Ledger Patches Nano X Supply Chain Vulnerability

Ledger Patches Nano X Supply Chain Vulnerability
фото показано с : beincrypto.com

2020-7-9 12:12

The Ledger security team has patched a hardware exploit that could compromise Ledger Nano X wallets as a part of a supply chain attack.

Following a report from Kraken Security Labs, a cybersecurity division of Kraken, that showed that the Ledger hardware wallet was susceptible to a supply chain attack, the device manufacturer has announced that it has patched the issue with a new firmware update for the Ledger Nano X.

The patch only targets Ledger Nano X and not the Ledger Nano S. The manufacturer has said that the secure element of the wallet has not been affected, meaning that the vulnerability does not compromise the security of the 24-word passphrase, private keys, and PIN code.

The vulnerability is purely physical and has been fully addressed with the patch. The team also stresses that the likelihood of this attack is very low. Ledger thanked Kraken for discovering the vulnerability, which they say Ledger’s security lab, the Ledger Donjon, had already discovered separately.

What Did Kraken Discover?

On July 8, Kraken Security Labs identified two supply chain attacks that were possible against the Ledger Nano X wallets.

As the name implies, supply chain attacks involve tampering with the device before it is delivered to the user. This can occur anywhere along the supply chain, perhaps perpetrated by a malicious reseller or by being intercepted. The device is compromised and targeted by the attackers.

Kraken reported that the firmware of the ‘non-secure processor’ is modified to use a debugging protocol as an input device, which can then send malicious keystrokes to the user’s host computer.

The report reads:

The Ledger Nano X ships with the debugging functionality enabled on its non-secure processor, a feature that is disabled as soon as the first ‘app’, such as the Bitcoin app, is installed on the device. However, prior to any apps being installed, the device can be reflashed with malicious firmware that can compromise the host computer, similar to “BadUSB” and “Rubber Ducky” attacks.

In a nutshell, the attack uses the wallet as a keyboard and can also be used to execute malware attacks on the victim’s computer.

Hardware Wallets Still the Safest, But Updates Always Necessary

Ledger is one of the most popular hardware wallets on the market and acts as an offline storage solution used by investors to safely store large amounts of their digital asset investments.

While much safer than the web, desktop, and mobile wallets, periodically, security teams release reports that prove that the protection is not airtight. To their credit, manufacturers like Ledger and Trezor have historically patched issues soon after being discovered.

A recent report published by HTF MI has shown that the purchase of hardware wallets has slowed down as a result of the COVID-19 pandemic. However, safe storage solutions continue to be a strong area of research and development as more investors enter the market.

The post Ledger Patches Nano X Supply Chain Vulnerability appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Quantum Resistant Ledger (QRL) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0.307
Капитализация $0 Rank 99999
Цена в час новости $ 0.1115 (-100%)

ledger supply chain nano kraken hardware attack

ledger supply → Результатов: 88


Фото:

EVRYTHNG, Arianee Join Forces to Trace Luxury Goods with Blockchain

EVRYTHNG, a company that claims to foster supply chain transparency using Internet of things (IoT), is partnering with Arianee, a distributed ledger technology  (DLT) project that’s focused on building perpetual relationships between brands and product owners, to track and prove the authenticity of luxury goods with blockchain technology, reports Ledger Insights on June 17, 2020.

2020-6-19 22:00


Фото:

IOTA (MIOTA) Joins Dig_it Project to Develop a Sustainable Mining Ecosystem

IOTA (MIOTA), a distributed ledger technology (DLT) project focused on the internet of things (IoT) ecosystem, will collaborate with 15 other entities to carry out the Dig_it project. Dig_it is a Research and Innovation Action (RIA) project aimed at digitizing and transforming Europe’s major mine supply chains: gold, copper, and charcoal, according to a blogRead MoreRead More.

2020-5-21 17:00


Фото:

China’s Tencent Begins Blockchain Accelerator Program 

Tencent, a leading Chinese technology giant that doubles as the world’s largest video game company have announced the launch of its blockchain accelerator program. Tencent says it plans to mentor 30 companies in three major areas of distributed ledger technology (DLT), including finance, logistics, supply chain, and more, according to a press release on AprilRead MoreRead More.

