News linked to both this project and an event.
According to Bloomberg, crypto hardware wallet manufacturer Ledger SAS has announced the hiring of Oded Blatman as Chief Information Officer (CIO) and Chief Security Officer (CSO), consolidating internal technology systems and security functions under a single executive lead. Previously with blockchain company Fireblocks, Blatman will oversee network and infrastructure security, product security, physical and workplace safety, internal IT, and enterprise risk management.
Odaily News, lawyer Ariel Givner stated that hardware wallet manufacturer Ledger is facing a class action lawsuit in New York. The complaint alleges that a security incident in December 2023 exposed customers' personally identifiable information such as names, email addresses, and phone numbers, and that the company failed to disclose the breach in a timely and complete manner. Hackers subsequently used the contact information to impersonate official representatives, tricking customers into approving fraudulent transactions and stealing crypto assets. The compromised information was also circulated on the dark web.
According to security firm Huntress, hackers are distributing credential-stealing malware to cryptocurrency users through forged Google Docs files, malicious files hosted on GitHub, and cloned Claude.ai pages. Attackers impersonate senior CoinDesk employees on the social platform X, luring victims into opening Google Docs documents containing malicious code under the guise of an online meeting invitation, which then prompts users to manually install the malicious software. Mac users face threats from Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are served fake Google API Connector updates that, once installed, deploy NetSupport RAT and counterfeit Ledger hardware wallet applications. Additionally, hackers have placed fraudulent ads on search engines like Bing to lure users to cloned Claude.ai pages where they execute malicious commands; the associated malware, MacSync and SectopRAT, can steal cookies, saved passwords, mnemonic phrases, and payment card information. Security firm Socket also concurrently identified 16 malicious extensions targeting Chrome and Edge, capable of draining EVM, Solana, and Tron wallet assets.
According to Cointelegraph, open-source wallet provider OneKey stated that its security team successfully reproduced a "transaction replacement attack" targeting the legacy Ledger Ethereum app version 1.22.1 in a laboratory environment. This vulnerability could allow attackers to replace transactions awaiting signature while users review legitimate ones, though successful exploitation requires controlling communication between the device and the host, such as through malware, compromised wallet software, or malicious websites.
Odaily News: OneKey Anzen has reproduced the Ledger vulnerability and discovered that Ledger Ethereum app version 1.22.1 contains a transaction replacement vulnerability. When an affected user is attacked, the hardware screen still displays transaction A under review, but the device may sign transaction B, which the user never viewed. OneKey Anzen stated that the issue stems from a race condition between the transaction display logic and the underlying buffer, with the attack requiring the host side to already be compromised by a malicious DApp or intermediary software. Ledger's CTO previously responded that a fix had been rolled out approximately two weeks ago, and users simply needed to update the app. Public information shows that the official tag for version 1.22.2 on Ledger's GitHub appeared on August 24. Ledger's official website states that the issue has been fixed through app-level checksums and SDK-layer patches, with Ledger Secure SDK v26.6.1 released on August 21, and the related apps have been rebuilt and republished. Users need to update the app via Ledger Live — updating only the device firmware will not complete the fix. Ledger stated that there is currently no evidence that this vulnerability has been actively exploited.
Odaily News: Ledger Chief Technology Officer Charles Guillemet stated that a smart contract security company recently claimed to have discovered a vulnerability in the Ledger Ethereum app. The Ledger Ethereum app did previously contain a vulnerability related to certain Clear Signing processes, but it was identified by Ledger's in-house security research team, Donjon, using an AI-driven vulnerability research tool, and was fixed and deployed two weeks ago. The security company in question only contacted Ledger's bug bounty program after the fix had already been completed, failing to follow responsible disclosure procedures and without communicating with the bug bounty team, then published content implying that the issue remained unresolved. Guillemet stated that users who promptly update their Ledger device firmware, Ledger apps, and related software will receive the latest security fixes.
Odaily News - Hardware wallet maker BitBox reports that credit card sales in August grew roughly 10x compared to the baseline of previous weeks, with the increase primarily driven by North America. Trezor and OneKey also confirmed rising sales during the same period, though neither disclosed specific figures.Trezor, BitBox, and OneKey have all re-reviewed their seed phrase generation, random number generator, entropy, and firmware verification processes. Trezor plans to conduct penetration testing on core firmware functions and publish related security audit reports. OneKey will strengthen reviews of security-critical code paths and transaction signing processes.Ledger CTO Charles Guillemet stated that AI-assisted attacks mean patch releases, vulnerability disclosures, and user education need to accelerate. Blockstream Jade has released a firmware update containing multiple fixes and recommends users simultaneously update their apps, operating systems, devices, routers, and home appliances. (Bitcoin.com News)
According to Cointelegraph, cybersecurity company Rapid7 has disclosed a cryptocurrency phishing campaign named "Operation Asterix" targeting approximately 885,000 phone numbers, aimed at luring users into visiting fraudulent Ledger, Trezor, and Exodus wallet apps or websites to steal mnemonic phrases and crypto assets.
