15-Year-Old Security Researcher Discovers Ledger Wallet Vulnerability

Hack Ledger Security Wallet
Journalist
Journalist
Sead FadilpašićVerified
Part of the Team Since
Jan 2018
About Author

Sead specializes in writing factual and informative articles to help the public navigate the ever-changing world of crypto. He has extensive experience in the blockchain industry, where he has served...

Last updated: 

Ledger, a manufacturer of hardware wallet for cryptocurrencies, released an update to its firmware, 1.4.1, accompanied by blog post that said they would be looking into security fixes. This comes after independent security researcher Saleem Rashid has demonstrated a new attack hackers can employ to break your Ledger Nano S wallet and steal your precious coins – both physically and remotely.

Source: ledger.fr

In a blog post Rashid explained, “The vulnerability arose due to Ledger’s use of a custom architecture to work around many of the limitations of their Secure Element. An attacker can exploit this vulnerability to compromise the device before the user receives it, or to steal private keys from the device physically or, in some scenarios, remotely.” He added, “I have demonstrated this attack on a real Ledger Nano S. Furthermore, I sent the source code to Ledger a few months ago, so they could reproduce it.”

Ledger followed up by saying that, “Following a transparent and responsible disclosure process, we are giving a full detailed assessment of the fixed attack vectors that the Firmware 1.4 patches, which were initially reported by three security researchers. As the publication of these technical details might elevate the threat level of non-patched devices, we strongly encourage our users to update their firmware.”

Ledger says the security researchers were asked to sign a Bounty Program Reward Agreement as one of the conditions of being remunerated for their efforts. Rashid actually forwent his bounty reward so that he could publish his blog post to explain in great detail what the security problem was, saying, “I chose to publish this report in lieu of receiving a bounty from Ledger, mainly because Eric Larchevêque, Ledger’s CEO, made some comments on Reddit which were fraught with technical inaccuracy. As a result of this I became concerned that this vulnerability would not be properly explained to customers.”

Still, there may not be too much cause for alarm. Attacks such as the one demonstrated by Saleem Rashid show the difficulty of creating a device that is immune from all known forms of attack.

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,155,134,399,827
2.21
Trending Crypto

More Articles

Bitcoin News
Russia’s Central Bank Says Bitcoin Mining Is Strengthening the Ruble
Anas Hassan
Anas Hassan
2025-12-22 09:22:41
Altcoin News
Binance Let Hundreds of Millions Flow Through Suspicous Accounts After US Settlement: FT
Amin Ayan
Amin Ayan
2025-12-22 08:34:55
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors