Ledger, a cryptocurrency wallet maker, claims to offer highly secure hardware wallets for storing cryptocurrencies. However, a 15-year-old programmer, Saleem Rashid, managed to hack the Ledger Nano S.
In a post, Rashid discussed the vulnerabilities of Ledger's hardware wallet, worth $100, caused by the use of custom architecture.
He explained that a flaw in the digital wallet allows hackers to steal private keys before or even after acquiring the device.
Physical access before seed setup
In this scenario, called “supply chain attack”, a hacker can modify the generated recovery seeds. Since all private keys originate from these recovery seeds, stealing the funds that have been loaded onto the device becomes easy.
Physical access after setup
This method is known as “Evil Maid Attack”, which allows an attacker to extract PIN, recovery seed and any BIP-39 passphrases that are used if the device has been used at least once after the attack.
Malware in combination with social engineering
Here, the user is prompted to update the MCU firmware on an infected computer. Upon confirming the update, the malicious software infects the MCU with malicious code and takes control of the screen and confirmation buttons.
After the disclosure of these security vulnerabilities, Ledger released a firmware update version 1.4.1 on March 20. This updated version fixes a total of three security issues, including those highlighted by Rashid.
Also, the company assured that the update will “verify the integrity of your device” and that a successful update means that “your device has not been targeted by any of the attacks for which patches were created”.
Although these updates brought some relief to Ledger users, the question remains about the company's claims that its digital wallets are 100% secure.
