Ledger — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
40
occurrences
First Seen
November 4, 2025
Last Seen
August 1, 2026

Ledger is a cryptocurrency hardware wallet company that also conducts security research.

Overview

Ledger is a cryptocurrency hardware wallet company that also conducts security research. In early December 2025, Ledger researchers disclosed a vulnerability in a widely used Android system-on-chip (MediaTek Dimensity 7300) that could enable unpatchable, persistent compromises on smartphones, highlighting hardware-level risks to mobile devices and the security of crypto-related apps and wallets.

Related Threat Clusters

  • Critical Chrome and iOS Vulnerabilities Prompt Urgent User Updates

    On March 21, 2026, Ledger CTO Charles Guillemet issued a security alert regarding a critical update for the Chrome web browser, addressing 26 vulnerabilities, including 4 critical and 22 high severity issues. These…

    3 articles · Updated March 21, 2026
  • FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users

    The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…

    135 articles · Updated May 22, 2026
  • MediaTek Chip Vulnerability Exposes 25% of Android Phones to Data Theft

    A critical vulnerability affecting MediaTek processors in Android smartphones allows attackers to extract sensitive user data, including PINs and cryptocurrency wallet seed phrases, in under 45 seconds. Discovered by…

    23 articles · Updated March 11, 2026
  • Malicious LLM Proxy Routers Compromise AI Security

    A recent study identified 28 malicious LLM proxy routers that can modify AI service responses and access sensitive credentials. The research tested 28 paid routers and 400 free routers, revealing that nine injected…

    2 articles · Updated April 15, 2026
  • FakeWallet Crypto Stealer Targets iOS Users via Phishing Apps

    In March 2026, Kaspersky identified over twenty phishing applications in the Apple App Store that impersonate popular cryptocurrency wallets. These malicious apps redirect users to fraudulent web pages that mimic the…

    7 articles · Updated April 20, 2026
  • Coldcard Firmware Flaw Leads to $88 Million Bitcoin Theft

    A significant vulnerability in Coldcard hardware wallets allowed attackers to exploit weak seed generation, resulting in the theft of approximately 1,367 BTC (around $88.6 million) from 4,585 addresses. The exploit,…

    80 articles · Updated August 2, 2026
  • Bybit Exposes Multi-Stage Malware Targeting Claude Code Users

    Bybit's Security Operations Center (SOC) reported a sophisticated malware campaign targeting macOS users searching for 'Claude Code,' an AI development tool from Anthropic. The campaign, first identified in March 2026,…

    5 articles · Updated April 21, 2026
  • MacSync Stealer Targets macOS via Malicious Google Ads Campaign

    The MacSync Stealer, a newly identified macOS infostealer, is being distributed through a sophisticated malvertising campaign on Google Ads that mimics Anthropic’s Claude Code CLI. Security researchers from Beezlebub…

    9 articles · Updated July 1, 2026
  • Phishing Scam Targets Ledger Users, $600K in Tether Forfeited by US Authorities

    In a significant case of cryptocurrency fraud, the U.S. Attorney's Office for the District of Connecticut has forfeited over $600,000 in Tether (USDT) linked to a phishing scam that targeted a Ledger hardware wallet…

    4 articles · Updated April 2, 2026
  • Ledger Data Breach Triggers Phishing Scams Targeting Users

    A third-party data breach involving Ledger has exposed order data, leading to a rise in phishing scams. While users' wallets and private keys remain secure, fraudsters are impersonating Ledger to exploit the situation.…

    2 articles · Updated January 21, 2026

Recent Intelligence Reports

  • Coldcard Hacked for $70M: How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked? — 247Wallst · August 1, 2026
  • A Weaponized Google Ad Install Malicious Claude Code to Hijack Entire macOS — Cybersecuritynews · July 1, 2026
  • Bluekit phishing kit adopts browser-in-the — Bleepingcomputer · June 25, 2026
  • Bluekit Phishing as a Service (PhaaS) — Cloudsek · June 16, 2026
  • Bybit Security exposes macOS malware campaign targeting users searching for Claude Code — Mexc.Co · April 21, 2026
  • FakeWallet crypto stealer spreading through iOS apps in the App Store — Securelist · April 20, 2026
  • FakeWallet crypto stealer spreading through iOS apps in the App Store — Securelist · April 20, 2026
  • Malicious LLM proxy routers found in the wild — News.Risky.Biz · April 15, 2026

CVSS v3.1 Breakdown