3 ms·
Ledger has for a long time been grossly inept in security, there's really nothing absurd about this attack at all. In the Bitcoin industry we frequently see ver
by 32032141 8y ago
Ledger has for a long time been grossly inept in security, there's really nothing absurd about this attack at all. In the Bitcoin industry we frequently see very detailed setup for long timeframe attacks and substantial effort going into identity theft and physical compromise. Worse, for these deices in particular a backdoored device is almost undetectable due to the way ECDSA can be used to transmit encrypted data in its signatures.
Ledger was recently compromised, or showed that they have no release process (both equally bad) by releasing a version of their application which stole user funds. Their claim is that they released a development version from a dirty git clone that contained "testing" code which happened to have a hardcoded address for sending every transaction to.
https://www.ledger.fr/2018/08/03/important-message-concerning-the-ledger-wallet-ethereum-chrome-app/ https://www.ledger.fr/2018/08/03/important-message-concernin...
- tgsovlerkhgsel 8y agoThat's indeed impressively bad. The full address seems to be https://etherscan.io/address/0xC33B16198DD9FB3bB342d8119694f94aDfcdca23 https://etherscan.io/address/0xC33B16198DD9FB3bB342d8119694f... There don't seem to be any outbound transactions from that address, so Ledger refunded the victims separately instead of sending the funds back. That means they likely don't control the key. OTOH, the funds (worth about $40k for the Ether + another $20k for the tokens) haven't moved at all, so "test key that was lost long ago" does seem plausible. (Especially since it also was used on the testnet before https://ropsten.etherscan.io/address/0xC33B16198DD9FB3bB342d8119694f94aDfcdca23 https://ropsten.etherscan.io/address/0xC33B16198DD9FB3bB342d...) Could of course also be an attacker who was hoping for a bigger loot and didn't want to risk getting caught over $60k, but as you said, not sure what's worse - incompetence or compromise.
- 32032141 8y agoYep. Either they are so incompetent that they released software out of their git tree from someone's work environment, and had absolutely no process to catch a ridiculous and obvious failure. Otherwise they got popped and are lying about it. Neither is anything but a disaster.