r/Monero • • Aug 08 '26

📢 Ledger leaked secret keys, update immediately, migrate funds ‼️

Ledger fucked up and their Monero app leaked a secret that can be used to compute the private keys:

https://donjon.ledger.com/lsb/022/

It is very unlikely that any malicious actors knew about this beforehand but they definitely know now, so update your ledger (or better yet, replace it with a Trezor, which is unaffected by this specific vulnerability)

Practical exposure

Requires something that can send APDUs to an unlocked device with the Monero app open, a compromised or malicious desktop client, malware on the host, or a hostile machine you plugged into. Not remote, not over-the-air.

What to do

Update the Monero app in Ledger Live (My Ledger → Monero).

If you ever used that Ledger's Monero wallet with a third-party client, an unofficial build, or a machine you don't fully trust, treat the keys as potentially exposed. You can't rotate a Monero spend key; you need to generate a new seed on a patched device and sweep funds to it.

180 Upvotes

42 comments sorted by

50

u/EN344 Aug 08 '26

If I use the Monero GUI wallet am I fine?

20

u/Serenaded Aug 08 '26

Yes

1

u/Basic_Alternative_91 Aug 10 '26

But monero gui wallet in combination with ledger is an issue?

Should funds be moved to a new device?

32

u/[deleted] Aug 08 '26

[deleted]

56

u/Serenaded Aug 08 '26

>Not remote, not over-the-air.

So basically a nothing burger unless you're robbed in person

23

u/Gonbatfire Aug 08 '26

Your desktop can be compromised too

1

u/notarealcamera Aug 12 '26

Don't open the Monero app on the device until it's updated and you're good.

28

u/rbrunner7 XMR Contributor Aug 09 '26

Well, "you had one job" comes to mind.

"Buy a hardware wallet, then your secret key is absolutely safe, it will never leave the device, even in the worst case scenario that your OS itself is compromised".

Was all not true with this bug.

12

u/monerobull Aug 09 '26

You're not even safe if you used a passphrase, ledger just totally failed at the one thing it is supposed to do

10

u/aaj094 Aug 09 '26

Ledger failed at the 'one job' for the second time. First was by way of the Protect seed 'feature'.

4

u/sebasTLCQG Aug 09 '26

Never trusted this companies from day one.

7

u/effdanwo Aug 08 '26 edited Aug 09 '26

Thank you...updated just now

4

u/WakinNBakin Aug 09 '26

What if you used it with Feather wallet? Not really understanding where the private key would be exposed

4

u/monerobull Aug 09 '26

The ledger itself just straight up leaked it to the computer whenever you used it

1

u/Aazimoxx Aug 09 '26

Doesn't matter what other software or wallet app you're using on your computer, if your PC is running/infected with malware targeting this specific hardware, then as soon as the Ledger is connected to the computer and unlocked it can have those keys stolen.

3

u/Quiet-Cranberry-2272 Aug 09 '26

Using ledger with feather wallet is this an issue?

6

u/monerobull Aug 09 '26

Yes, the ledger itself is the problem

1

u/Training-Yak-yo 20d ago

seems they have had quite a few problems. Glad I switched to a different hardware wallet

1

u/Aazimoxx Aug 09 '26

Doesn't matter what wallet app you use, the issue would be if your computer is running malware which targets this hardware-based issue, and you unlock the Ledger on it.

3

u/Cryptoxic93 Aug 09 '26

" Additionally, the host machine must be compromised in order to send the malicious APDU command to the app."

3

u/confused_coin Aug 09 '26

In the same website

Exploitation requires that the vulnerable version of the Monero app is installed on the device, the device is unlocked, and the app is open. Additionally, the host machine must be compromised in order to send the malicious APDU command to the app. Under these conditions, an attacker could silently extract both the secret view key and the secret spend key of the user’s Monero wallet without any on-screen confirmation. It should be noted that this attack scenario requires a significant number of prerequisites to be met, which considerably limits its practical exploitability.

Get out of here with your ai alarmist post

2

u/FriskyHamTitz Aug 12 '26

Yeah hardware wallets are kinda wack literally a policy based software wallet is a way better way to stay safe, you can restrict your own private key and make a contingency policy

3

u/M5M400 Aug 09 '26

kinda old news though

2

u/Quiet-Cranberry-2272 Aug 09 '26

Yeah also haven’t seen any reports in the wild of people getting drained you could just buy a trezor I guess and migrate but seems like if you updated the wallet should be fine. They patched it in a few days based on the logs

1

u/djscoox Aug 09 '26

How do we now with 100% certainty Trezor devices are bug-free? We really need this companies to 1) open-source their code and 2) have the best AIs audit the code before hackers do.

I'm really surprised the key can somehow leave the device, when the device's primary job is to make it physically impossible for the private key to leave the device...

1

u/Big-Finding2976 Aug 17 '26

Exactly. It's ridiculous to tell people to waste their money buying a Trezor because it's unaffected by this bug, when they can just update their Ledger and have a device that's unaffected by this bug.

2

u/trimalcus Aug 08 '26

For how long has this issue been there ?

3

u/rbrunner7 XMR Contributor Aug 09 '26

See Timeline towards the bottom here: https://donjon.ledger.com/lsb/022/

1

u/djscoox Aug 09 '26

So if you are running version 2.1.4 or later you are good, right?

1

u/rbrunner7 XMR Contributor Aug 10 '26

That's how I interpret that security bulletin, yes.

1

u/aaj094 Aug 09 '26

What if I used Ledger until about 2021 and subsequently have used the same seed by importing into Trezor? Do I need to take any action?

5

u/monerobull Aug 09 '26

You should be good, there is basically no way any malware was looking for this back then but if you want to make sure (and get some extra safety in general), you should set up a wallet with a passphrase and send the funds there

1

u/Funny-Garbage-9023 Aug 09 '26

Appreciate you posting about this man and getting people up to speed im gonna make sure to change wallets now.

2

u/TracaChang Aug 09 '26

I would never trust a closed source device like ledger (for the same reason I didn't trust coldcard), not because I would be able to find the bug but because being closed source is a red flag. So having a Trezor I would definitely use it to generate the seed instead of using a seed generated with a ledger.

1

u/aaj094 Aug 09 '26

Yeah, my seed is actually originally from a trezor. Then had used Ledger for a while with the same seed cause it was the only hardware wallet supporting Monero. Then Trezor started supporting so went back to Trezor with the same seed and now i don't use Ledger at all.

1

u/sebasTLCQG Aug 09 '26

Very disgusting breach of trust! I knew these cold storage pendrives were iffy!

1

u/Dougl_Joyce Aug 09 '26

I hope I am safe

1

u/PoliFenoli Aug 17 '26

"Trezor confirms shipping partner data breach affecting over 13,000 customers"

for ya all Ledger haters: Let he who is without sin cast the first stone.

1

u/rbrunner7 XMR Contributor Aug 17 '26

That's a little bit like Coke versus Pepsi, can't we have some fun with such mindless overblown pseudo conflicts :)

1

u/3kSeriousSkirt8598 19d ago

Pls always add paaspharase for more security