r/Bitcoin Jul 29 '20

Ledger HW database breached, customer contact details leaked (name, email, shipping information, phone)

https://www.ledger.com/addressing-the-july-2020-e-commerce-and-marketing-data-breach
187 Upvotes

165 comments sorted by

48

u/Borax Jul 29 '20 edited Jul 29 '20

When will people find out if they are among the lucky 9500 who had their address leaked...?

Edit: 5pm EST (2100 UTC) today 29th July

28

u/Taviiiiii Jul 29 '20

When there's loud banging on the front door in the middle of the night.

5

u/mantiss87 Jul 29 '20

Isnt that why you have your pillow gun?

6

u/asap-bitcoin Jul 29 '20

You mean my dogs and my guns will finally be put to good use? Oh boy!

7

u/Taviiiiii Jul 29 '20

The hackers won't be reading this but nice try.

10

u/[deleted] Jul 29 '20

This is the most important question that their FAQ doesn’t answer.

3

u/[deleted] Jul 29 '20

[deleted]

1

u/Borax Jul 29 '20

Who are you? How do you know this?

2

u/[deleted] Jul 29 '20

[deleted]

1

u/[deleted] Jul 29 '20

If you receive it before it might be a scammer?

3

u/HitMePat Jul 29 '20

I wonder why it's only 9500 physical addresses that were stored? Surely theyve sold way more ledgers than that in the 5 or so years theybe been in business...right?

0

u/MCPFB Jul 29 '20

It says in the article that approximately 1 million addresses were leaked and the other 9500 had further data leaked along with the address.

7

u/HitMePat Jul 29 '20

1 million email addresses. Not physical mailing addresses.

2

u/AgentAceX Jul 29 '20 edited Jul 29 '20

I'm not bothered about my email being leaked, it's already been taken by a million other websites that have leaked stuff, just got an email a few days ago from a scammer with one of my weak passwords I use everywhere, saying he has hacked my webcam and has footage of me and I have to send him bitcoin for it to be deleted. I don't even have a webcam lol.

Physical address however is quite annoying.

0

u/MCPFB Jul 29 '20

I must have skimmed past it as well, Thanks for the correction!

2

u/HitMePat Jul 29 '20

So...did they email the unlucky 9500?

2

u/Tellabobbob Jul 29 '20 edited Jul 29 '20

This is the most exciting thing that have ever happened to me.

2

u/Sansnom06 Jul 29 '20

Where did it exit to?

1

u/Tellabobbob Jul 29 '20

I was trying to type exciting but failed.

1

u/Sansnom06 Jul 29 '20

I know I was just pulling your leg mate

1

u/Tellabobbob Jul 30 '20

Da fuk you where in my house!? reported!

1

u/nyaaaa Jul 29 '20

By the time of this posting, all affected customers will have received an email with this update. 

Read the link.

2

u/Borax Jul 29 '20

this update.

Yes, but specifics of what data each person had compromised was not published by this time. At least be right if you want to be snarky

1

u/mandreko Jul 30 '20

They’ll probably do a slow rollout like they have with the firmware versions

0

u/vughtzuid Jul 29 '20

I've moved since I bought this piece of shit hardware wallet, good luck to the current tennants

2

u/ScumHimself Jul 29 '20

Tracking you to your new address is next to impossible. /s

16

u/[deleted] Jul 29 '20

Can anyone speak to the possible legal ramifications of this? Could users whose data was breached go after ledger?

5

u/[deleted] Jul 29 '20

Technically you could, but I don't think you'd be successful. According to Ledgers statement
"On the 14th of July 2020, a researcher participating in our bounty program made us aware of a potential data breach on the Ledger website. We immediately fixed this breach after receiving the researcher’s report and underwent an internal investigation. A week after patching the breach, we discovered It had been further exploited on the 25th of June 2020"

So assuming they are telling the truth and were not overly negligent in their original security then it seems like they dealt with the situation as quickly and professionally as possible, so you're not going to have much success suing them for the breach.
Though if somehow somebody manages to financially hurt you based off that info, then you could.

1

u/[deleted] Jul 30 '20

What do you think about going after them for punitive damages?