2020-5-1 01:07


Canadian Govt Funds Two Blockchain Firms To Track Steel Through Supply Chain

Reports have surfaced that the Canadian Government has sought the services of two Blockchain solutions firm to create a Blockchain platform that would help trace its steel. The government through an initiative tasked with development of Canadian SME’s, the Innovation, Science, and Financial Development Canada (ISED) has awarded Mavenett and Peer Ledger each $150,000 to […]

2020-3-10 16:08


Фото:

VeChainThor (VET) v1.3.0 Upgrade Launches with Better Performance and Efficiency 

VeChain (VET), a distributed ledger technology (DLT) project that claims to be focused on enhancing supply chain processes, has announced that it’s version 1. 3. 0 update is now live. VeChain says the latest release is the most significant update since the launch of its mainnet and it offers users better performance, efficiency and more, according toRead MoreRead More.

2020-2-19 18:00


Фото:

Block Aero Wins Grant to Develop Blockchain for Rolls Royce

Aeronautical blockchain firm Block Aero has been awarded a $37,000 grant to develop a supply chain focused blockchain network for Rolls Royce’s aeronautics division. Ledger Insights reported that the blockchain will help stakeholders in the ecosystem seamlessly connect with each other and receive information with regards to maintenance and component replacement, November 27, 2019.

2019-11-28 20:00


Gominer ICO

Gominer Token is a Peer-to-Peer token that has a sophisticated level of security for a multi-functional digital currency and for all future use expansion. The token is created to help our user to interact and expand the way of their earning in Cloud mining.

2019-7-28 17:33


IOTA’s Tangle DLT to ensure allergen food safety for Primority

IOTA’s Tangle DLT to ensure allergen food safety for Primority - CryptoNinjas IOTA Foundation, a non-profit foundation focused on distributed ledger technology (DLT) and open-source ecosystem development, today announced a partnership with Primority, a digital food safety management company that helps food product manufacturers monitor food safety in food supply chains.

2019-6-21 19:10


Фото:

Carrefour wants to track 20% of its products on the blockchain by 2020

Carrefour is betting big on distributed ledger tech. The french supermarket behemoth wants to track 20 percent of all of its in-house products on the blockchain by the end of 2019. The retailer already uses the technology to track 20 out of its 300 Carrefour-branded products across the supply chain, but it plans to add about 40 more goods to the list over the coming months, Carrefour blockchain program director Emmanuel Delerm told Hard Fork.

2019-4-17 14:13


Coffee Board of India to Use Blockchain Distributed Ledger Tech for Supply Chain Improvements

Although India has been attacking virtual currencies during the last year, the country is ready to start using blockchain technology to improve the coffee supply chain. The Coffee Board of India has recently launched a new blockchain-based marketplace that aims at integrating coffee farmers and the markets. The information was released by the Indian Ministry […]

2019-3-29 03:20


Фото:

Australian Bank ANZ Still Doesn’t Understand Blockchain Technology

The Australia and New Zealand Banking Group Limited (ANZ) has thrown some serious shade at distributed ledger technology — commonly referred to as ‘the blockchain. ’  According to the third-largest bank by market capitalization in Australia, legacy financial institutions aren’t exactly under immediate threat from the trustless transactions introduced by Bitcoin (BTC) and its creator, Satoshi Nakamoto.

2019-3-25 04:00


Blockchain Being Studied by AirAsia Group Bhd For Operational Purposes

Blockchain Being Studied By AirAsia Group Bhd For Operational Purposes Blockchain technology has continued to find ways to be applied to various industries in the time that it has been around. Multiple banks, supply chains, and other management systems have found that the immutable ledger and consistent tracking of information benefit them greatly, so why […]

2019-3-17 23:44


Фото:

JPMorgan: Blockchain Technology Will Improve the Trade and Finance Sector

While the revolutionary distributed ledger technology (DLT) is slowly but steadily gaining traction in various sectors of the world economy including supply chain, healthcare, and others, American multinational investment bank, JPMorgan says it may take another “three to five years” before blockchain technology starts making meaningful impact on trade-finance, reported Bloomberg on January 29, 2019.

2019-2-1 19:00


UK’s British Standards Institution (BSI) and OriginTrail Partner to Increase Supply Chain Transparency Via Blockchain

British Standards Institution (BSI) Joins Forces with OriginTrail to Increase Transparency in the Supply Chain Via Blockchain Technology British Standards Institution (BSI), the body responsible for producing technical standards on a vast array of products and services in the United Kingdom, has allied with OriginTrail, a distributed ledger technology (DLT) firm to develop blockchain-based solutions […]

2019-1-24 21:45


Фото:

Hyperledger Launches Framework to Help Developers Deliver Blockchain-Based Supply Chain Solutions 

Hyperledger, a collaborative project focused on advancing cross-industry blockchain technologies, has announced the creation of Grid, a framework aimed at enhancing the development and delivery of distributed ledger technology (DLT)  powered solutions for the supply chain ecosystem, according to a press release on January 22, 2019.

2019-1-24 10:00