Ledger wallet vulnerability. How to protect your funds from intruders?

Ledger wallet vulnerability. How to protect your funds from intruders?

According to a tweet from the company published on February 3, a vulnerability has been discovered in Ledger's hardware cryptocurrency wallets that compromises users' funds. A “man in the middle” attack (data interception) can be applied to wallets, which attempts to generate an address for receiving cryptocurrency, and more specifically Bitcoin, to another wallet.

The attack itself can be carried out when a user attempts to create a new address to receive bitcoin on a Ledger wallet.

If the computer on which the action is performed is infected with malware, then the attacker can easily replace the recipient's address. As a result, all transferred funds will go to the hacker’s wallet.

To the great joy of wallet owners, the manufacturing company indicated how this problem can be solved. To do this, you need to use the “undocumented” wallet function. It reflects the receiving address on the physical display of the device itself.

You need to press the monitor button, which is located in the transfer receiving menu. Next, the address will appear on the screen, comparing it with the required one, the user has the opportunity to personally verify its correctness. The address must be confirmed each time a new key needs to be generated.

The company also warns that this feature is optional. Therefore, all responsibility for the consequences lies solely with the users.

Let us remind you that, unlike storing funds on an online exchange or a hot wallet, the use of hardware wallets is considered one of the safest ways to store digital currency.

But, still, this is not a reason to relax too much, since this function only works with Bitcoin. This means that if you intend to transfer, for example, Ethereum, you will not be able to track the address. In such a case, Docdroid offers to boot the operating system via Live CD. Such procedures will need to be followed until the company sorts out the problem and offers other options.

Recall that we discussed similar viruses and ways to avoid address spoofing in this article.





Subscribe to our news in Telegram

You May Also Like

2242018-10-08

Hacked Facebook accounts are sold on the dark web

The data of each of Facebook's 50 million users, stolen in late September, is being sold on the dark web. After the social network announced the discovered vulnerability, the company hastened to officially announce that it had been fixed and that there was no threat to users. However, this data breach was one of the largest in the history of the social network, and now a fresh Facebook user database has appeared on underground online markets.

Security
2022018-08-10

Iranian hackers use Bitcoin in confrontation with US

Iranian hackers are developing cyber attacks that block computer systems, disrupt city services and demand cryptocurrency ransom, according to a new report from Accenture PLC.

Security, Regulation

Latest articles from Security category