Bitcoin wallet Ledger’s database hacked for 1 million emails

2 44
Avatar for merskie
3 years ago

News Business

Hardware wallet maker Ledger suffered a breach of 1 million customer emails and e-commerce documents in June. No user funds were affected.

By Shaurya Malwa3 min readJul 29, 2020Jul 29, 2020

Ledger wallet connected to a computer to access crypto. Image: Shutterstock

In brief

  • Ledger said it was hacked in June when one million emails were compromised.

  • No user funds or financial information was accessed.

  • Investigations are ongoing with French cybersecurity authorities.

Bitcoin hardware wallet maker Ledger revealed today that its e-commerce database was hacked last month, leaking 1 million emails and some personal documents. No user funds were affected by the breach.

Ledger said the attack targeted only its marketing and e-commerce database, meaning the hackers were unable to access users' recovery phrases or private keys. All financial information—such as payment information, passwords, and funds—was similarly unaffected. The breach was unrelated to Ledger's hardware wallets or its Ledger Live security product, the company added.

"Solely contact and order details were involved. This is mostly the email address of approximately [1 million] of our customers. Further to the investigation, we have also been able to establish that a subset of them was also exposed: first and last name, postal address phone number, and product(s) ordered,” said Ledger in its announcement.

The firm specified that more detailed personal information was leaked in 9,500 cases, including phone numbers, postal addresses and what product they purchased. The announcement added that, "More detailed personal information could have been exposed."

A researcher participating in Ledger’s bug bounty program flagged the issue initially on July 14. The firm patched the problem at the time, but later discovered the breach had occurred weeks earlier on June 25. The cause: A third-party tool that accessed the marketing and e-commerce database using a (now-disabled) API key.

Hacker claims to have stolen data from Ledger, Trezor and KeepKey

A hacker is reportedly selling stolen data from three popular hardware wallets—prompting an investigation by at least two of the companies allegedly involved.  The hacker claims to have stolen...

News Business

Mathew Di SalvoMay 25, 2020May 25, 2020

In a note to clients, Ledger CEO Pascal Gauthier said the firm was "extremely regretful" about the incident. He further cautioned users to be wary of phishing attempts: “We take privacy very seriously, we discovered this vulnerability thanks to our own bug bounty program, we fixed it immediately.”

BTC Price 

“But regardless of all that we did to avoid and fix this situation, we sincerely apologize for the inconvenience that this matter may cause you,” added Gauthier.

Ledger Nano X review: an expensive step in the right direction

Since cryptocurrencies were invented over a decade ago, there have been many attempts to build more advanced, secure and user-friendly walletsto store them. As of 2020, the current gold-standa...

Reviews Wallets

Daniel PhillipsJan 12, 2020Feb 19, 2020

Meanwhile, Ledger said France’s Data Protection Authority, the CNIL, was notified about the breach on July 16. The firm is also working with the Orange Cyberdefense (OCD) to find any evidence of the stolen data being sold online.

All affected users were notified about the breach today and the investigation is ongoing.

Update: This article has been updated with more details from Ledger.

Before you leave, follow us on Twitter to be the first to major stories when they break.

https://decrypt.co/37063/bitcoin-wallet-ledgers-database-hacked-for-1-million-emails

Top stories, original features, rewards & more.

Get the best of Decrypt where you want it most.

Recommended News

  • Iran allows industrial Bitcoin mining as it seeks economic refuge

    Iran has allowed the country’s biggest power plant operators to build and run large Bitcoin mining units, according to local publication Irna News—with three caveats. Mostafa Rajabi Mashhadi, ...

    News Business

    Shaurya MalwaJul 30, 2020Jul 30, 2020

  • Rich Dad Poor Dad author suggests gold bulls load up on Bitcoin

    If the gold market is too rich for your blood, you may want to consider silver or Bitcoin, according to Robert Kiyosaki, author of the best-selling book "Rich Dad Poor Dad." Dennis Gartman re...

    News Business

    Jose Antonio LanzJul 30, 2020Jul 30, 2020

  • Ethereum is dominating Bitcoin on this crypto exchange

    Alt season, where smaller coins are on the rise, is among us once again—even if somewhat contained. Since July, 20, crypto exchange CEX.IO has reported a spike in pairings for Ethereum (ETH). ...

    News Business

    Robert StevensJul 30, 2020Jul 30, 2020

6
$ 0.00
Avatar for merskie
3 years ago

Comments

hi need deposit for this article

$ 0.00
2 years ago

Personally, I prefer using web wallets.

$ 0.00
3 years ago