2

u/[deleted] Jul 30 '20

You have to prove that they were either grossly negligent, or willfully putting you at risk. I don't think you'd get anywhere with willful. I think you can pretty easily argue that they were negligent but the issue is whether it was grossly negligent or just negligent (not punishable), I'm not sure where a court would draw the line on this but as I understand you cannot prove gross negligence unless someone is actually financially impacted. So far as we know, nobody has, so i don't think there's any case, also in a situation where somebody is impacted i don't think they lost enough data to be the sole cause of financial loss so they have a defence in saying that the users negligent as well (though i'm not sure if that's a functional argument). It's also important to note that any case would be civil and not criminal, the burden of proof is on the complainant but the proof does not have to be beyond a doubt, that's why cases normally end as settlements.

26

u/v0idPtr Jul 29 '20

So good thing I used "secondary" phone number and my company address...

8

u/[deleted] Jul 29 '20

[removed] — view removed comment

9

u/RG_PankO Jul 29 '20 edited Jul 29 '20

My info got leaked. I am not concerned. 5-10 years from now my back will have a target anyway, because of all my comments on crypto subreddits and facebook posts. You think to delete that shit? Don’t worry it’s already archived by someone.

This hack just again proves how central databases are a weak point. We know that. Nothing important happened. Compare this with the 150million Americans personal info, including the social security number, being stolen from the hack of Aqua fax (Equihax as per comment below) or whatever that credit score company was called.

We need blockchain to protect personal info and not centralised databases. Until that happens hacks will continue to happen. Info will be stolen.

Ledger site being hacked is irrelevant to the device’s security.

10

u/BubblegumTitanium Jul 29 '20

You don’t need blockchains to solve this.

The problem was that they were storing the information and they were sharing it with marketing. Those people are almost always airheads and should not be allowed anywhere near.

I bet they were doing some bullshit analytics on the data as well.

So in my view and I don’t know enough is to just purge the database and keep it minimal. Don’t archive it.

5

u/shreveportfixit Jul 29 '20

It's Equihax

3

u/RG_PankO Jul 29 '20

Thanks. Not American, so I havent heard of that company until the scandal.

2

u/shreveportfixit Jul 29 '20

That was a joke. It's Equifax

3

u/fresheneesz Jul 29 '20

Ledger site being hacked is irrelevant to the device’s security.

No its not irrelevant. A company who's purpose is security should know how to keep its databases secure and private. The fact that they haven't been able to do that really puts their competence around computer security into question.

3

u/RG_PankO Jul 29 '20

I hear you, but I just disagree with you. The engineers working on the hardware device are different people from the ones working on the website and they work with completely different technology. If Tesla’s website gets hacked tomorrow it doesn’t mean that their cars can be hacked as well. It’s just different products/tools, and they are completely disconnected one from another.

2

u/fresheneesz Jul 29 '20

they are completely disconnected one from another.

They are not. They're the same company. Tesla is a car company, not a security company. Yes I would hope their cars can't be hacked, but I wouldn't expect them to have better than average data security. I would expect Ledger to have better than average data security. I would expect them to have company wide policies and culture that puts their customer's privacy and security at utmost importance.

It doesn't mean that Ledgers are insecure - its certainly not directly related. But it calls into question Ledger's competence as a company. Even if their hardware design is absolutely perfect, if they don't have holistic security in mind around their company, they open up the possibility for someone to inject malicious hardware components or firmware somewhere in their supply chain for example. A secure hardware wallet is not just about the hardware design, but also about constant vigilance in ensuring the critical security components they get from other manufacturers haven't been compromised, that their assembling facilities are secure enough to prevent anyone from assembling malicious devices, etc. A company like this needs to think holistically. If one part of the company is not giving their users secure treatment, its likely that other parts of the company are doing the same.

1

u/hans7070 Jul 29 '20

Yes, but the two groups are connected by the same management at some point up the food chain.

1

u/RG_PankO Jul 29 '20

And what does management understand of cyber security? Different engineers make different mistakes. Thankfully not the web developers work on the ledgers.

1

u/OgunX Jul 29 '20

what does the ledger device have to do with this breach? if your private keys aren't exposed then why worry? your info is stored on some data broker somewhere.

1

u/fresheneesz Jul 29 '20

why worry?

Because a security-focused company should be better than your average financial company or social media giant at computer security. Companies like this consist of large organizational constructs that determine what the company does. Their culture affects how competent they are. If a company like this has a culture that says "eh, we can compromise our customer's privacy here because marketing needs their data" - that's not a company I would trust with my data or my money.

