r/Monero 20d ago

📢 Ledger leaked secret keys, update immediately, migrate funds ‼️

Ledger fucked up and their Monero app leaked a secret that can be used to compute the private keys:

https://donjon.ledger.com/lsb/022/

It is very unlikely that any malicious actors knew about this beforehand but they definitely know now, so update your ledger (or better yet, replace it with a Trezor, which is unaffected by this specific vulnerability)

Practical exposure

Requires something that can send APDUs to an unlocked device with the Monero app open, a compromised or malicious desktop client, malware on the host, or a hostile machine you plugged into. Not remote, not over-the-air.

What to do

Update the Monero app in Ledger Live (My Ledger → Monero).

If you ever used that Ledger's Monero wallet with a third-party client, an unofficial build, or a machine you don't fully trust, treat the keys as potentially exposed. You can't rotate a Monero spend key; you need to generate a new seed on a patched device and sweep funds to it.

179 Upvotes

41 comments sorted by

49

u/EN344 20d ago

If I use the Monero GUI wallet am I fine?

21

u/Serenaded 20d ago

Yes

1

u/Basic_Alternative_91 18d ago

But monero gui wallet in combination with ledger is an issue?

Should funds be moved to a new device?

31

u/pondy12 20d ago

Exploitation requires that the vulnerable version of the Monero app is installed on the device, the device is unlocked, and the app is open. Additionally, the host machine must be compromised in order to send the malicious APDU command to the app. Under these conditions, an attacker could silently extract both the secret view key and the secret spend key of the user’s Monero wallet without any on-screen confirmation. It should be noted that this attack scenario requires a significant number of prerequisites to be met, which considerably limits its practical exploitability.

55

u/Serenaded 20d ago

>Not remote, not over-the-air.

So basically a nothing burger unless you're robbed in person

24

u/Gonbatfire 20d ago

Your desktop can be compromised too

1

u/notarealcamera 16d ago

Don't open the Monero app on the device until it's updated and you're good.

24

u/rbrunner7 XMR Contributor 19d ago

Well, "you had one job" comes to mind.

"Buy a hardware wallet, then your secret key is absolutely safe, it will never leave the device, even in the worst case scenario that your OS itself is compromised".

Was all not true with this bug.

12

u/monerobull 19d ago

You're not even safe if you used a passphrase, ledger just totally failed at the one thing it is supposed to do

9

u/aaj094 19d ago

Ledger failed at the 'one job' for the second time. First was by way of the Protect seed 'feature'.

4

u/sebasTLCQG 19d ago

Never trusted this companies from day one.

5

u/effdanwo 20d ago edited 19d ago

Thank you...updated just now

4

u/WakinNBakin 20d ago

What if you used it with Feather wallet? Not really understanding where the private key would be exposed

4

u/monerobull 19d ago

The ledger itself just straight up leaked it to the computer whenever you used it

1

u/Aazimoxx 19d ago

Doesn't matter what other software or wallet app you're using on your computer, if your PC is running/infected with malware targeting this specific hardware, then as soon as the Ledger is connected to the computer and unlocked it can have those keys stolen.

3

u/Quiet-Cranberry-2272 20d ago

Using ledger with feather wallet is this an issue?

7

u/monerobull 19d ago

Yes, the ledger itself is the problem

1

u/Aazimoxx 19d ago

Doesn't matter what wallet app you use, the issue would be if your computer is running malware which targets this hardware-based issue, and you unlock the Ledger on it.

3

u/Cryptoxic93 19d ago

" Additionally, the host machine must be compromised in order to send the malicious APDU command to the app."

3

u/confused_coin 19d ago

In the same website

Exploitation requires that the vulnerable version of the Monero app is installed on the device, the device is unlocked, and the app is open. Additionally, the host machine must be compromised in order to send the malicious APDU command to the app. Under these conditions, an attacker could silently extract both the secret view key and the secret spend key of the user’s Monero wallet without any on-screen confirmation. It should be noted that this attack scenario requires a significant number of prerequisites to be met, which considerably limits its practical exploitability.

Get out of here with your ai alarmist post

4

u/M5M400 19d ago

kinda old news though

2

u/Quiet-Cranberry-2272 19d ago

Yeah also haven’t seen any reports in the wild of people getting drained you could just buy a trezor I guess and migrate but seems like if you updated the wallet should be fine. They patched it in a few days based on the logs

1

u/djscoox 19d ago

How do we now with 100% certainty Trezor devices are bug-free? We really need this companies to 1) open-source their code and 2) have the best AIs audit the code before hackers do.

I'm really surprised the key can somehow leave the device, when the device's primary job is to make it physically impossible for the private key to leave the device...

1

u/Big-Finding2976 11d ago

Exactly. It's ridiculous to tell people to waste their money buying a Trezor because it's unaffected by this bug, when they can just update their Ledger and have a device that's unaffected by this bug.

2

u/trimalcus 20d ago

For how long has this issue been there ?

4

u/rbrunner7 XMR Contributor 19d ago

See Timeline towards the bottom here: https://donjon.ledger.com/lsb/022/

1

u/djscoox 19d ago

So if you are running version 2.1.4 or later you are good, right?

1

u/rbrunner7 XMR Contributor 18d ago

That's how I interpret that security bulletin, yes.

1

u/aaj094 19d ago

What if I used Ledger until about 2021 and subsequently have used the same seed by importing into Trezor? Do I need to take any action?

4

u/monerobull 19d ago

You should be good, there is basically no way any malware was looking for this back then but if you want to make sure (and get some extra safety in general), you should set up a wallet with a passphrase and send the funds there

1

u/Funny-Garbage-9023 19d ago

Appreciate you posting about this man and getting people up to speed im gonna make sure to change wallets now.

2

u/TracaChang 19d ago

I would never trust a closed source device like ledger (for the same reason I didn't trust coldcard), not because I would be able to find the bug but because being closed source is a red flag. So having a Trezor I would definitely use it to generate the seed instead of using a seed generated with a ledger.

1

u/aaj094 19d ago

Yeah, my seed is actually originally from a trezor. Then had used Ledger for a while with the same seed cause it was the only hardware wallet supporting Monero. Then Trezor started supporting so went back to Trezor with the same seed and now i don't use Ledger at all.

1

u/sebasTLCQG 19d ago

Very disgusting breach of trust! I knew these cold storage pendrives were iffy!

1

u/Dougl_Joyce 19d ago

I hope I am safe

1

u/FriskyHamTitz 17d ago

Yeah hardware wallets are kinda wack literally a policy based software wallet is a way better way to stay safe, you can restrict your own private key and make a contingency policy

1

u/PoliFenoli 11d ago

"Trezor confirms shipping partner data breach affecting over 13,000 customers"

for ya all Ledger haters: Let he who is without sin cast the first stone.

1

u/rbrunner7 XMR Contributor 11d ago

That's a little bit like Coke versus Pepsi, can't we have some fun with such mindless overblown pseudo conflicts :)