Ledger is a cryptocurrency hardware wallet company that also conducts security research.
Ledger is a cryptocurrency hardware wallet company that also conducts security research. In early December 2025, Ledger researchers disclosed a vulnerability in a widely used Android system-on-chip (MediaTek Dimensity 7300) that could enable unpatchable, persistent compromises on smartphones, highlighting hardware-level risks to mobile devices and the security of crypto-related apps and wallets.
On March 21, 2026, Ledger CTO Charles Guillemet issued a security alert regarding a critical update for the Chrome web browser, addressing 26 vulnerabilities, including 4 critical and 22 high severity issues. These…
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
A critical vulnerability affecting MediaTek processors in Android smartphones allows attackers to extract sensitive user data, including PINs and cryptocurrency wallet seed phrases, in under 45 seconds. Discovered by…
A recent study identified 28 malicious LLM proxy routers that can modify AI service responses and access sensitive credentials. The research tested 28 paid routers and 400 free routers, revealing that nine injected…
In March 2026, Kaspersky identified over twenty phishing applications in the Apple App Store that impersonate popular cryptocurrency wallets. These malicious apps redirect users to fraudulent web pages that mimic the…
A significant vulnerability in Coldcard hardware wallets allowed attackers to exploit weak seed generation, resulting in the theft of approximately 1,367 BTC (around $88.6 million) from 4,585 addresses. The exploit,…
Bybit's Security Operations Center (SOC) reported a sophisticated malware campaign targeting macOS users searching for 'Claude Code,' an AI development tool from Anthropic. The campaign, first identified in March 2026,…
The MacSync Stealer, a newly identified macOS infostealer, is being distributed through a sophisticated malvertising campaign on Google Ads that mimics Anthropic’s Claude Code CLI. Security researchers from Beezlebub…
In a significant case of cryptocurrency fraud, the U.S. Attorney's Office for the District of Connecticut has forfeited over $600,000 in Tether (USDT) linked to a phishing scam that targeted a Ledger hardware wallet…
A third-party data breach involving Ledger has exposed order data, leading to a rise in phishing scams. While users' wallets and private keys remain secure, fraudsters are impersonating Ledger to exploit the situation.…