Ledger wallet vulnerability could compromise your cryptocurrency
Cryptocurrency hardware maker Ledger has acknowledged a report detailing a vulnerability in its product.
The issue was detailed in an anonymous report, which Ledger acknowledged in a tweet.
The vulnerability allows hackers to manipulate Ledger’s software by accessing the files on a device.
By manipulating these files, attackers can inject their own receive address onto the host machine, causing funds to be sent to an attacker.
Ledger wallets use JavaScript running on the host machine to generate new addresses for every receive transaction, and Ledger recommends users verify this address by making use of its built-in display feature.
It must be noted that this attack cannot compromise your private keys.
To mitigate the man in the middle attack vector reported here https://t.co/GFFVUOmlkk (affecting all hardware wallet vendors), always verify your receive address on the device’s screen by clicking on the “monitor button” pic.twitter.com/EMjZJu2NDh
— Ledger (@LedgerHQ) February 3, 2018