Ledger Probes Reported $86M Theft Tied to Reseller Wallets
The investigation puts reseller channels and hardware-wallet supply chains under scrutiny, though the reported theft remains potential, not confirmed.
Every Zipp story tagged #WalletSecurity, newest first.
The investigation puts reseller channels and hardware-wallet supply chains under scrutiny, though the reported theft remains potential, not confirmed.
The suspected supply-chain attack has not been confirmed, and Ledger says there is no evidence its hardware or core infrastructure was directly compromised.
The cryptography is solvable; the coordination is not. Migrating millions of wallets and nodes across decentralized networks needs years of technical and governance work, and quantum capability is…
No practical attack has been demonstrated, but researchers say exposed public keys could become a target before Ethereum's planned 2029 shift to quantum-resistant cryptography.
Rising Treasury yields and renewed rate-hike expectations add pressure as traders debate how urgently wallets must prepare for advances in AI-driven mathematics.
The warning puts key management and migration planning on the agenda before quantum computers become a practical threat.
The proposal centers on moving assets to fresh addresses whose public keys remain hidden behind hashes, with large holders prioritized.
The debate highlights a difficult security trade-off: prepare for advances in cryptography without exposing holders to losses from rushed transfers or misconfigured upgrades.
The warning challenges the assumption that quantum computers will be the first technology to threaten elliptic-curve cryptography, but no practical attack has been demonstrated.
The stolen holdings included BP, MARSCOIN and CASHCAT, which the attacker swapped into ETH, BNB and SOL before laundering the funds.
The safeguard closes a gap between keeping private keys secure and ensuring a signature actually authorizes the recipient a user approved.
The risk concentrates in BIP39-seed, xprv-import, and 4.0.x Electrum wallets. The remedy is a fresh export, since upgrading the software does not recover key material already lost with old backups.
The draft would give wallet developers a benchmark for checking ECDSA signers, but a matching signature would not prove a device is safe.
The precaution affects non-custodial staking operations; MetaMask says it does not hold clients' withdrawal keys.
MetaMask says wallets face no immediate threat, but it is taking precautions in its staking operations.
Apple said the flaw may have been exploited in sophisticated attacks against specific targets, putting users on older iOS versions in focus.
The breach shifts scrutiny from initial access to incident response: Bitget’s own systems flagged unauthorized transfers before the largest losses began.
The draft targets wallet metadata that seed phrases cannot recover, but an exposed eligible xpub could also unlock the encrypted backup and reveal its script structure.
GoPlus says the attackers forged transaction data inside a compromised wallet backend, making Bitget's own authorized signing system generate valid signatures for $387.5M in unauthorized transfers.
Closing the marketplace did not cancel onchain permissions, so former users may still need to revoke access to protect assets held in approved wallets.