Online discussions continue to swirl around Ledger’s new firmware update for its crypto hardware wallet, which experts have claimed could put users’ private keys at risk.
Ledger published a Twitter thread on Wednesday attempting to alleviate concerns around the safety of users’ assets, but published a self-contradictory and confusing tweet that stoked the flames of controversy even further.
Ledger’s Worrying Tweet
In a now-deleted tweet, Ledger support verified criticisms from Wednesday exposing a troublesome reality of using their product: the manufacturer could, technically, release firmware that extracts users’ private keys from their wallets.
“You have always trusted Ledger not to deploy such firmware whether you knew it or not,” wrote the company.
Ledger’s Deleted Tweet. 05/17/23
This contradicts a claim from the company’s main account last November, in which Ledger claimed that user private keys cannot be extracted from a wallet’s secure element chip through a firmware update.
At the time, Ledger and other wallet manufacturers were recording record sales in the aftermath of FTX’s collapse, as crypto investors sought the security of self-custody and cold storage for their crypto assets.
On Thursday, Ledger said that it decided to delete its Wednesday tweet due to its “confusing wording.” However, Ledger’s CTO Charles Guillemet published a follow-up thread explaining that wallets, in general, have “many ways” to implement a backdoor, and that some level of trust is required with any third-party wallet purchase.
22/ If you want to be completely trustless, you’ll have to learn electronics to build your computer, learn ASM to build your compiler, then build a wallet stack, your own node and synchronizer, you’ll have to learn cryptography to build your own signature stack.
— Charles Guillemet (@P3b7_) May 18, 2023
“Open source doesn’t really solve this,” he added. “It’s impossible to have guarantees that the electronic itself is not backdoored, nor that the firmware that runs inside the wallet is the one you audited.”
Ledger Recover
Criticism around Ledger swelled on Wednesday after the company announced its new hardware wallet service “Ledger Recover.” With user permission, the service breaks a wallet’s private keys into three shards, encrypts them, and stores them with three separate centralized providers – one of which is Ledger.
The subscription service requires users to provide personal identifying information before using it. In return, users are granted a method of recovering their private keys in case they lose both their hardware device and seed phrase paper backup.
The crypto community blasted the service and its associated firmware update for adding a code path that can send private keys to third parties. Many experts including developer and auditor “foobar” recommended that followers stop using the company’s devices.
If you have a ledger, your keys are not compromised (yet). But if you upgrade to the latest firmware, it’ll stick in a code path that can send your private key to third parties. Given ledger doxxed their own customers in the past, it’s unlikely that they’ll keep this info safe
— foobar (@0xfoobar) May 16, 2023
The post Ledger Responds to Customer Fears On Wallet Safety, But Deletes “Confusing” Tweet appeared first on CryptoPotato.
The highly anticipated debate between incumbent Massachusetts senator and digital asset critic Elizabeth Warren and her pro-crypto challenger, John Deaton, finally happened. Among the highlights of the exchange was Senator Warren’s accusation that Deaton could become a mouthpiece for the crypto industry if he won, ostensibly putting its interests ahead of those who elected him.
Bitcoin went through a volatile end of the week in which it posted a new 13-month high before it slipped under $30,000 but has managed to defend that level. The altcoins are calmer on a daily scale, aside from SOL, AVAX, LEO, ARB, and a few others, which have added some value. BTC Defends $30K…
Following a couple of unsuccessful attempts, the New York City-based giant asset manager VanEck has filed another document with the SEC to launch a Bitcoin ETF. If successful, the VanEck Bitcoin Trust would reflect the performance of the MVIS CryptoCompare Bitcoin Benchmark Rate. VanEck Tries Again For A BTC ETF Founded in 1955, VanEck is…
[PRESS RELEASE – Please Read Disclaimer] The growth of the staking industry has pushed countless projects to work on providing such services to its users as they aim to receive income based on the number of tokens locked for staking. The latest to do so is Minto – a digital currency project founded more than…
The United States will aim for clear regulatory rules to enable banks and their customers to hold and operate with cryptocurrencies, said the FDIC chair, Jelena McWilliams. As such, the positive developments coming from the world’s largest economy continue as the nation recently had its first Bitcoin Futures ETF. US Banks to Hold Crypto? Up…
Ripple has announced a partnership with Lithuania’s FINCI to provide retail remittances and B2B payments through RippleNet’s On-Demand Liquidity (ODL). Thanks to this partnership, FINCI’s customers can make seamless payments between Europe and Mexico, a PR from Ripple said. Ripple-FINCI Partnership FINCI is an online cross-border money transfer provider, while RippleNet’s ODL provides crypto-enabled international…
From euphoria to depression: The crypto traders thought they are leaving off for Christmas in an optimistic mood; however, Bitcoin had other plans, as of now. Two days ago, following accurately touching the critical resistance level of $7700, which was discussed here many times as the short-term first significant level, the cryptocurrency got poorly rejected.…
According to the latest report from Immunefi, from January to October 2023, over $1.41 billion has been lost to hacking and fraudulent activities in 292 specific incidents. In October 2023 alone, losses amounted to approximately $22.2 million, primarily attributed to hacking and fraud. The most frequently targeted blockchain networks during the period were BNB Chain
The leading cryptocurrency exchange Binance has expanded its partnership with the blockchain-based provider of sports and entertainment entities, Chiliz. The first direct result of this will be the distribution of Juventus and PSG Fan Tokens through Binance Launchpool. Binance Doubles-Down On Chiliz The Malta-based giant trading venue announced the new endeavor in a press release…