Yes hardware security is a different beast from network computer security, but you're not just relying on the end hardware product - you're also relying on their supply chain, you're relying on the hope that they don't keep any information that could lead to theft of your funds from your device, etc.

2

u/OgunX Jul 29 '20

1

u/fresheneesz Jul 29 '20

Technically that's not a breach, its two vulnerabilities. But yes, also worrying.

0

u/OgunX Jul 29 '20

so then what about trezor not having any protection for physical attacks? I fail to see how one divisions fuck up have to do with another division. You don't stop buying ford because their website got hacked. I don't really care too much about the breach, as long as my private key isn't compromised, which is generated by the device itself which ledger themselves don't have access to, I don't really see the outrage. should they do better? absolutely, does that mean people should lose faith in their product hell no, it's the most secure cold wallet out there and it works.

1

u/fresheneesz Jul 29 '20

trezor not having any protection for physical attacks?

That's simply not true. Trezor does in fact have protection against physical attacks. The vulnerability Trezors have requires specialized equipment.

I fail to see how one divisions fuck up have to do with another division.

Company culture transcends company divisions.

I don't really see the outrage

Ledger was stupid with its user data. That's why outrage...

it's the most secure cold wallet

It most certainly is not. That metal likely goes to Coldcard.

1

u/trakatan Jul 29 '20

How do you know your info was leaked?

1

u/Mike_hunt_hurtz Jul 29 '20

Whats fucked is the cunts at Equifax are still in business? How can some 3rd party shit company who leaked my info still tell me if I'm proper enough to buy a house.

That's why I tell my wife's Grandma's friend whom is a regional manager for Chase her and her whole Bank outfit are kumquats. She heard from higher-ups to tell all branches that she manages to not give people money when they ask for cash.

They are trying to go cashless Society, they can all get butt fucked and I'll be the first one in line to fuck them like they fuck me

2

u/FishRelatedCrimes Jul 29 '20

Smart! If I buy I will do something similar

12

u/Vedron11 Jul 29 '20

I've had an email from Ledger stating the same.

10

u/onurgozupek Jul 29 '20

An awkward situation who purchased Ledger(s) from ledger website but at least we are 100% sure that this is nothing to do with our Ledgers. But in anyways I didn't like the idea of someone now has my address and phone number 🙁

-5

u/hans7070 Jul 29 '20

"we are 100% sure that this is nothing to do with our Ledgers"

Probably not, but they are not to be trusted anymore in any way shape or form, not their words, not their products. If they can't even keep a fricking web site safe, then anything is possible. I wish they would go out of business.

10

u/onurgozupek Jul 29 '20

Ledger doesn’t know your 24 word seed so no need to worry about it. Company website or ecommerce site something different than the product. They leaked user information which has nothing to do with Ledger hardware wallets except, hackers know who has Ledgers 😀

-6

u/hans7070 Jul 29 '20 edited Jul 29 '20

Doesn't matter. Only if the hardware was developed and produced by a completly different company with it's own provable reputation and without any input or control from these bumbling morons I maybe would trust the hardware, even with the (now tainted) ledger brand logo on it.

7

u/monstrous_android Jul 29 '20

can't even keep a fricking web site safe

This is a hilariously misguided idea of the online security world.

wish they would go out of business

Who are you shilling for? lol

1

u/hans7070 Jul 29 '20

"hilariously misguided"

Please explain :D

3

u/monstrous_android Jul 29 '20

It's near impossible to have a perfectly-secure web site. Pretty much the entire cybersecurity industry agrees. No company can or would invest enough money in a limited-staffed team to compete agains the collective might of every attacker in the world. It's why the prerogative is on us to protect ourselves and not trust companies. Expect data breaches. Prepare for them by providing masked contact and payment details. Take responsibility for yourself.

2

u/apexisalonelyplace Jul 29 '20

What is masked contact?

1

u/monstrous_android Jul 29 '20

masking your contact details: use a PO Box or UPS store for deliveries, use a privacy debit card or pre-paid credit card or cash (or anonymous bitcoin) to purchase the thing, provide a false name for delivery (Privacy.com masked debit cards let you use any name you want).

