Ledger Probes Reported $86M Theft Tied to Reseller Wallets
The investigation puts reseller channels and hardware-wallet supply chains under scrutiny, though the reported theft remains potential, not confirmed.
Every Zipp story tagged #Ledger, newest first.
The investigation puts reseller channels and hardware-wallet supply chains under scrutiny, though the reported theft remains potential, not confirmed.
The losses remain unconfirmed and the cause is unknown, but Ledger has urged some recent buyers not to set up their devices and to move assets if already activated.
The suspected supply-chain attack has not been confirmed, and Ledger says there is no evidence its hardware or core infrastructure was directly compromised.
The reported losses remain unverified, but Ledger's advice to pause setup and move funds highlights the security risk of devices obtained through untrusted channels.
The warning puts reseller provenance at the center of hardware-wallet security, with Ledger advising affected buyers not to initialize their devices.
Ledger merged the fix for one bug on May 5 and the other on May 25. They shipped in August. The gap between merge and release is the uncomfortable read for hardware-wallet customers.
The 683M ZIL figure gets the headline, but the seven-year survival of the bug inside a Ledger-signed application is the real read for any token still relying on native hardware-wallet signing.
A seven-year-old flaw in XRP Ledger's signature library would have let an attacker derive a private key from as few as five signed transactions, putting wallets at risk before maintainers patched it.
The flaw lets private keys be recovered from any affected onchain signature; EVM transactions and SDKs are unaffected, narrowing the blast radius.
A nonce-reuse bug in the Zilliqa Ledger app let attackers reconstruct private keys from roughly five native signatures, and Upbit's cautionary-asset designation now puts ZIL trading support itself in…
Transaction sign-off stays on a physical device, so an autonomous agent can read balances and draft swaps but can never broadcast one without a human tap.
The open-source toolkit lets AI agents read balances and prepare transactions, but every sensitive action still needs physical approval on a Ledger device.
The on-chain investigator singled out Ledger and pitched an iPhone-as-signer workaround, reigniting a long-running debate over whether hardware wallets actually keep self-custody safe.
The onchain investigator argues current hardware wallets aren't fit for signing critical transactions or storing large balances, and floated a dedicated iPhone as a stronger alternative.
Both vendors agree the bug is real on a lab bench; Tangem argues it stays academic because resetting the PIN needs a laser, the card in hand, and rare know-how.
Eric Larchevêque frames a seven-figure BTC not as a victory lap for the asset, but as a tell that the world around it has broken.
Ledger's security research team has disclosed a vulnerability in the chip used by Trezor's Safe 7 hardware wallet…
The vulnerability lives on a single chip inside Trezor's new Safe 7, but the device's multi-layer architecture means attackers would still need physical access, lab equipment and deep expertise —…
The $4B-valuation deal the company lined up with Goldman, Jefferies, and Barclays in January is now on ice, with insiders flagging private fundraising as the alternative path.
No S-1 was ever filed, the banks were never paid to push through, and the $4B valuation Ledger explored in January is now sitting on the shelf alongside Kraken's shelved listing — the IPO market for…