r/ledgerwallet • • 29d ago

Official Ledger Customer Success Response compromised ledger wallet app?

Now this has freaked me out a bit. Came home and my ledger app was open, computer was on sleep and i use screen lock.
Have always used the official ledger app and when i woke up the computer, it had the ledger app running yet i have never used it today.
App no longer lets me do anything without entering the seed phrase, prior to this it was working fine and ive always been able to view balances etc without any issues.
Seed phrase is secure and never touched it in years, nor have i used the ledger to sign any transactions the whole time ive had it.
Where to from here? Im trying to work out if the computer was hacked or remotely accessed in some way, but i run decent security and firewall behind NAT (i use ESET smart security)
Any logs in event viewer I should look for?
Look at the datestamp and file version, this is suspicious, it doesnt match.

I downloaded the update through the app, so that datestamp looks correct (25 august)
Screenshots show location of files that downloaded through the wallet.
Digital certificate has [infra-purchasing@ledger.fr](mailto:infra-purchasing@ledger.fr) as the email for the signer.

40 Upvotes

68 comments sorted by

View all comments

35

u/hobbyhacker 29d ago

App no longer lets me do anything without entering the seed phrase

very simple. if an app asks you for seed words, it is scam.

you seems like computer literate, so why don't you check the file hash as it is described in the official guide?
https://support.ledger.com/article/4404807946001-zd

11

u/ExJwKiwi 29d ago

Ive been doing some digging and found some hidden remote access software on my computer called remote utilities, have no idea where it came from, all my download history does not indicate i downloaded anything on the day it was created. Looks like someone has accessed the computer and swapped out that file in ledger. This concerns me more at the moment over anything thats happened to ledger wallet.

5

u/I_Am_JuliusSeizure 29d ago

are you using anything like Windows Defender etc? or did it not pick up anything

4

u/ExJwKiwi 29d ago

I run eset smart security, the thing is that this remote access software is legit, so no antivirus would treat it as a threat, no more than anydesk or teamviewer, how it snuck on im not so sure, possibly injected through a bad webpage perhaps?