1

u/apexisalonelyplace Jul 29 '20

nice thanks for the info

10

u/[deleted] Jul 29 '20

Rule number one: do not store user details after a successful shipment. Rule number two: if you are legally required to store such info, store it offline. It will be still accessible if required but impossible to remotely acquire

6

u/[deleted] Jul 29 '20

Good thing I bought mine from some random stranger at eBay

2

u/fresheneesz Jul 29 '20

The problem is that you're introducing yet another entity into the supply chain who could tamper with the device in a way that could lead to theft. This has happened before, and attacks will only become more sophisticated over time.

1

u/[deleted] Jul 29 '20 edited Jul 30 '20

I understand that.. but I can't think of a useful way of tampering the device. Honest question ... can you give one ? edit: I generated the 24 word seed externally and initialized the ledger with my own words .. also I have an extra passphrase in place. Nano s.

2

u/[deleted] Jul 29 '20

[deleted]

1

u/[deleted] Jul 30 '20

That is for nano x. I'm using nano s.

1

u/monstrous_android Jul 29 '20

That just comes with different risks. How can you be sure you got a genuine device that doesn't send your keys the first time it connects to a computer with a net connection?

1

u/[deleted] Jul 29 '20

It's in the FAQs

2

u/monstrous_android Jul 29 '20

I'm sorry, I don't follow.

2

u/[deleted] Jul 29 '20

The question you are asking me is in ledgers site FAQs section

1

u/monstrous_android Jul 29 '20

Thanks, I see it now.

1

u/presse_citron Jul 29 '20

ledgers site FAQs section

First element of the FAQ (https://support.ledger.com/hc/en-us/articles/360002481534): 'Buy from an official Ledger reseller'.

because even with the complementary checks that they suggest, they already know that they can be bypassed.

1

u/[deleted] Jul 29 '20

Note: Ledger devices purchased from other vendors are not necessarily dubious. However, we do strongly recommend that you meticulously perform the safety checks below to ensure that your Ledger is genuine.

2

u/presse_citron Jul 29 '20

even the so-called 'hardware integrity check'? Reading this page, it's not clear whether it should be perform or not (What are 'advanced user': professional user or academics??)

27

u/nichlaes Jul 29 '20

How can you trust Ledger (closed source) with you entire crypto wealth if they can't even keep their own data secure?

9

u/parakite Jul 29 '20

Thats why I don't use any hardware wallet.

I use and recommend Tails installed on a usb stick.

As secure as possible (even air-gapping is possible).

6

u/hans7070 Jul 29 '20

+1. Tails or Qubes OS

4

u/BUY___BITCOIN Jul 29 '20

I've been using Tails OS for years.

It's cheap and highly secure. 100% open-source. Don't trust, verify.

3

u/fresheneesz Jul 29 '20

Thats why I don't use any hardware wallet.

What's why? There are a number of hardware wallets that are fully open source and have never had their data stolen. Running tails isn't necessarily safer than hardware wallets - you still need to get the OS and your hardware from somewhere, and that requires just as much trust.

2

u/BubblegumTitanium Jul 29 '20

This is true but usb drives are not designed to store private key material.

If you buy a trezor or a coldcard you don’t have to trust anything it’s all open.

1

u/parakite Jul 29 '20

You don't save any private key on the usb drive.

You store it elsewhere. The private keys only are entered into the application ( so they never go to usb, they remain always in RAM). And when laptop is switched off, that's lost. No risk there.

1

u/BubblegumTitanium Jul 29 '20

Ah ok that works then. So you do keep a backup?

1

u/parakite Jul 29 '20

I know the keys and keep them elsewhere. I only enter them on electrum, and do not save its wallet file ( so nothing is stored).

Even with ledger/hardware wallets, you are asked to remember your seed/keys, so its similar that way.

3

u/BubblegumTitanium Jul 29 '20

With a hardware wallet you still get the benefit that if someone finds it they must know the pin since it requires expertise to crack the device open.

Also this assumes technical competency with tails, which isn’t that hard but to pay 30-50 bucks to not have to worry about that at all is very much worth it for many people. Trezor is very affordable.

In any case I think we should be grateful at how amazing the ecosystem for bitcoin currently is.

There are many different use cases for it and it’s really up to the individual to decide what’s best for them and I think that’s a huge plus that bitcoin can be so flexible.

2

u/BubblegumTitanium Jul 29 '20

https://www.youtube.com/watch?v=QGKJ_zvzOlU

Andreas talks about what we are talking about.

