Bitcoin stolen from Ledger hardware wallets

Ouch. I would never trust a grey imported crypto hardware wallet. Yeah, supply-chain attacks, not even authorized, are all too secure.

I don't see how Ledger can do anything about this? It will hurt their reputation, but that is it.
 
This "wallet" misconception needs to change. The more we use the invalid analogy the more confusion abounds.

The heading should read Bitcoin stolen through compromised private key storage devices.
The bitcoin is not "offline" on the "wallet". The "wallet" is just a private key storage device. Compromise the private key and anyone can access your BTC from anywhere using that PK.
 
Companies that sell supposedly secure hardware should be liable for losses suffered by users if their technology isn't really as secure as they claim. At the end of the day, they are not selling a physical device, they are selling the idea that the device is secure, if it isn't then they have sold a lie, and that makes them accountable.
 
Companies that sell supposedly secure hardware should be liable for losses suffered by users if their technology isn't really as secure as they claim. At the end of the day, they are not selling a physical device, they are selling the idea that the device is secure, if it isn't then they have sold a lie, and that makes them accountable.
There is no such thing as a secure device. Prove me wrong.
 
I don't need to, companies that provide these 'secure' devices on the other hand do need to be held liable for selling the lie.
Says the man posting from an insecure device. :)
Do you do electronic banking from an iPhone or Android phone, knowing they're not 100% secure?
Are you going to blame the companies that supply the hardware and software when it's breached?
 
Last edited:
Says the man posting from an insecure device.
How about you stop trusting things instead of wearing blinkers?
Do you do electronic banking from an iPhone or Android phone, knowing they're not 100% secure?
Are you going to blame the companies that supply the hardware and software when it's breached?
Did someone do something nasty in your cereal this morning? - I am neither your wife, girlfriend nor friend, you want to be the big boy go try it with them. And yes any company that sells me a product which it claims is secure, and it isn't through no fault of my own is going to get sued for any loss I suffer due to their faulure.
 
Did someone do something nasty in your cereal this morning? - I am neither your wife, girlfriend nor friend, you want to be the big boy go try it with them. And yes any company that sells me a product which it claims is secure, and it isn't through no fault of my own is going to get sued for any loss I suffer due to their faulure.
You've probably just forgotten about the terms and conditions that you agreed to - or you didn't bother reading them. Sorry to break the bad news.
 
Last edited:
Did someone do something nasty in your cereal this morning? - I am neither your wife, girlfriend nor friend, you want to be the big boy go try it with them. And yes any company that sells me a product which it claims is secure, and it isn't through no fault of my own is going to get sued for any loss I suffer due to their faulure.

​


Limitation of Liability​

Except where prohibited by law, in no event will Apple be liable to you for any indirect, consequential, exemplary, incidental or punitive damages, including lost profits, even if Apple has been advised of the possibility of such damages.

If, notwithstanding the other provisions of these Terms of Use, Apple is found to be liable to you for any damage or loss which arises out of or is in any way connected with your use of the Site or any Content, Apple’s liability shall in no event exceed the greater of (1) the total of any subscription or similar fees with respect to any service or feature of or on the Site paid in the six months prior to the date of the initial claim made against Apple (but not including the purchase price for any Apple hardware or software products or any AppleCare or similar support program), or (2) US$100.00. Some jurisdictions do not allow limitations of liability, so the foregoing limitation may not apply to you.

Indemnity​

You agree to indemnify and hold Apple, its officers, directors, shareholders, predecessors, successors in interest, employees, agents, subsidiaries and affiliates, harmless from any demands, loss, liability, claims or expenses (including attorneys’ fees), made against Apple by any third party due to or arising out of or in connection with your use of the Site.



LIMITATION OF LIABILITY

EXCEPT AS PROVIDED IN THIS WARRANTY AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, APPLE IS NOT RESPONSIBLE FOR DIRECT, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES RESULTING FROM ANY BREACH OF WARRANTY OR CONDITION, OR UNDER ANY OTHER LEGAL THEORY, INCLUDING BUT NOT LIMITED TO LOSS OF USE; LOSS OF REVENUE; LOSS OF ACTUAL OR ANTICIPATED PROFITS (INCLUDING LOSS OF PROFITS ON CONTRACTS); LOSS OF THE USE OF MONEY; LOSS OF ANTICIPATED SAVINGS; LOSS OF BUSINESS; LOSS OF OPPORTUNITY; LOSS OF GOODWILL; LOSS OF REPUTATION; LOSS OF, DAMAGE TO, COMPROMISE OR CORRUPTION OF DATA; OR ANY INDIRECT OR CONSEQUENTIAL LOSS OR DAMAGE HOWSOEVER CAUSED INCLUDING THE REPLACEMENT OF EQUIPMENT AND PROPERTY, ANY COSTS OF RECOVERING, PROGRAMMING, OR REPRODUCING ANY PROGRAM OR DATA STORED IN OR USED WITH THE APPLE PRODUCT OR ANY FAILURE TO MAINTAIN THE CONFIDENTIALITY OF INFORMATION STORED ON THE APPLE PRODUCT.
 
And yes any company that sells me a product which it claims is secure, and it isn't through no fault of my own is going to get sued for any loss I suffer due to their faulure.

Ignoring the terms for a moment: yes, a company that sells a device through official channels can carry liability if it causes the user a loss. That gets murkier when a bad actor, through no fault* of the company, tampers with the device. Think of a third party implanting hardware in it. There have been reports of devices sold on marketplaces like Amazon with extra hardware inside. Just look at how small this 2.2mm eSIM is!

Bitcoin stolen from Ledger hardware wallets

Crypto hardware wallet manufacturer Ledger is investigating a suspected supply-chain attack on devices sold by a specific vendor.

The real story here is likely this claim:

*That said, if the company didn’t have sufficient safeguards against upstream hardware supply-chain attacks, or if an authorised reseller like Cryptobilis had a corporate takeover that muddied who was actually selling the Ledger units, then I can see an argument that the company carries some liability too.
 
Top
Sign up to the MyBroadband newsletter
X