If you’ve got a ledger device and connect to it with an android device STOP RIGHT NOW!


From Ledger:
The vulnerability, which we are tracking internally as LDN-2026-0301, allows an attacker with proximity access or a malicious app installed on the victim's Android phone to silently intercept and modify data exchanged between the Ledger hardware wallet and the Ledger Live mobile application.
In a successful exploit scenario, a bad actor could manipulate transaction details in transit — altering destination addresses or amounts — before they reach the hardware wallet's trusted display for user verification. This is a man-in-the-middle attack at the transport layer, exploiting a flaw in Android's connection handling rather than in Ledger's own firmware or software.

Resolution: rolling out a mandatory firmware update for all Ledger hardware wallets that introduces end-to-end encrypted and authenticated communication between Ledger Live and your device. This update neutralizes the Android transport-layer attack by ensuring that any tampering with data in transit is immediately detected and rejected.
post-image
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin