Online discussions continue to swirl around Ledger’s new firmware update for its crypto hardware wallet, which experts have claimed could put users’ private keys at risk.
Ledger published a Twitter thread on Wednesday attempting to alleviate concerns around the safety of users’ assets, but published a self-contradictory and confusing tweet that stoked the flames of controversy even further.
Ledger’s Worrying Tweet
In a now-deleted tweet, Ledger support verified criticisms from Wednesday exposing a troublesome reality of using their product: the manufacturer could, technically, release firmware that extracts users’ private keys from their wallets.
“You have always trusted Ledger not to deploy such firmware whether you knew it or not,” wrote the company.
Ledger’s Deleted Tweet. 05/17/23
This contradicts a claim from the company’s main account last November, in which Ledger claimed that user private keys cannot be extracted from a wallet’s secure element chip through a firmware update.
At the time, Ledger and other wallet manufacturers were recording record sales in the aftermath of FTX’s collapse, as crypto investors sought the security of self-custody and cold storage for their crypto assets.
On Thursday, Ledger said that it decided to delete its Wednesday tweet due to its “confusing wording.” However, Ledger’s CTO Charles Guillemet published a follow-up thread explaining that wallets, in general, have “many ways” to implement a backdoor, and that some level of trust is required with any third-party wallet purchase.
22/ If you want to be completely trustless, you’ll have to learn electronics to build your computer, learn ASM to build your compiler, then build a wallet stack, your own node and synchronizer, you’ll have to learn cryptography to build your own signature stack.
— Charles Guillemet (@P3b7_) May 18, 2023
“Open source doesn’t really solve this,” he added. “It’s impossible to have guarantees that the electronic itself is not backdoored, nor that the firmware that runs inside the wallet is the one you audited.”
Ledger Recover
Criticism around Ledger swelled on Wednesday after the company announced its new hardware wallet service “Ledger Recover.” With user permission, the service breaks a wallet’s private keys into three shards, encrypts them, and stores them with three separate centralized providers – one of which is Ledger.
The subscription service requires users to provide personal identifying information before using it. In return, users are granted a method of recovering their private keys in case they lose both their hardware device and seed phrase paper backup.
The crypto community blasted the service and its associated firmware update for adding a code path that can send private keys to third parties. Many experts including developer and auditor “foobar” recommended that followers stop using the company’s devices.
If you have a ledger, your keys are not compromised (yet). But if you upgrade to the latest firmware, it’ll stick in a code path that can send your private key to third parties. Given ledger doxxed their own customers in the past, it’s unlikely that they’ll keep this info safe
— foobar (@0xfoobar) May 16, 2023
The post Ledger Responds to Customer Fears On Wallet Safety, But Deletes “Confusing” Tweet appeared first on CryptoPotato.
After another week of consolidation for bitcoin, with a drawdown to $31k, investors look to the weekend for a sigh of relief as the GBTC shares unlock continues. On-chain analysts detected an unusually large inflow of 41,000 BTC over a few transactions into Coinbase Pro Exchange, in just one hour. The immediate reaction from Crypto…
Patrick Hilmann, the Chief Strategy Officer (CSO) of leading crypto exchange Binance, alleged that Sam Bankman-Fried (SBF), the founder and former CEO of the now-defunct rival exchange FTX, consistently criticized Binance’s CEO Changpeng Zhao (CZ) before FTX’s collapse, a behavior Hilmann referred to as “shading.” In a recent tweet, the CSO disclosed that SBF was…
TL;DR Analysts project XRP could hit new highs, with forecasts ranging from $4 to $9. However, one market observer envisioned a double-digit crash if the price fails to close above $4 by March 10. New ATH Soon? Ripple’s XRP started 2025 on the right foot, with its price surging to almost $2.50 on January 4.
Quite a lot has been going on in the cryptocurrency industry over the past seven days, but most of it failed to impact the price action,Week’s remains rather dull. Can’toin is trading below $17K, down about 2.9% in the past seven dParents’ble to recover the coveted level. The volatility has seemingly disappeared from the market,…
Binance CEO Changpeng Zhao (CZ) published a tweet on Wednesday noting that China Central Television (CCTV) recently put out a broadcast related to digital assets. The executive claimed that similar coverage has served as a catalyst for crypto bull runs in the past. CZ provided a link to the broadcast which aired on May 23,…
[PRESS RELEASE – Please Read Disclaimer] Former PlayStation EVP, Simon Rutter, joins as Chairman. VR Game Peaky Blinders: The King’s Ransom and Web 3 game Resurgence Today, a new entertainment PLC EMERGENT ENTERTAINMENT is announced. Emergent Entertainment officially merges London-based video game studio Maze Theory with blockchain veterans and developers Pluto Digital PLC, following a…
It’s been approximately one year since the COVID-19 threat infiltrated the Western World and caused massive disruptions. Consequently, it has been a little less than twelve months since the US government initiated considerable relief packages and sent $1,200 to every adult earning less than $75,000 per year. While highly unlikely, this particular amount could have…
Chris Dixon, founding partner at a16z Crypto, claims that misguided regulations fueled the meme coin explosion witnessed in 2024. The venture capitalist criticized the Biden administration’s approach to digital assets, arguing that its restrictive policies stifled real innovation and left the market with mostly speculative tokens. A Distorted Crypto Sector Speaking to prominent crypto journalist
While they are issued by smart contract blockchains with base layer currencies like Ethereum (ETH) and Solana (SOL), meme coins have fetched far greater gains in a shorter period of time than the most established cryptos. Bitcoin, for example, gained 347% from key price support at a Dec. 31, 2022 low level of $16,500 to