Odaily News Rapid7, a cybersecurity firm, has disclosed a crypto phishing campaign named Operation Asterix that targets approximately 885,000 phone numbers across multiple countries, redirecting victims to fraudulent wallet service websites. A total of 5,576 phone numbers have been matched with Binance user accounts and placed on the attack queue.The attackers steal seed phrases through fake apps impersonating Ledger, Trezor, and Exodus, while also contacting victims via fraudulent customer support emails and phone calls. Rapid7 also found that among over 316,000 phone numbers in Germany, 43,066 were matched with crypto trading accounts, representing a hit rate of approximately 13.6%.The related attacks also include a bulk phone number verification tool targeting Kraken accounts, and the investigation revealed that AI tools are being widely used in phishing operations. According to data from blockchain security firm Hacken, phishing attacks and social engineering scams caused $306 million in losses in the first quarter of this year, accounting for the majority of the $482 million total losses in the crypto industry. (Cointelegraph)
Odaily News, DefiLlama founder 0xngmi, of the crypto data analytics platform, stated that the team spent months asking Apple to remove phishing apps impersonating DefiLlama from the App Store, which delayed the mobile app's launch until all such counterfeit apps had been removed. 0xngmi noted that after the team downloaded one of the malicious apps and documented a small crypto wallet being stolen, Apple removed it within days. In 2024, the App Store also saw counterfeit apps impersonating Rabby Wallet and Curve Finance; in November 2023, a fake Ledger Live app on the Microsoft Store siphoned off $588,000 across 38 transactions. (Cointelegraph)
Odaily News: After a firmware vulnerability in Coldcard hardware wallets was exploited, approximately 2,100 Bitcoin were stolen, with losses nearing $130 million. On-chain data shows that in the days surrounding the incident, wallets held by long-term holders transferred out approximately 233,000 Bitcoin, valued at around $15 billion. Casa CEO Nick Neuman stated that some of the transferred funds came from Coldcard users migrating to multi-signature wallets, with Ledger and Trezor users also taking similar measures after the event. During the same period, approximately 22,000 Bitcoin were transferred into exchanges. Coinkite has advised users who generated seed phrases using firmware versions 4.0.1 through 4.1.9 to treat their wallets as compromised and immediately migrate to new seed phrases. These versions cover the period from March 2021 to July 2026. (Decrypt)
据 Cointelegraph 报道,比特币政策研究所(BPI)联合 Anchorage Digital、BitGo、Bitwise、Blockstream、Kraken、Ledger、MARA、Trezor 等多家加密机构,发布公开信敦促各大前沿 AI 实验室为比特币及开源软件开发者建立或扩展可信访问计划。 信中指出,Bitcoin Core 等开源维护者目前缺乏对 AI 实验室网络安全程序的访问渠道,被迫依赖能力较弱的开源模型,而比特币网络当前保护着逾 1 万亿美元资产,任何开源基础设施漏洞均可能危及用户毕生积蓄。BPI 同时披露,已收到多份报告显示包括潜在境外势力在内的复杂攻击者正借助先进 AI 能力持续发动攻击。
Odaily News: The cross-chain bridge connecting XRP Ledger and Coreum was attacked on August 9. The attacker exploited a validation logic vulnerability to steal approximately 199,900 XRP, reducing the bridge's asset balance from roughly 200,400 XRP to 493.5 XRP. The attack did not involve private key leaks and did not target the XRP Ledger protocol itself. The attacker forged deposit operations, causing the bridge system to recognize them as legitimate deposits and triggering the bridge wallet on the other end to send real XRP. On-chain data shows that the attacker completed the fund transfer through 94 multi-signature authorization transactions within 97 minutes. These transactions required signatures from 17 of the 28 relay node keys, allowing the attacker to bypass the bridge's validation mechanism. As of August 11, the Coreum cross-chain bridge remains suspended, and the Coreum Development Foundation has not yet released an official incident report. The XRP mainnet and user private keys remain unaffected and secure.
