BTC $78,786.24 -1.13%
ETH $2,470.14 -0.39%
BNB $734.89 -1.46%
XRP $1.38 -1.92%
SOL $103.23 -2.36%
TRX $0.3337 -0.43%
DOGE $0.0889 +0.06%
ADA $0.2173 -0.02%
BCH $258.80 +1.39%
LINK $12.87 +5.32%
HYPE $85.13 -3.58%
AAVE $130.61 -2.30%
SUI $0.8016 +1.39%
XLM $0.1885 +2.57%
ZEC $1,147.26 -1.82%
BTC $78,786.24 -1.13%
ETH $2,470.14 -0.39%
BNB $734.89 -1.46%
XRP $1.38 -1.92%
SOL $103.23 -2.36%
TRX $0.3337 -0.43%
DOGE $0.0889 +0.06%
ADA $0.2173 -0.02%
BCH $258.80 +1.39%
LINK $12.87 +5.32%
HYPE $85.13 -3.58%
AAVE $130.61 -2.30%
SUI $0.8016 +1.39%
XLM $0.1885 +2.57%
ZEC $1,147.26 -1.82%

ledger

Ledger is a company focused on cryptocurrency hardware wallets, providing secure storage solutions to protect users' digital assets. Its products include the Ledger Nano S and Ledger Nano X, which support multiple cryptocurrencies and enhance security through offline storage of private keys. Ledger's devices are widely used by individual and institutional investors, aiming to prevent hacking and theft of digital assets.
All
Article
Flash

first_img Ripple has established a four-phase quantum-resistant migration plan for the XRP Ledger

Ayo Akinyele, Senior Director of Engineering at Ripple, stated that the company is developing a four-phase quantum-resistant migration plan for the XRP Ledger, aiming to complete the transition before quantum computers become a real threat. The plan includes assessing the network's exposure, testing quantum-resistant cryptographic solutions, running existing security systems in parallel with quantum-resistant alternatives, and preparing emergency response pathways for scenarios where quantum computing advances exceed expectations.Akinyele emphasized that migration is not just about replacing a cryptographic algorithm, but requires more flexible infrastructure, stronger key management, and clearer upgrade paths. The XRP Ledger has supported changing the keys that control accounts without altering the accounts themselves, a feature that is expected to reduce the difficulty of future migrations, but independent validators on the network still need to coordinate any broader rule changes.Meanwhile, Anthropic's model last month reduced the workload required to break leading post-quantum signature candidates by 67 million times, and Bitcoin and Ethereum developers also released their respective migration plans this week. Akinyele pointed out that AI and quantum computing are different technologies, but they are driving financial infrastructure to evolve in the same direction, as AI agents begin to trade and pay autonomously, raising new requirements for payment infrastructure that is always online and natively internet-based.

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

Ledger CTO responds to vulnerability FUD: The issue was fixed before it was disclosed, and users can safely use it by updating in a timely manner

Ledger's Chief Technology Officer Charles Guillemet stated that there has recently been "FUD" targeting Ledger in the market, as a smart contract security company claimed to have discovered vulnerabilities in the Ledger Ethereum application. Guillemet mentioned that there indeed were vulnerabilities related to certain Clear Signing processes in the Ledger Ethereum application, but these vulnerabilities were discovered by Ledger's security research team Donjon using AI-driven vulnerability research tools, and the fixes were completed and deployed two weeks ago. Users can obtain protection by timely updating their Ledger device firmware and applications.The relevant security company contacted Ledger's bug bounty program only after the fixes were completed, did not follow responsible disclosure processes, and did not communicate with the bug bounty team, yet implied in subsequent content that the issue had not been resolved. This approach is not true security research but rather a way to create panic for attention. AI is changing the cybersecurity landscape, and both attackers and defenders can enhance efficiency with AI, but AI-driven security research can only truly enhance the security of the entire ecosystem when basic security principles such as responsible disclosure and pre-release verification are followed.Guillemet finally reminded Ledger users to keep their device firmware, Ledger applications, and related software up to date to automatically receive the latest security fixes and research results. Users should not be influenced by the related "FUD" and should timely update their software and maintain safe habits.

XRP Ledger plans to launch a privacy transfer feature, targeting the over $530 million institutional-grade tokenized asset market

The latest software version 3.3.0 of the XRP Ledger (XRPL) introduces multiple upgrade proposals, among which the "Confidential Transfers" feature aims to provide higher privacy protection for institutional users, supporting the encryption of token balances and transfer amounts while maintaining visibility of account and token types. This feature is primarily targeted at Multi-Purpose Tokens (MPT) on the XRPL, with application scenarios including tokenized financial assets such as funds and bonds. Through cryptographic technologies like zero-knowledge proofs, the network can verify the validity of transactions without disclosing specific amounts.According to market news, the XRPL currently has approximately $1.38 billion in on-chain real-world assets (RWA), including about $845.7 million in RLUSD. In addition to RLUSD, there are over $530 million in tokenized assets on the XRPL, involving issuers such as Ondo, VERT Capital, Archax, and Société Générale. Besides Confidential Transfers, the XRPL 3.3.0 version also includes five proposals: Batch, Sponsor, Permission Delegation, and Dynamic MPT, which address institutional needs for batch transactions, fee payment, permission management, and dynamic adjustment of token attributes. However, these upgrades have not yet been officially launched and will need to gain over 80% support from trusted validation nodes on the XRPL for two consecutive weeks before activation. The market is paying attention to whether institutions like Aviva and Ondo, which have issued assets on the XRPL, will adopt this privacy feature.

Zilliqa Ledger application exposes serious vulnerability, signing 5 native transactions may leak private keys

Zilliqa stated that there is a serious random number generation vulnerability in the Zilliqa Ledger application, affecting the Schnorr signatures of native non-EVM Zilliqa transactions. Attackers can recover the signer's private key from the biased temporary random numbers using only publicly available on-chain data.Any account that has signed and broadcasted about 5 or more native transactions through the Zilliqa Ledger application should be considered compromised. Since the related signatures are permanently recorded on the chain, subsequent updates to the application cannot eliminate the risk, and the affected private keys must be deactivated. EVM transactions and development tools such as zilliqa-js, gozilliqa-sdk, and pyzil are not affected.The vulnerability arises from the application selecting the wrong 32 bytes when copying the random number, retaining 8 bytes of zero padding and losing 8 bytes of entropy, resulting in each random number having a maximum of 64 bits fixed to zero. Attackers can use 5 or more affected signatures to recover the private key within seconds using ordinary hardware. Zilliqa observed suspected active exploitation on July 19 and confirmed the root cause on July 21.Zilliqa has suspended native transactions to prevent further loss of funds and is preparing a revised application with Ledger. However, the revised version cannot protect the exposed keys, and affected users should not transfer assets on their own but wait for the official announcement of a coordinated disposal plan.
app_icon
ChainCatcher Building the Web3 world with innovations.