Ledger releases a security update for its wallet

The new version addresses a “man-in-the-middle” type of attack
07 February 2018   1748

Ledger Wallet Bitcoin Chrome application has been recently updated to include a new security feature - verification of the reception address directly on a hardware device. This patch fixes a specific issue that has gained weight among the community.

A malware has been recently announced that is potentially capable of infecting the Ledger Chrome application along with the whole user’s system. Thus, theoretically the attacker could replace the ‘receive’ address displayed on the screen of the application on the infected system with the attacker’s address. This type of an attack is called “man-in-the-middle”.

Now the users can easily verify the received address on their device. Additionally, Eric Larcheveque, CEO of Ledger, explained the 3 important steps the company is making in terms of improving the security: software updates, upgraded Bug Bounty program and prevention by working on developing resources and materials to help users to better understand the threats.

Security is an arms race. We’re in it for the long haul and are prepared for it. At Ledger, we take our mission seriously and that mission is to protect you

 

Eric Larcheveque

Ledger CEO

Reddit users were mainly puzzled with the update:

u/cryptogalaxy said “I just saw the email and I'm not sure I understand. They no longer display your receiving address on the computer but instead only display it on your device so you can no longer copy paste your address? That could cause typing errors when you want to transfer from an exchange to your wallet as you have to manually type out the whole address each time. Did I misunderstand or is this their so called "upgrade"?”

u/adavidmiller said “I don't get it, didn't you always have to confirm the receiving address manually on the ledger itself?”

u/advanceb said “If I have a ledger nano S how do I update this? Do I still keep the same private keys etc?”

u/Niros1 said “Does this issue also relevant for MEW? Does MEW generate the addresses with JS?”

Ledger Team to Find Issue in New Nano S Software

Last update's security improvements have affected the amount of device memory
15 February 2019   150

Ledger hardware wallet developers stated that an unforeseen problem was found in software version 1.5.5 for the Nano S model. Improvements in the security context have affected the amount of device memory.

When planning for this update we didn’t anticipate the impact it would have on Ledger Nano S capacity. This was not planned obsolescence, simply put, we messed up. We apologize and we’re committed to making it right.
 

Ledger Team

The project team apologized for the incident and promised to fix the problem during the second quarter of 2019.

The project also announced the addition of Nano S support in the Ledger Live mobile app on Android.

Earlier, researchers at Wallet.fail discovered a number of vulnerabilities in the Trezor and Ledger hardware cryptocurrency wallets. As a result, they were able to conduct a series of successful attacks on wallets during the Chaos Communication Congress in Leipzig.