[ 3 / biz / cgl / ck / diy / fa / ic / jp / lit / sci / vr / vt ] [ index / top / reports ] [ become a patron ] [ status ]
2023-11: Warosu is now out of extended maintenance.

/biz/ - Business & Finance


View post   

File: 125 KB, 1368x855, lhack.png [View same] [iqdb] [saucenao] [google]
56976678 No.56976678 [Reply] [Original]

>@Ledger you might want to take a look at this...
>Suspect code is being loaded from here: github...
https://twitter.com/MatthewLilley/status/1735277333093781697

>> No.56976694

>>56976678
Oh no no, how did it go so wrong

People still trust ledger after all the fuckups

>> No.56976752
File: 172 KB, 1506x438, GBTy_-gWAAAFeWT.jpg [View same] [iqdb] [saucenao] [google]
56976752

>> No.56976764
File: 24 KB, 442x694, 1636975731413.jpg [View same] [iqdb] [saucenao] [google]
56976764

>future of finance

>> No.56976798

Anything is safer than a ledger, lmfao. Binance, Coinbase, even fucking metamask. This is the same brilliant company that allowed hackers access to their customer data years ago. They're morons. Imagine trusting them with your fucking crypto! LMAO.

>> No.56976805
File: 11 KB, 280x376, disgust.jpg [View same] [iqdb] [saucenao] [google]
56976805

We tell you
Every. fucking. Time.
Get a Trezor.
Open source.
You only have yourself to blame.

>> No.56976830

>>56976805
Even if you have a Trezor you can get drained right this moment using dApps, this isn't just about Ledger wallets

>> No.56976843

>>56976805
And where am I supposed to store my digital wallet eink art collection then, smarty pants?

>> No.56976853

>>56976843
Frame, using the Trezor to sign, you stupid mongoloid. It isn't locked to the stock application.

>> No.56976883

Can someone explain how this works? I thought you couldn’t drain a ledger wallet without being able to physically access it? Why am I so stupid?!

>> No.56976891

Okay, is this FUD or do I really need to ditch my Ledger for something else?

>> No.56976901

>>56976830
explain how

>> No.56976911

>>56976883
If you don't do anything you can't get drained, you can only get drained if you approve a transaction to get drained.
Right now a lot of dApps are vulnerable because the malicious code is in the dApp connector, so you can get drained even with literally any web3 wallet now if you approve the transaction.

>> No.56976917

>>56976891

i think it has more to do with the transaction itself via bridges. ccip cant come soon enough.

>> No.56976928

>>56976911
I see so I’m safu as long as I don’t approve any transactions for the time. Thank you kind internet stranger!

>> No.56976929

>>56976883
>drain a ledger
Your ledger doesn't hold coins nigger, it just stores your private key.
The attacker put malicious code into a library that dapps use to interact with ledgers.

>> No.56976933

>>56976901
Read >>56976911

For example revoke.cash is confirmed as compromised, so if you now go use revoke.cash with any web3 wallet you'll just approve a transaction to get drained.

>> No.56976945

>>56976929
Nigger the only library I know about is the one where books are kept and homeless faggots go to sleep.

>> No.56976969
File: 77 KB, 1004x721, fker.jpg [View same] [iqdb] [saucenao] [google]
56976969

>>56976933
This isn't true
Stop spreading this bullshit
Its a specific library that ledger wallets use that's been compromised to put a fake wallet connect screen in front of the real one

>> No.56976978

>>56976678
Good thing i staked my chainlink a week ago and am not touching my ledger.

Bros can the ledger seed phase be imported into Trezor?

>> No.56976986

>>56976978
If you're worried about your ledger being compromised then you'll want to make a completely new wallet.

>> No.56977016

HELP!!!
The hackers added chainlink to my wallet. How do I get rid of it?

>> No.56977018

>>56976986
Can't. Need that same address for build rewards and priority staking.

>> No.56977034

future of finance

>> No.56977080

>>56977016
I'm sorry to tell you this, but if it's staked then it has to sit there for a month.
Again, really sorry.

>> No.56977127

>>56976969
So it's a UI hack

>> No.56977154

>Ledger AGAIN
Anyone buying this literal pile of shit after all those things Ledger fucked up is beyond any help

>> No.56977167

>us senator wants to combat crypto
>this happen
>also with sushiswap
There's no such thing as coincidence with those people

>> No.56977196

>>56977167
meds

>> No.56977520

just check the contract address of the token on your blind signing is the same as on dexscreener

>> No.56977554

>>56977520
>>56977240

Rabby seems to be the best wallet, as it simulates your transaction before you approve, so you can see if anything is off.

>> No.56977580
File: 249 KB, 1284x1341, hap.jpg [View same] [iqdb] [saucenao] [google]
56977580

as a code noob that uses Ledger
what should I do?
Just leave my coins on there and wait for a fix?

>> No.56977650

>>56977520
This.
I refuse to believe there are people who don't actually do this.

>> No.56977957

>>56977580
Yes, just do nothing, or >>56977520. As long as you check the address on your device, you are 100% safe, as always.

>> No.56978250

>>56977650
I’m beginning to think it’s only by the grace of God that I haven’t been drained.

>> No.56978589
File: 581 KB, 1436x1522, 3453ter-24332-f.png [View same] [iqdb] [saucenao] [google]
56978589

>>56976798
>metamask
The problem isn't ledger. It's NPM

>> No.56978610

>>56978589
>> running javascript.
>> running node.js

just asking to get your shit stolen

>> No.56978746

>>56977520
i think you should also have an address that is exclusively used for storage/only to send/receive, nothing else.

>> No.56978791

>>56978589
Many such cases. Look up npm malware on Google and all the results are recent

>> No.56980498
File: 140 KB, 640x973, 1702579749392.jpg [View same] [iqdb] [saucenao] [google]
56980498

When i first bought a ledger in like 2017 i went to update the firmware and it bricked itself out of the box I shit your not... I immediately knew it was pure garbage.
The choice is simple, the french are gay wffeminate faggots known for being cucks dating back into the 1700s.

Trezor is made by czechs, arguably the smartest slavs due to their 50% german admixture, the german autism mixed with slavic masculinity leads to a solid engineering mind.
Open source is always a green flag.

>> No.56980580

holy fuck, the hackers took my 0.05 BTC but they left my 10,000 LINK

they also left a note on the btc transaction

"buy real coins nigger"

WHAT THE FUCK

>> No.56980600

>>56980498
french have a bigger territory than germans

seems like the faggots are better at fighting than MUH ARYAN CHADS

>> No.56980798

this is why i've never trusted connecting ledger with a web3 interface. If i wanna buy shitcoins, i just send eth from my ledger to my metamask wallet.

YOU GOTTA KEEP EM SEPARATED
https://youtu.be/GHUql3OC_uU?si=GwD5epxEWk7S6rda&t=65

>> No.56981072

>>56980600
sounds like something a faggot would say

>>56976830
>>56976933
This fuck is wrong, the exploit is in the Ledger ConnectorKit which is exclusively for ledgers.

don't listen to jews or ledger shills

>> No.56981544

Can this affect trezor wallets?

>> No.56981603

>>56980580
they took your dignity

>> No.56981640

>>56976678
I just ordered the new trezor.
I was pissed off about the whole firmware fiasco and analytics but this is just too much.

>> No.56981659

>>56980498
The french literally dominated the world in the 1700s up to Napoleon.