Is This Latest Ledger Firmware Update A Disaster In The Making?

2023-5-16 15:30

Ledger, the hardware wallet provider, recently upgraded its firmware to version 2.2.1. They introduced an additional safety net called the “Ledger Recover” that the crypto community is vehemently rejecting.

While upgrades are critical considering the fast-paced nature of cryptocurrencies, Ledger is now being criticized after offering an option for users to store their seed phrases online. The hardware wallet manufacturer said this feature makes it easier for users to quickly recover their seed phrases in case they misplace them.

The “Ledger Recover” Feature Rejected

The subscription-based service called “Ledger Recover” effectively grants the manufacturer access to clients’ seed phrases; defeating the purpose of using a cold wallet in the first place.

Related Reading: DOJ Crypto Task Force Goes After DeFi Hackers As Illicit Activity Soars

The platform says Recover is an “ID-based key recovery service that provides backup” for seed phrases for coins like Bitcoin.

Earlier, Ledger’s co-founder said Recover will split a seed phrase into three shards. A section is distributed to Ledger, Coincover — a crypto custody firm, and EscrowTech, a company that escrows codes. Therefore, if a user loses access to their cold wallet by misplacing their private key, two of the three custodians can combine their code to recover the wallet’s contents.

While this could help, as it is designed, a cold or hardware wallet is non-custodial. Technically, it should be delinked from the internet. By default, Ledger wallet holders should always be responsible for their seed phrases.

Seed phrases allow users to sign transactions confirming that they are the true owners. Whenever they are misplaced, the token owner losses access to all their coins. 

Although the “Ledger Recover” feature is a precaution, some even claim this move makes Ledger a “hot” wallet. A hot wallet is a cryptocurrency wallet connected to the internet and is often the target of nefarious agents. Whenever hackers strike, they aim to wipe clean assets stored in hot wallets like MetaMask or Coinbase Wallet.

KYC Requirements And Learning From The Past

Besides Ledger requiring access to private keys, the “Recover” feature demands that users verify their identity as part of the know-your-customer (KYC) rules. 

As part of this verification and compliance with KYC, users must submit their government-issued cards. Critics say this is against the principles of crypto that work toward preserving privacy and diffusing power from one entity. 

Trusting private identity documents to a centralized entity can be disastrous. In 2020, Ledger’s database was compromised, and hackers dumped hundreds of thousands of wallet buyers’ confidential information, including physical addresses.

Hackers later used the same dumped details to target clients in an extortion campaign that affected even some of the top executives of Ledger.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Quantum Resistant Ledger (QRL) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0.307
Капитализация $0 Rank 99999
Цена в час новости $ 0.1392 (-100%)

ledger firmware called safety additional community vehemently

ledger firmware → Результатов: 20


First Level Security Certificate (CPSN) Given To Crypto Wallet Ledger Nano S By France’s ANSSI

First Level Security Certificate (CPSN) Given To Ledger Nano S By France’s ANSSI Ledger Nano S was originally developed by the French crypto hardware wallet Ledger. Having already planned on fixing issues with the firmware update for this product, impacting the storage capacity of the device, it looks like the Ledger Nano S is making […]

2019-3-19 22:45


Фото:

Ledger Faces Backlash for Failing to Properly Test Nano S Software Update

Ledger, a French cryptocurrency hardware wallet manufacturer, has faced criticism for failing to conduct proper testing before launching a firmware update to their Nano S wallet. While the company said that the update, which significantly decreased the device’s storage, was the result of a mistake, some users speculated it was part of a scheme to […] The post Ledger Faces Backlash for Failing to Properly Test Nano S Software Update appeared first on CryptoSlate.

2019-3-1 09:06


Разработчики Ledger рассказали о непредвиденной проблеме в новой версии ПО для Nano S

Разработчики аппаратных кошельков Ledger заявили, что в версии ПО 1. 5. 5 для модели Nano S была обнаружена непредвиденная проблема. Улучшения в контексте безопасности повлияли на объем памяти устройства.

2019-2-15 15:40


Фото:

Security Researchers Reveal Wallet Vulnerabilities On Stage at 35C3

In a demonstration titled “Wallet. fail,” a team of security researchers hacked into the Trezor One, Ledger Blue and Ledger Nano S. Unfortunately, it appears as if their findings were first put on display at the 35th Chaos Communication Congress (35C3) in Leipzig, Germany, rather than through accepted Responsible Disclosure practices, which would have allowed the manufacturers to patch the vulnerabilities and protect their customers from any potential attack.

2019-1-1 19:15


Вышли новые версии ПО для аппаратных кошельков Trezor

Разработчики аппаратных кошельков Trezor решили не отставать от своих конкурентов в лице компании Ledger, которая продолжает радовать своих пользователей постоянным дополнением числа поддерживаемых криптовалют, и тоже провели существенное расширение доступных для хранения активов.

2018-11-8 10:39