released on August 21, and the related apps have been rebuilt and republished. Users need to update the app via Ledger Live — updating only the device firmware will not complete the fix. Ledger stated that there is currently no evidence that this vulnerability has been actively exploited.
Odaily News: Sparrow Wallet v2.5.4 has been released following an extensive AI-assisted review, featuring multiple security hardening updates aimed at reducing users' reliance on external servers such as Electrum.Additionally, this version strengthens Ledger, Keycard, Trezor, Payjoin, PSBT, and multi-signature handling, removes Bitcoin Core credentials and other sensitive information from debug logs, restricts permissions for existing wallet and backup directories to owner-only access, closes residual local DNS resolution leaks when using Tor, and reinforces validation for wallet import, signing, downloads, and server responses. The update expands Sparrow Wallet's scope of independent verification for transaction data, hardware devices, and other inputs, reducing dependence on data provided by external servers. (Bitcoin News)
Odaily News: Ledger Chief Technology Officer Charles Guillemet stated that a smart contract security company recently claimed to have discovered a vulnerability in the Ledger Ethereum app. The Ledger Ethereum app did previously contain a vulnerability related to certain Clear Signing processes, but it was identified by Ledger's in-house security research team, Donjon, using an AI-driven vulnerability research tool, and was fixed and deployed two weeks ago. The security company in question only contacted Ledger's bug bounty program after the fix had already been completed, failing to follow responsible disclosure procedures and without communicating with the bug bounty team, then published content implying that the issue remained unresolved. Guillemet stated that users who promptly update their Ledger device firmware, Ledger apps, and related software will receive the latest security fixes.
According to Bitcoin.com News, Ripple’s stablecoin RLUSD reached a historical high of $2.442 billion in supply this week, up approximately 41% from $1.72 billion a month ago. Notably, the new supply has primarily flowed into Ethereum rather than the XRP Ledger. Ethereum currently holds $1.37 billion compared to the XRP Ledger’s $1.05 billion, marking a complete reversal from July when the XRP Ledger accounted for 58.9% of the total. Of the roughly $840 million in new supply added since July, Ethereum absorbed the vast majority.
According to Bloomberg, crypto hardware wallet manufacturer Ledger SAS has announced the hiring of Oded Blatman as Chief Information Officer (CIO) and Chief Security Officer (CSO), consolidating internal technology systems and security functions under a single executive lead. Previously with blockchain company Fireblocks, Blatman will oversee network and infrastructure security, product security, physical and workplace safety, internal IT, and enterprise risk management.
According to Cointelegraph, Citibank and DBS Bank completed the first weekend cross-border tokenized deposit transaction between Singapore and the United States on Saturday. The transaction was executed via the SWIFT Digital Ledger, leveraging tokenized deposits to bypass traditional banking hour restrictions and settle within minutes. DBS Bank stated that, compared to the processing time of traditional cross-border transfers which can take up to two business days, this transaction significantly improved efficiency.
The Evernorth report shows that the number of accounts on the XRP Ledger has declined, but the volume per transaction has nearly tripled, and the network's total value has surpassed $4.2 billion, driven by stablecoins.
According to BIS Working Paper 1374 released by the Bank for International Settlements (BIS), the BIS, together with several researchers, has proposed a verifiable framework that binds official statistical data to the blockchain. The solution computes cryptographic fingerprints for SDMX datasets and anchors the digest values to the XRP Ledger, enabling independent verification of data provenance and integrity while leaving existing data publication workflows unaffected. Prototype tests show a data publication latency of approximately 3–5 seconds and a verification latency of approximately 1–2 seconds, meeting the requirements for real-time interactions and automated systems. Since only fingerprints, rather than raw data, are stored on-chain, data confidentiality is preserved. Cost modeling indicates that on-chain fees become negligible after batch processing, with a single ledger record capable of covering thousands of datasets. The study also provides an open-source reference implementation and reserves capacity for future integration of zero-knowledge proofs and AI-driven automated verification.
Odaily News, lawyer Ariel Givner stated that hardware wallet manufacturer Ledger is facing a class action lawsuit in New York. The complaint alleges that a security incident in December 2023 exposed customers' personally identifiable information such as names, email addresses, and phone numbers, and that the company failed to disclose the breach in a timely and complete manner. Hackers subsequently used the contact information to impersonate official representatives, tricking customers into approving fraudulent transactions and stealing crypto assets. The compromised information was also circulated on the dark web.