A Newly Discovered Vulnerability in Ledger Wallet Could Be Disastrous If Not Properly Fixed

Published at: Aug. 5, 2020

A recent report contends that the Ledger app has failed to fix a major vulnerability that allows for a “Bitcoin Fork” attack.

Mo Nokhbeh has claimed that Ledger’s wallet fails to properly isolate the apps responsible for authorizing the transactions of different assets. This creates a vulnerability where a user’s wallet can be fooled into authorizing a transaction for a less valuable asset — such as Litecoin (LTC), Bitcoin Cash (BCH) or any other Bitcoin fork coin — when in reality, a Bitcoin (BTC) transaction is being released. Nokhbeh told Cointelegraph:

“This app should be isolated such that it only signs for testnet derivation paths. However, sending it a regular mainnet bitcoin transaction will pass. In addition, it will present the TX as if it's testnet bitcoin, to a testnet bitcoin address.”

According to Nokhbeh, he made Ledger fully aware of this vulnerability, and despite acknowledging it, the company has failed to fix it. Instead, they have chosen to release an update to their existing app that will provide users with a warning prompt if such an exploit is detected.

We have reached out to Ledger for comment and will update pending a response.

Tags
Related Posts
Price Analysis 14/10: BTC, ETH, XRP, BCH, LTC, EOS, BNB, BSV, XLM, TRX
A draft report by the G7 group of nations outlined the risks associated with “global stablecoins.” The report said: “No stablecoin project should begin operation until the legal, regulatory and oversight challenges and risks are adequately addressed.” This report is likely to increase the troubles for Facebook’s Libra project. Former Commodity Futures Trading Commission chairman Christopher Giancarlo believes that Libra and the prospects of central bank digital currencies will increase regulator's intrusions into the crypto space. This can work as a double-edged sword. If regulators provide clarity, it is likely to attract large institutional players into the game, but if …
Bitcoin / Oct. 14, 2019
US Cryptocurrency Exchange ErisX Receives License for Crypto Futures
Chicago-based crypto exchange ErisX has procured a derivatives clearing organization (DCO) license from the United States Commodity Futures Trading Commission (CFTC). According to an official blog post on July 1, ErisX is planning to make digital asset futures contracts available for trade on its regulated derivatives market later this year via its new DCO. ErisX also launched its spot market in April, with the promise of eventually rolling out a single digital asset platform for spot and futures trading. At press time, the ErisX spot market exchange includes U.S. dollar trading pairs with bitcoin (BTC), bitcoin cash (BCH), ether (ETH) …
Bitcoin / July 1, 2019
Bitcoin, Ethereum, Ripple, Bitcoin Cash, EOS, Litecoin, Binance Coin, Bitcoin SV, Stellar, Cardano: Price Analysis May 31
The views and opinions expressed here are solely those of the author and do not necessarily reflect the views of Cointelegraph. Every investment and trading move involves risk, you should conduct your own research when making a decision. Market data is provided by the HitBTC exchange. Michael Novogratz, founder and CEO of cryptocurrency merchant bank Galaxy Digital, believes that the adoption of the blockchain technology by mainstream technology companies and interest by Wall Street firms helped start the rally. He now expects Bitcoin to remain range bound between $7,000 and $10,000. Bitcoin has seen a massive run in 2019. When …
Bitcoin / May 31, 2019
Bitcoin, Ethereum, Ripple, Bitcoin Cash, EOS, Litecoin, Binance Coin, Stellar, Cardano, TRON: Price Analysis May 20
The views and opinions expressed here are solely those of the author and do not necessarily reflect the views of Cointelegraph. Every investment and trading move involves risk, you should conduct your own research when making a decision. Market data is provided by the HitBTC exchange. Bitcoin rallied about 101.55% between April 2 and May 14. This sharp rally after a long bear phase surprised many, including us. Analysts at JPMorgan Chase have said that, after the rally, Bitcoin is trading above its intrinsic value. They find some similarities in the current rally to the one in late 2017. However, …
Bitcoin / May 20, 2019
Bitcoin, Ethereum, Ripple, Bitcoin Cash, EOS, Stellar, Litecoin, Cardano, Monero, IOTA: Price Analysis, September 12
The views and opinions expressed here are solely those of the author and do not necessarily reflect the views of Cointelegraph.com. Every investment and trading move involves risk, you should conduct your own research when making a decision. The market data is provided by the HitBTC exchange. Financial regulators are watching companies involved in the cryptocurrency industry with increasing scrutiny. On September 11, the U.S. Securities and Exchange Commission (SEC) penalized a crypto hedge fund for the first time, while the Financial Industry Regulatory Authority (FINRA) charged broker Timothy Ayre with securities fraud over a cryptocurrency deal. These actions by …
Bitcoin / Sept. 12, 2018