Ledger Donjon

179 posts

Ledger Donjon banner
Ledger Donjon

Ledger Donjon

@DonjonLedger

The security research at Ledger.

Paris Katılım Haziran 2019
1 Takip Edilen5.9K Takipçiler
Sabitlenmiş Tweet
Ledger Donjon
Ledger Donjon@DonjonLedger·
Donjon is the Security Research team at @Ledger. Follow us to get the the latest news from our research. More info on our blog: ledger-donjon.github.io
Ledger Donjon tweet media
English
11
68
73
0
BTCPay Server
BTCPay Server@BtcpayServer·
BTCPay 2.3.6 is out! New features, bug fixes and security patches. Huge thanks to @DonjonLedger for using their new AI security agent to review our project ahead of release and all contributors who made it happen.
BTCPay Server tweet media
English
7
25
88
9.3K
Ledger Donjon retweetledi
Charles Guillemet
🚨Only days after Coruna, one of the first large-scale iOS exploit kits, DarkSword is already being exploited in the wild. Coruna showed the pattern: state-grade iOS exploits don’t stay in government hands. They leak, spread, and end up in broader ecosystems. One visit to a compromised site, and your phone, including your crypto, is gone. DarkSword confirms it. - Another state-grade exploit chain. - Already reused by multiple actors. - Already deployed at scale via watering-hole attacks. - Targets so far: Ukraine, Saudi Arabia, Turkey, Malaysia. - Victim model: anyone who visits a compromised but legitimate website. ⚠️No click. No warning. Full device compromise. Data exfiltration. Real-time surveillance. Total loss of control. Affected: iOS 18.4 → 18.7. This used to be rare. Targeted. Surgical. Now it’s industrialized. 👉Two major iOS exploit chains in less than a week isn’t noise, it’s a shift. From now, you should assume your phone is compromised, Stop treating it like a safe. x.com/P3b7_/status/2…
English
2
14
46
20.1K
Ledger Donjon retweetledi
Pascal Gauthier @Ledger
Our phones were never designed to be secure vaults. The @DonjonLedger proves that every single day. For years, we’ve trusted our phones to protect everything: our data, our identity, our money. But smartphones are inherently fragile. They’re multipurpose, always-connected devices built for convenience first — not hardened security. That model may have been enough for the early internet of information. It doesn’t work for the internet of value. When a single vulnerability can put hundreds of millions of devices at risk, it’s a reminder of a simple truth: the device you use every day should not be the final line of defense for your digital value. 875 million Android devices can be compromised in under 60 seconds. That’s exactly why your phone should never be where your value ultimately lives. Pair it with a @Ledger signer and use the Ledger Wallet app. shop.ledger.com/?srsltid=AfmBO… forbes.com/sites/daveywin…
English
123
46
163
4.3K
Ledger Donjon retweetledi
Charles Guillemet
Charles Guillemet@P3b7_·
🚨 @DonjonLedger has struck again discovering a MediaTek vulnerability potentially impacting millions of Android phones. Another reminder that smartphones aren’t built for security. Even when powered off, user data - including pins & seeds - can be extracted in under a minute.
English
106
124
440
151.1K
Ledger
Ledger@Ledger·
Every morning, a team of elite hackers walks into Ledger HQ. Their job: strengthen the security of every device we ship: and raise the standard for the entire ecosystem. This is the Ledger Donjon 🧵
Ledger tweet media
English
131
86
374
44.5K
Ledger Donjon retweetledi
Charles Guillemet
Charles Guillemet@P3b7_·
What if a hacker could gain total control of your smartphone, not via malware, but the hardware itself? The @DonjonLedger discovered a potentially unpatchable flaw impacting MediaTek Dimensity 7300 - a popular Android phone SoC - enabling arbitrary code execution in minutes. Here’s how 🚨
Charles Guillemet tweet media
English
14
37
189
29.9K
Ledger Donjon retweetledi
Charles Guillemet
Charles Guillemet@P3b7_·
⚠️ Our white hat team, the @DonjonLedger, discovered a flaw in Tangem cards that makes brute force attacks possible. As always, the Donjon followed responsible disclosure to inform Tangem, user protection is our priority. We can now reveal our findings in full: 🧵👇
Charles Guillemet tweet media
English
137
204
1K
237.5K
Ledger Donjon
Ledger Donjon@DonjonLedger·
Security leaves no room for error, a single variable mishandled, and the entire security model can collapse. We're excited to share an illustration of this through our recent research on the Tangem card. Big thanks to the @Tangem team for their responsiveness and collaboration!
Charles Guillemet@P3b7_

🚨At Ledger Donjon, we don’t just secure our own products, we help make the entire crypto ecosystem safer. As part of our ongoing security research and responsible disclosure efforts, we identified an important vulnerability in Tangem’s Android app. 👇🧵

English
3
5
25
5.1K
Ledger Donjon
Ledger Donjon@DonjonLedger·
Donjon is at @BlackHatEvents Asia this week! Karim (@k15ab_ ) is presenting his research on using deep learning attribution methods for fault injection attacks. Don't miss his presentation: #i-have-got-to-warn-you-it-is-a-learning-robot-using-deep-learning-attribution-methods-for-fault-injection-attacks-44092" target="_blank" rel="nofollow noopener">blackhat.com/asia-25/briefi…
English
1
2
8
1.7K
Ledger Donjon
Ledger Donjon@DonjonLedger·
Last week at @hardwear_io NL 2024, we showcased some of our attack tools we use in the Donjon, and a live demo of a double fault injection ⚡️⚡️ with the transportable laser bench! Our tools are open-source and presented on our webpage: donjon.ledger.com/tools-suite/
Ledger Donjon tweet media
English
2
1
12
1.7K
Ledger Donjon
Ledger Donjon@DonjonLedger·
Last week, the Ledger Donjon team joined the NoLimitSecu 🇫🇷 podcast to share Ledger’s vision on wallet security in episode #475, titled 'Sécurité des wallets'. For English speakers, you can use auto-generated subtitles on youtube.com/watch?v=2BpI6i… #ledger #donjon #CyberSecurity
YouTube video
YouTube
NoLimitSecu@nolimitsecu

#Podcast #Cybersécurité Épisode #475 consacré à la sécurité des Wallets, avec @IooNag et @b0l0k_ (@Ledger) nolimitsecu.fr/securite-des-w…

English
0
4
10
4.6K
Ledger Donjon
Ledger Donjon@DonjonLedger·
This week the Donjon brought its transportable laser bench to the jaif.io/2024 conference in Rennes by train 🚄. A proof that a functional Laser Fault Injection bench is not that impossible to see anywhere. Next step in the Village @hardwear_io NL 2024 conference!
Ledger Donjon tweet media
English
0
10
36
4.1K
Ledger Donjon
Ledger Donjon@DonjonLedger·
During next @hardware_io conference, @DonjonLedger will showcase tools developed and used for Fault Injection Attacks! Pass by in the Village to see a part of our Tool Suite: Scaffold, Silicon Toaster, Laser Studio, QuickLog, Curmea… operating on our transportable laser bench!
hardwear.io@hardwear_io

Unlock new levels of precision with hardware tools such as Scaffold, Silicon Toaster, and Curmea! 🛠️✨ Ideal for precise perturbations in operations including current regulations, signal generation, process disruption Join @mickm111 at #hw_ioNL2024 👉 hardwear.io/netherlands-20…

English
0
1
6
1.2K