‘Self-custody will die very quickly’ – Ledger wallet theft hits $91M
Key Summary
A recent Ledger wallet theft has resulted in $91 million in losses, primarily affecting the Tron network and Bitcoin addresses. The attack, attributed to a supply chain issue with a Southeast Asian reseller, raises concerns about the future of crypto self-custody. Experts warn that self-custody may 'die very quickly' if nothing is done to address the issue.
Ledger Wallet Theft Hits $91M, Self-Custody on Brink of Collapse
Introduction
The recent Ledger wallet theft has resulted in significant losses, with $91 million in stolen funds. The attack primarily affected the Tron network and Bitcoin addresses, with 276 victim addresses drained of $64.5 million and $17.7 million, respectively. The Ethereum ecosystem suffered $8.8 million across 55 addresses.\\n\n
Impact on Self-Custody
The Ledger attack highlights the vulnerability of self-custody solutions. The use of hardware wallets, such as the Ledger Nano X and Ledger Nano S Plus, can be compromised if not properly secured. The attack was attributed to a supply chain issue with a Southeast Asian reseller, CryptoBilis. The two models above were allegedly compromised and had spyware components that could read and send seed phrases to a server. Seed phrases are like passwords to crypto wallets, and the attacker could drain the funds in these devices if they aren't in a multi-sig setup.\\n\n
Industry Response
The industry is still reeling from the $114 million Coldcard hardware exploit in Q3. The recent Ledger attack has raised concerns about the lack of coordination among industry players to address these issues. Binance, for example, has vowed to support the industry's collective efforts to recover the stolen funds. The exchange's CEO, Richard Teng, stated that 'security is a shared responsibility, and Binance stands ready to support the industry's collective efforts.'\\n\n
Conclusion
The Ledger attack has highlighted the vulnerability of self-custody solutions. The industry must take steps to address these issues and ensure that users are protected from such attacks. The recent theft of $91 million has raised concerns that self-custody may 'die very quickly' if nothing is done to address the issue.