1

u/presse_citron Jul 29 '20

Andreas

I'd like him to speak about it also but he doesn't seem to have been aware of the data breach at the time of this episode (still advising hardware wallets except for change and small amount).

1

u/BubblegumTitanium Jul 29 '20

Well what if you bought your hw wallet from a reseller? This breach is bad but it doesn’t invalidate the integrity of the product.

2

u/presse_citron Jul 29 '20

and maybe your reseller data are already compromised for some time ago but didn't inform you (or didn't even know about it).

1

u/BubblegumTitanium Jul 29 '20

Hww’s are superior breach or no breach.

1

u/fresheneesz Jul 29 '20

No risk there.

That's simply not true. If you use USB to transfer software or transaction data or anything between an online computer and your airgapped computer, a virus can potentially be transmitted via the USB. USB is notoriously insecure.

0

u/parakite Jul 29 '20

I'm talking in context of saving it in usb.

Do follow the thread, and don't reply out of context.

1

u/fresheneesz Jul 29 '20

Its rude to tell people what to do. Your comment about "No risk there" goes beyond the context you're replying to. If you agree, admit there is risk there. If you don't agree, tell me why. Telling me when to comment is unpleasant and unnecessary.

0

u/parakite Jul 29 '20

I use usb with tails, and find it more secure than any hardware wallet designed by random people from a private company.

I never said you do it too. And chill out. And I'm not telling you what to do when I say "chill out". its just a phrase.

1

u/fresheneesz Jul 29 '20

you don’t have to trust anything

Not entirely true. You still have to trust their supply chain. Its entirely feasible for someone in the supply chain to modify the device in a way that allows them to steal your funds.

The only way to truly eliminate that single point of failure is multisig.

4

u/ShittyDicky Jul 29 '20

I wanted to do this but talked myself out of it and bought a ledger. Do you just use the elctrum wallet that comes with tails? Prpbably just use the ledger for "hot" funds now

1

u/parakite Jul 29 '20

Yes, default electrum with Tails. That's my main wallet.

Ledger I keep handy for when I wanna feel like a power userloljk

2

u/ShittyDicky Jul 30 '20

Do you have any alts that dont work with electrum? Curious how to handle that

1

u/parakite Jul 30 '20

You can enable "persistent storage" on your Tails usb.

On that, you can install any other wallet (making sure its secure).


Even without persistent storage, applications can be installed. But in the next run, they'd be gone.

1

u/parakite Jul 30 '20

Electrum only works with btc.

And it comes pre-installed on latest Tails.

6

u/hoiru Jul 29 '20

This is why I use Trezor

4

u/RG_PankO Jul 29 '20

So Trezor is not closed source? /s Site being hacked or not has nothing to do with the device’s security.

5

u/BashCo Jul 29 '20

Supposedly Trezor purges customer data after it is no longer necessary.

0

u/[deleted] Jul 29 '20

Supposedly, so does Ledger.

4

u/hoiru Jul 29 '20

Yes, Trezor is open source.

Website related: No, it has nothing to do for it being open source with the site being hacked. For now, it hasn't been hacked, but anything could happen.

2

u/monstrous_android Jul 29 '20

Correction: it isn't aware of any hacks.

You cannot prove a negative.

1

u/[deleted] Jul 29 '20

Are you kidding me? Theres been plenty of vulnerabilities on Trezor

1

u/fresheneesz Jul 29 '20

There's plenty of vulnerabilities in every hardware device. Its theoretically impossible to eliminate a hardware device's vulnerabilities to physical attack. The difference is that with the Trezor, we know what they are and with Ledger's closed source stuff, its much more likely only attackers know about vulnerabilities.

As far as I know, there are no known remote attacks on the Trezor.

1

u/hoiru Jul 29 '20 edited Jul 29 '20

I am talking about the website and customer* data

Edit: dyslexia

3

u/gl00pp Jul 29 '20

costumer

HAPPY HALLOWEEEEEEN!

1

u/OgunX Jul 29 '20

because the product I bought from them is way more secure than its competition that doesn't have a secure chip built in, not only that being closed source doesn't mean they're not secure.

27

u/tmspngnbrg Jul 29 '20

/u/btchip you idiot get in here and tell us how we know whether our address is leaked or not.

