
Nicolas Bacca
6.1K posts

Nicolas Bacca
@BTChip
Chef @zknoxhq | Co-founder @Ledger 🦄. I build permissionless and hard to break things. Fan of Magic Internet Money (but no MSB). Entrepreneur if duty calls



For some unknown reason I was under the impression that the TSS stack of vulns were in the same sorta class as other cryptography vulns. It’s honestly a completely different beast and I’m struggling to understand how anyone figured this would ever be secure enough lol?

The latest 𝕏 algorithm has been published to GitHub github.com/xai-org/x-algo…






🚨 CYBERINTEL ALERT: ALLEGED IDOR VULNERABILITY IN LEDGER PAYMENT GATEWAY 🇫🇷💳🔐 [STATUS: UNCONFIRMED / CRYPTO PAYMENT DATA EXPOSURE] VECERT Intelligence has detected posts made by the threat actor "xorcat," in which they claim to have identified an alleged IDOR (Insecure Direct Object Reference) vulnerability within infrastructure associated with Ledger. The actor asserts that this flaw would allow unauthorized access to customer information and recent payment details related to Ledger devices. 🏢 Allegedly Affected Entity: Ledger. 👤 Threat Actor: xorcat. 📂 Allegedly Compromised Assets: Customer Information: Names, physical addresses, phone numbers, and email addresses associated with purchase orders. Payment and Shipping Data: References to shipping statuses and products related to Ledger Nano devices. Access via IDOR: The actor claims that the vulnerability would allow for the enumeration and extraction of records without proper authorization. Exploitation Scripts: Publication of alleged scripts designed to automate the mass extraction of information. 📅 Report Date: May 10, 2026. 📊 Technical Analysis of Evidence (VECERT Intelligence) The published evidence suggests a potential exposure scenario linked to insecure access controls: Possible IDOR Vulnerability: The information displayed aligns with typical patterns of object enumeration or exposed internal references. Risk of Crypto Customer Exposure: The correlation between personal data and hardware wallet purchases heightens the risk of physical targeting and spear-phishing. Commercialization of Exploits: The actor claims to be selling exclusive access and extraction tools, which could facilitate exploitation by third parties. ⚠️ Risk Implications Threat to Hardware Wallet Users: The exposure of information associated with physical wallet owners could facilitate targeted campaigns and extortion attempts. Social Engineering Risk: The leaked data could be utilized for phishing attacks related to Ledger and for the fraudulent recovery of assets. Exploitation Persistence: The availability of automated scripts increases the risk of continued abuse should the vulnerability exist. 🛡️ Cyber Defense Recommendations 🔒 Access Control Auditing: Review the validation of direct objects and internal references exposed within APIs and payment gateways. ⚙️ Enumeration Monitoring: Detect anomalous patterns of sequential queries and automated scraping. 🛡️ Customer Data Protection: Minimize the exposure of sensitive information in API responses and tracking systems. 🔍 Forensic Investigation: Verify suspicious access attempts, potential historical data exfiltrations, and activity linked to IDOR exploitation. Monitor: analyzer.vecert.io #CyberSecurity #Ledger #CryptoSecurity #IDOR #ThreatIntel #CyberAlert #DataExposure #InfoSec 🇫🇷💳🛡️⚠️🚨











🥖 The French government is accusing X of the very things the French government itself is doing: - Illegally collecting personal data - Processing personal data without proper security - Extracting data from automated systems - Violating the secrecy of electronic communications






Ok... Fuyez Coinbase.






