If you are a Ledger user, be very careful, the hardware wallet team warns that you may be a victim of a phishing attack that could make you lose all your Bitcoin funds.
The Ledger developer team, one of the hardware wallets or physical wallets cryptocurrencies, safest and most reliable in the world, issued a release recent to warn your customers and users about a possible phishing attack that is currently running. The warning indicates that users are receiving emails from a fake domain, which invites victims to download a supposed update for the wallet, but which is actually intended to steal the funds in Bitcoin (BTC) that are stored within these devices.
The developers ask users to be very cautious when entering their private data, such as passwords, recovery phrases or sending cryptocurrencies or digital assets, as cybercriminals are continually devising ways to steal users' funds, and phishing attacks They seem to be one of your best alternatives. Ledger maintains that attackers can perfectly and easily imitate the wallet's domain or website, as well as Ledger content or applications, to entice users to enter their 24-word recovery phrase or some other private data. Given Ledger's recent warnings, several users of this wallet are beginning to express their annoyance over the company's data leak, which allowed attackers to obtain personal data, such as email addresses, of the company's clients. wallet.
It may interest you: Ledger reports on a hack that leaked customer information over the past two months
Fake email, a phishing attempt
The Moon, a Twitter user claims that he received an email, supposedly directed from the Ledger team, informing him that his funds are at risk because the team has discovered that several of the administrative servers of the Ledger Live services are infected with malware. The email asks users to download an update to supposedly fix the problem and eliminate the risk. However, given the warnings issued by the team on its official website, The Moon points out that it is a phishing scam, which is why it calls on other users of the wallet not to download anything from said email, since They can put your security at risk and lose your funds.
Another user pointed out that the false address was visible in the address from which the email was received, since the URL is incorrect, detailing that the dot in the second 'e' of Ledger (ledgėr) reveals the scam.
An alert for all Ledger clients
On Reddit, a user under the pseudonym Cuongnq, notes that the Ledger team must address the marketing and e-commerce data breach that it suffered since July of this year, since the email received, in the phishing attempt, seems very professional, so many users may be confused and be victims of attack. Cuongnq published the email received, which reads:
“We regret to inform you that Ledger has experienced a security breach affecting approximately 85,000 of our customers and that the wallet associated with your email address (xxxx@yyy.com) is among those affected by the breach.
Namely, on Saturday, October 24, 2020, our forensic team discovered that several of Ledger Live's administrative servers were infected with malware.
At this time, it is technically impossible to conclusively assess the severity and scope of the data breach. Due to these circumstances, we must assume that your cryptocurrency assets are at risk of being stolen.
If you receive this email, it is because you were affected by the breach. To protect your assets, download the latest version of Ledger Live and follow the instructions to set up a new PIN for your wallet.”
Fearing the loss of their funds, many users may end up falling victim to the attack, revealing their recovery phrase or private keys and losing their funds permanently. Cuongnq recalled that the exploited vulnerability allowed an unauthorized third party to access the company's e-commerce and marketing database, stealing customers' email addresses, as well as other personal data such as first and last names, postal address and phone number. This medium reported on the seriousness of this attack in June.
Protection measures for users
To avoid being a victim of the phishing scam, the Ledger team reminds its customers and users that they should not enter their seed phrase or recovery key anywhere other than the hardware wallet device, and also remember that the Ledger team Ledger will never, under any circumstances, ask any user to supply their 24-word recovery phrase.
Finally, the Ledger team published a list of all the fake sites that seek to deceive users, remembering that they should only download Ledger Live from their Official site, and avoid recovery apps, YouTube accounts, and other fake ads.
Continue reading: Researcher discovers security vulnerability in Ledger that allows Bitcoin spending with fully valid signatures