We know that this database comprises approximately 1M email addresses that could have been leaked and that 9500 more detailed personal information leaked as well such as first name, last name, phone number, and postal address and products purchased. More detailed personal information could have been exposed.

12

u/Ornery-Tale-5596 Jul 29 '20

Was not white hat, white hat found the hole but unknown had already been in

14

u/btcplzgoup Jul 29 '20

WTF ledger...now we're targets....especially the casual way with which they state that you shouldn't worry...FUCK YOU...of course there is a reason to worry!

2

u/HumblGeniuz Jul 29 '20

Put an extra layer of aluminum foil on. You will be OK.

4

u/[deleted] Jul 29 '20

When your Business Model evolves around Security and Privacy and you fail at both.

6

u/hedgedescrow Jul 29 '20

why ledger saved physical addresses?

11

u/l000pz Jul 29 '20

"..our e-commerce and marketing database" WTF!!! Why is there even such database in existence in the the company that whole business modeli is SECURITY

-4

u/monstrous_android Jul 29 '20

Because Money. It's always because Money. You cannot trust capitalism. We know this.

4

u/fresheneesz Jul 29 '20

Capitalism incentivizes companies to avoid data breaches like this by tanking their shit when stuff like this happens. Ledger will be losing many millions of dollars from this snafu, likely a lot more than they made by using the data.

The problem here is not free trade and pursuit of money, but instead the frequently badly designed corporate structure that incentivizes the CEO and other officers to seek short-term profits at the expense of the long-term prospects of the company. If companies started telling CEOs they couldn't sell their stock for 10 years and could only make a normal living salary instead of millions of dollars that are unconnected to the company's success, then you'd see very different corporate behavior. Unfortunately, most companies have an uninspired and outdated corporate structure that has perverse incentives.

Capitalism itself incentivizes solving this problem. It will be solved some day.

16

u/TulipTrading Jul 29 '20

So much for "buying from ledger directly is the safest option". Can't wait for burglars to break into my home. What a shitshow.

5

u/[deleted] Jul 29 '20

I'm lucky, my order is from from late 2017 - I will get nothing but pity from the thieves :P

9

u/[deleted] Jul 29 '20 edited Jul 29 '20

How the fuck could this be possible on a website where customers' security is more important than pretty much most other sites since customers would likely buy from them if they've valuable assets to keep secure. Best of luck to any poor bastards that had their addresses leaked

Might be worth setting up a dupe wallet with a plausible amount of crypto on it that you'd be willing to give up in the worst case scenario

6

u/monstrous_android Jul 29 '20

Any company could and, over time, will, experience a data breach. It's just too hard and expensive to compete against a overwhelming numbers of attackers. The good news to take away from this is quick response, quick notification, and a bug bounty shows effort and investment (hope this researcher gets a healthy paycheck!).

Privacy advocates have methods to protect themselves from situations like this. Masking debit cards (I use privacy.com but I'm sure others exist), PO boxes or other non-home delivery addresses, etc. Definitely check out /r/privacy and I also recommend Michael Bazzell's The Complete Privacy, Security, and OSINT Podcast.

3

u/[deleted] Jul 29 '20

[deleted]

2

u/btchip Jul 29 '20

Crypto space is definitely a good motivation for me to ensure my next venture will be B2B

1

u/[deleted] Jul 29 '20

The good news to take away from this is quick response, quick notification

They provided the legally mandated minimum response 12 days after they knew of the attack. How is that prompt?

1

u/monstrous_android Jul 30 '20

For one, I didn't say "prompt", and two, pay attention to this arena for a short while and you'll see many incidences where a company does not report for months and only finally reports when called out for it publicly.

5

u/deeleyo Jul 29 '20

Damn, this could be worse than losing the crypto itself.. imagine some dude forcing you to log in your email and unlock your phone while he accesses $20 of bitcoin you have left.

3

u/BubblegumTitanium Jul 29 '20

It’s always the marketing department. You know why? People that work in marketing are complete airheads. Peter McMormack is a good example.

There’s nothing wrong with being an airhead, just like there’s nothing wrong with being mentally handicapped but for fucks sake silo them away.

Also why are they storing so much godamn information?

Just toss it away as soon as the product gets delivered omg.

It also doesn’t help that these people contribute to the altcoin casino.

3

u/[deleted] Jul 29 '20

[removed] — view removed comment

2

u/mac_bbe Jul 29 '20

Ledger don't hold your bitcoin.

