Home News HOT news Newly Discovered Vulnerability In All Ledger Hardware Wallets Puts User Funds At Risk

Newly Discovered Vulnerability In All Ledger Hardware Wallets Puts User Funds At Risk

32 min read
0
86
Newly Discovered Vulnerability In All Ledger Hardware Wallets Puts User Funds At Risk 725 Ly9jb2ludGVsZWdyYXBoLmNvbS9zdG9yYWdlL3VwbG9hZHMvdmlldy83YmNmOTQxMzIyNGZlNmRiYmQ5MjhhZTBjYTk3ZTI5ZC5qcGc

Hardware cryptocurrency wallet manufacturer Ledger has discovered a vulnerability that affects all of its devices and can lead to users losing their funds, according to a report released on Saturday, Feb. 3.

According to the report, а “man in the middle” attack can be performed when the user attempts to generate an address to receive bitcoins to their Ledger wallet. If the computer that is used in this process is infected by malware, the attacker can secretly replace the code responsible for generating the address, causing “all future deposits to be sent to the attacker.”

How to protect yourself
Fortunately for the owners of their wallets, Ledger has also revealed how to avoid the “man in the middle” attack. According to the report, users should take advantage of an “undocumented” feature of the wallet that displays the receiving address on the wallet’s physical display.

1  Newly Discovered Vulnerability In All Ledger Hardware Wallets Puts User Funds At Risk 1 2 500x414

By clicking the monitor button at the bottom left of the “Receive Bitcoins” menu and confirming the address on the hardware wallet’s display every time they generate a new one, users can ensure that the address has not been tampered with.

The report further indicates that this feature is not mandatory and is not enforced by Ledger’s own interface, placing the ultimate responsibility for the safety of the funds on users themselves.

Hardware wallets are regarded as one of the safest ways to store cryptocurrencies, as opposed to holding them on an online exchange or wallet.

However, with Ledger’s over one million users affected by the newly discovered vector of attack, it becomes clear that even having a hardware wallet does not “make you invincible,” in the company’s own words.

Source: goo.gl/sZQpYj

Check Also

Crypton Studio at the Russian Blockchain Week 2018, Skolkovo

The Technopark Skolkovo, Moscow, hosted the opening of the Russian Blockchain Week 2018 co…