[PSA] If you use Bitcoin on a Ledger device, you need to update

in LeoFinance11 months ago

If you use a Ledger device with Bitcoin, you are going to want to update your device immediately. A vulnerablity has been discovered that allows you to spend Bitcoin without signing the transaction due to a bug in the included miniscript software.

The bug was discovered back in April and patched in an update released yesterday.

This is the update you are looking for, it is a software app upgrade and not a firmware upgrade.

The update is really quick and you want to be running version 2.1.2 of the Bitcoin app.

This vulnerability is limited to Ledger devices and no known flaws currently exist on the Trezor device.

I recommend doing this update immediately rather than waiting for the next time you use the device and potentially forget.

You can read more about this vulnerability by checking out the full disclosure here.

Image Sources: 1

Posted Using LeoFinance Alpha

Sort:  

Thank you for the notice. It is really important to be aware of these things, as we regard cold wallets to be the safest form of storage. I am very glad that I stumbled upon your blog.

You really made me loss so much which is very bad from My both post it unfair that two posts which is supposed to be at 5 dollar is now at 0.5 something please desist from My Blog I Beg you 🙏🙏, your reasons for the downvote is best known to you but it's really affecting my blog I generally it's really uncalled for.
Every penny I make has its use am trying to manage it downvoting adds no value to you and I don't see reasons you keeps doing it to to hivers in the general Blockchain like yourself.
Please allow me use my little Earnings Thanks 🙏

Please stop downvoting my posts just because an account you dislike upvoted them. My family is working class, and every dollar we make we need. Your ego downvote war just has seen me lose thousands of dollars in potential wars. I wish you would explain to my daughters how your whale wars cause us to lose gas money used to take our kids to school.

This blockchain represents real life pretty well, trickle down economics to the fullest. And if I downvoted this post there would be hell to pay and repercussions I can't even imagine. Seems like an imbalance of power, you downvote my content without reason other than you simply dislike the account that upvoted me. I am tired of explaining to ASEAN Hivers that you don't downvote their posts because the quality is poor, but merely because you have a voting war with another rich person.

This has left a bad taste in the mouths of many of my community members, and because you don't even explain the reason, your actions drive many people away from this blockchain. I wish you and your xeldal war would just stay out of ASEAN Hive and keep your politics far away from us.

You could at least take the time to make a post explaining your actions to those living in developing countries who need every penny they can earn on Hive.

Honestly,I do not understand until I just read your comment,been overthinking lately on what could have possibly gone wrong with my posts or account getting downvoted by this account,chatted his account,made several complains and I've lost alot on the little votes I get,infact I'm starting to feel people would have marked my account and not want to vote my post because what's the point if it will get downvoted,I'm just tired,this is really cyber bully,thanks for this comment,at least I know i haven't done anything wrong

People should be required to write at least 1000 words why they feel the need to down vote.

https://leofinance.io/threads/view/alokkumar121/re-leothreads-wl7ysgfe
https://leofinance.io/threads/view/thetimetravelerz/re-leothreads-pukhhelt
The rewards earned on this comment will go directly to the people ( alokkumar121, thetimetravelerz ) sharing the post on LeoThreads,LikeTu,dBuzz.

https://reddit.com/r/cybersecurity/comments/13f8kc5/psa_if_you_use_bitcoin_on_a_ledger_device_you/
The rewards earned on this comment will go directly to the people sharing the post on Reddit as long as they are registered with @poshtoken. Sign up at https://hiveposh.com.

You made me get up to go grab my hardwallet but sadly I don't have any bitcoin to protect :(

only btc on ledger is vulnerable? eth is safe?

that allows you to spend Bitcoin without signing the transaction due to a bug in the included miniscript software

lol

Eh... I was anticipating another Rick Roll. 😔

But thanks for the info.

@themarkymark
Thanks for sharing
I see a high risk exposing vulnerable on device.i got zero Bitcoin for now
Lolzzzz

Thanks for the heads up.