Odaily News: According to on-chain investigator Specter, the same attacker is running similar phishing campaigns targeting Ledger. The relevant screenshots were taken two days ago, and the sponsored ads have now been removed. To date, these campaigns have stolen over $3 million.
Odaily News: Hardware wallet manufacturer Ledger has stated that the recent Coldcard vulnerability indicates the hardware Bitcoin wallet industry needs to reassess its security model. Ledger CTO Charles Guillemet stated that Ledger devices were not affected, as their recovery phrases are generated by a hardware random number generator built into a certified secure element. Coldcard manufacturer Coinkite disclosed last week that its air-gapped Coldcard Bitcoin hardware wallet contains a vulnerability traceable to firmware versions from March 2021. The vulnerability uses a software fallback mechanism to generate wallet recovery seeds, allowing certain private keys to be guessed, with related losses reaching approximately $130 million. Coinkite released a fixed firmware on Sunday and urged affected users to transfer funds to newly generated wallets. Charles Guillemet stated that open source is different from being audited — the flaw had existed in public code for over five years, and AI is enabling attackers to scan code and identify vulnerabilities at machine speed. Charles Guillemet also said that over the past two years, Ledger has combined AI with security engineers and cryptography experts to review code and identify vulnerabilities. He believes that when evaluating hardware wallets, users should understand how randomness is generated and whether that process has received independent certification.
Bloomberg Senior ETF Analyst Eric Balchunas commented on the Coldcard wallet security incident, questioning whether a company with only about 5 employees is suitable to undertake such critical Bitcoin storage responsibilities. He stated that the number of employees behind Coldcard "seems unbelievably low," asking whether people would be willing to store their life savings in a bank with only 5 employees headquartered in Canada. In the crypto industry, this might be viewed as a feature, but from a traditional finance perspective, it becomes a clear risk signal. Balchunas further stated that, in comparison, institutions with larger teams such as Coinbase and Ledger may hold advantages in security investment and operational capabilities, even if users need to bear higher transaction costs. Bitcoin ETFs offer another option: investors can obtain the security guarantees provided by large, professional, regulated financial institutions while also enjoying lower management fees.
Odaily News: Jazzi Cooper, RippleX Product Lead, announced on X that the next version of XRP Ledger, xrpld 3.3.0, is set to launch next week. Upon release, it will introduce five new features to validators: confidential MPT, batch transactions, delegated permissions, fee sponsorship and reserves, and dynamic MPT. Among these, the amendments for batch transactions and delegated permissions were previously urgently withdrawn after security researchers discovered severe vulnerabilities. She noted that XRP Ledger already has the capacity to support tokenized assets at scale, and this upgrade will further drive the adoption of these assets in global transfers, trading, collateralization, and settlement scenarios.
Zilliqa has stated there is a critical vulnerability in its Ledger application that has existed since 2019, causing private keys used for native ZIL transactions to be susceptible to recovery attacks. At present, native transactions have been suspended, and relevant parties are working on a coordinated fix. EVM transactions are not affected.
According to The Block, Ledger's security research team Donjon disclosed a security vulnerability in Tangem hardware wallet cards. After obtaining the physical card, attackers can use laser fault injection equipment to bypass recovery state verification in the firmware and reset the password, thereby controlling the wallet and initiating transactions. The research states that this vulnerability affects all Tangem cards currently in circulation, and since the product does not support firmware updates, it cannot be fixed via patches.
Ledger's Donjon security research team successfully bypassed the firmware verification system of the TROPIC01 chip inside the Trezor Safe 7 using laser attacks in a laboratory setting. Chip manufacturer Tropic Square subsequently discovered another attack path affecting the chip's MAC-and-Destroy security mechanism. This vulnerability currently impacts all TROPIC01 chips in production within the field. Trezor stated that the TROPIC01 chip is one of three independent security layers within the Trezor Safe 7, and user funds, wallet backups, and private keys are not stored on it.The chip's hardware encryption storage mechanism completely withstood Ledger's extraction attempts during initial testing. Tropic Square has delayed the release of technical details regarding the vulnerability until the launch of a reinforced silicon version of the TROPIC01 chip later in 2026, with full details expected to be disclosed in the spring of 2027.A firmware mitigation is currently available by disabling the chip's MAINTENANCE mode. Trezor CEO Matej Zak stated that PINs, wallet backups, and user fund keys have never been stored on a single chip. (The Block)