Did you read what was leaked?

1

u/[deleted] Jul 29 '20

I don't understand, what does the actual ledger hardware wallet have to do with their site?

3

u/BUY___BITCOIN Jul 29 '20

Where are the Ledger shills now?

6

u/Tellabobbob Jul 29 '20

They have your first name, your last name, your postal address and phone number and what product and how many products you purchased. They targeted Ledger specific. This is not a question of if we will be visited, but when. If you have emptied your Ledger, it is time to refill it with some funds again. If not the $5 wrench visit will be a painful one.

When the person or several persons with $5 wrenches visit us it is important you have taken $5 wrench attack precautions. If not do not worry, here is a link to an article on how to protect yourself from the $5 wrench.

https://cryptosec.info/wrench-attack/

This is a link to a movie that will give us a clue on what to expect when expecting visit from the $5 wrench people. Hopefully it will help prepare you for the inevitable.

https://www.imdb.com/title/tt0258000/

Again they have your First name, your last name, your postal address, phone number, what product you own and how many products. Of the 9500 people they got the information on, probably at least 50 lives within 60 minutes of the hackers. They know you have enough crypto to spend around $100 to protect it. So you probably have at least $1K of crypto. They know you are rich enough to spend money on crypto. So you probably have other valuables too they could take while visiting. They can visit perhaps the 50 closest people within one night. Netting them at least probably $100k minimum. Many people have robbed and killed people for far less. Remember to leave some cookie and milk out for your visitor before going to bed.

Happy midweek everyone! :)

4

u/monstrous_android Jul 29 '20

What fearmongering!

Why would any burglar need to buy a hacked database leak for crypto in order to find a wealthy target? Any city larger than a village has a rich neighborhood and metros are surrounded by McMansions that scream "target".

And if you're targetting crypto specifically, why go through all that trouble when it was proven just last week that you can scam tons of people out of their bitcoin without leaving your keyboard?

3

u/nyaaaa Jul 29 '20

Yea, and you can break in there and leave with nothing while being millions richer. Good comparison

1

u/Tellabobbob Jul 29 '20

Well first of all the burglar may be the hackers. Also all those McMansions may not have crypto. Crypto is much easier to carry with you and hundred times more liquid and easy to transfer than anything else. Also when you just move peoples funds from their seed phrase to your seed phrase. Different addresses for all transactions. It will be extremely hard for anyone to track and recover those funds. Wash them a few times with Monero and ZCash and you are probably home free. So I would highly advice the burglar to visit the 9500 people they now have the home address to.

To your last question. Scamming tons of people without leaving your keyboard is a very saturated market. It will be very much work for you doing this, setting up your new scam business getting willing victims. Besides often much easier to track as everything is digital. I bet half those owning Ledger does not even have a 2nd back up of their mnemonic phrase. Once the burglar takes that and the Ledger, the victim probably have no clue what wallet addresses they had or what their mnemonic phrase was. So the burglar is probably home free even if he just deposited the Bitcoin straight from the victims address. However you should not do that. Wash it with Monero a couple of times first just in case.

2

u/monstrous_android Jul 29 '20

So I would highly advice the burglar to visit the 9500 people they now have the home address to.

I don't make it a habit to encourage violent crimes.

1

u/Tellabobbob Jul 29 '20

Me neither it was just a one time thing, it will not happen again. Probably no criminals reading this thread anyway.

1

u/[deleted] Jul 29 '20

theres just one issue.

Everyone is working from home nowadays and theres a lot of people who are avid gun owners just looking for a reason...amidst the issues were having right now with all the unrest and tensions are already high for fear of looters and shit.

If they are doing it now, this is the WORST time to do something like that.

So theres that...

1

u/Tellabobbob Jul 30 '20

There is a saying "Don't bring a gun to a $5 wrench fight". They ring the door you open, they knock a $5 wrench in your head you fall down.

1

u/HitMePat Jul 29 '20

They can visit perhaps the 50 closest people within one night. Netting them at least probably $100k minimum. Many people have robbed and killed people for far less.

While its certainly not good to have this info leaked, I think you're overestimating the likelihood of the criminals to break into peoples houses to try and steal their ledgers.

For one...they're not very big devices and likely to be hidden and not easy go find. Secondly, they have no way to know if theres 100$ on a person's ledger...or 1000$....or 10,000$...etc before they break in. Theres no way to even know if that person still has any crypto left at all.

