In 2023 we learned ledger can extract your key from the device and has now been compromised.

Reply to this note

Please Login to reply.

Discussion

major key alert

I’m not sure what to do. I have an air gapped Ledger that hasn’t been updated with a substantial amount of currency on it. I could wait for the storm to clear, try to move it to another device hastily….experience has taught me that hasty shifts to unproven technology is not a recipe for success in the crypto space. #ledger #bitcoin

If you have the seed phrase you could just import into a better hardware wallet

This

You suggest what as a better hardware wallet?

Jade or coldcard

Jade

Or Bitkey ;)

Do your own research but I like the Blockstream Jade.

https://blockstream.com/jade/

I have not studied the issue, been too busy, but I think there have been a few broadcasts on it.

I totally agree, stay calm, keep it air.

In time, set up a cold card or jade, air gapped.

I appreciate you. 🤘🏻

*keep it air gapped

🫂

🫂

Don't rush and make mistakes. Take your time and do it right. I would also generate a new seed phrase. Who knows if ledger already has your current one somewhere on a server.

Solid advice. It’s been gapped for a while. I think limiting the exposure time is a fairly solid way of protecting assets too. I’ll connect, and immediately transfer. Hopefully when the fees aren’t so damn high!

I wouldn't connect at all. Import the seed phrase into a different wallet first, doesnt really matter which one. Then from there send it to a better wallet like jade or coldcard.

Triage then repair.

I wouldn’t connect at all if there’s any chance of a compromise/issue. In the digital space you can get rekt at the speed of light. Don’t assume you can fly under the radar by going quickly. Malicious code will always outpace you.

Excellent point, and duly noted. Thank you.

Also if that is the case, nothing I do will matter. The battle is already likely lost.

I believe that is the case if you updated to the resent firmware. I believe it does ask you if you want to participate or not in the online backup crap. That's the major concern for everyone. Could it have nabbed your keys whether you agreed or not, possibly.

I also think for those that do not update firmware they are fine in that current state. Those that updated may or may not be fine. Those that chose the online key backup, did you really think that was a good idea?

Those that uploaded their keys, I wouldn't think a new wallet would help.

I'm nobody but thinking out loud.

Wow really