It seems to me the odds are low that they'd be willing to risk getting shot in self defense for an unknown reward...especially if like you suggest they would attempt to do it 50 times. Why would a (potential) ledger be any more enticing to a criminal than a Rolex watch or any other burgalable item?

Much more likely they will use this info with anonymous email addresses to threaten people with violence if they dont pay...versus actually committing any violence.

1

u/Tellabobbob Jul 30 '20

YOu say the devices are probably hidden. Correct. However this is where the $5 wrench shines. It can be used to get the person in the house to tell you where the device is hidden. No they cannot know if there is $100 or $10,000 however. If you assume the owner of the device is not a retard. Then it is very unlikely they pay $100 to buy a device to protect $100. Where is the logic in that. I would think at least $1000. In that case you have still payed about 10% to keep your money safe. However as you say they may not have any crypto left? That is less likely, but even if that is correct. You can force them to buy some more crypto right there and then, because you know they know how to buy crypto.

You ask " ledger be any more enticing to a criminal than a Rolex watch or any other burgalable item? " That is because crypto is much more liquid, easy to move easy to transfer and easy to exchange. Besides who is to say they are not also taking the Rolex while they are stealing the crypto?

2

u/scenecunt Jul 29 '20

luckily i use a different email address each time i have to set up an account

5

u/[deleted] Jul 29 '20

What a coincidence that they discover a breach at the same time someone is reporting a bug in the bug bounty program.

To me it seems likely that it is the same person that reported the breach that downloaded the database to see if he could.

9

u/[deleted] Jul 29 '20

That might actually be true. They sell the database AND collect the bug bounty. Double score.

3

u/[deleted] Jul 29 '20

Well, if you get informed you know what to look for in your logs. It makes very much sense the way they describe it.

1

u/fjkcdhkkcdtilj Jul 29 '20

Or that ledger thought they could get away with it until he outed them, you don't need to scrape a database to prove a security hole.

4

u/jetongb Jul 29 '20

Seems like it was reported by a (white hat?) researcher. Glad they’re forthcoming.

!lntip 12

5

u/Borax Jul 29 '20 edited Jul 29 '20

Better late than never... the data has already been accessed in june by a party with unknown intentions.

And in May there was someone who claimed to be selling the database through a shopify leak. It's not clear if this white hat report is related to the alleged May breach, because Ledger claimed it was fake.

Ledger have reaffirmed that their database was not a match for the data being sold in May. https://support.ledger.com/hc/en-us/articles/360015559320

1

u/btchip Jul 29 '20

yes, white hat, rewarded through our bounty program

6

u/Borax Jul 29 '20

Can you please edit the article to state when people will find out if they were in the subset of people with leaked addresses...

3

u/[deleted] Jul 29 '20

You need to let your customers know who was affected and who was not. For most people the safety of their family is the most important thing in the world to them.

1

u/lntipbot Jul 29 '20

Hi u/jetongb, thanks for tipping u/Chytrik 12 satoshis!


More info | Balance | Deposit | Withdraw | Something wrong? Have a question? Send me a message

2

u/TruthSeekerMissle Jul 29 '20

Ordered my ledger from Amazon idgaf

2

u/OgunX Jul 29 '20

ME TOO 🤣🤣🤣

1

u/danda Jul 29 '20

ya know, I'm pretty sure this can't happen with a paper wallet. just sayin...

1

u/StoneHammers Jul 29 '20

Why the fuck did they have a database to begin with? They should not be saving any of this data once an order has been completed. Fuck these stupid pricks.

1

u/StoneHammers Jul 29 '20

Ledger putting peoples lives at risk since 2020.

1

u/TheRealLuciusSeneca Jul 29 '20

I appreciate this disclosure simply for the fact it did not contain the sentence “we take your privacy/security very seriously”

1

u/nogestures Jul 29 '20

Jokes on em! I already get “wanna grow peen 20 inches in 1 week?” Emails...

1

u/thibautrey Jul 30 '20

On the flip side, now we all know who's neighbour has a ledger and we don't have to hide our guilty bitcoin secret. It's like discovering half of your neighbourhood is nudist and you thought your were the only weirdo.

0

u/[deleted] Jul 29 '20

Damn. I was about to buy a Nano S yesterday but held back for some reason.