Good day everyone,
I hope you are all well, welcome to CryptoGod-1’s blog on all things Crypto. I hope you are all well, in the last day or so some very interesting, and something terrifying news has emerged for all users of Ledger for storing their crypto. Here I will go through the details and reactions of what exactly has happened and why it is bad news for users.
What is Ledger
Ledger is a crypto cold wallet storage maker based out of Paris. The hardware wallets as they are known work by linking a user's crypto to a USB thumb drive, storage the information of their crypto assets in the wallet. While the crypto itself is not actually 'in' the wallet, the advantage of a cold wallet is that it is not required to be connected to the internet all the time, unlike hot wallets such as MetaMask. They are considered more secure in this respect and are a favourite amongst the 'old school' crypto community.
Ledger is one of the most popular and trusted brands of cold storage wallets, and when a user purchases a wallet and sets it up, they are given a unique and random string of words, called a seed phrase or secret key. This is used as a wallet recovery mechanism, and can ensure a user can recover their crypto assets even if the physical cold wallet gets damaged.
Secret keys have always been somewhat controversial, with many newer users in the crypto space uneasy with storing these codes and afraid of losing them. Users are instructed to write the phrase down and hide it away somewhere safe but many have been known to misplace them over the years. If a secret key is lost, there is no method of recovery for the wallet, meaning the crypto is basically lost forever. The secret key can also be used to 'crack' the wallet if a bad actor gets their hands on the code.
Update and News
In a post on Twitter, Ledger announced they have released an update for their crypto storage known as Ledger Recover. It will be launching soon, and as shown in the video below, "Ledger Recover is an optional subscription for users who want a backup of their Secret Recovery Phrase. You don’t have to use it, and can continue managing your recovery phrase yourself if that’s why you bought a Ledger."
However, it has since emerged that it is not quite as straightforward as being made out. We all understand that the secret key is the main component for accessing a wallet, whether its a hot or cold wallet, and with this information anybody can gain access to the crypto within the wallet. While this new feature will aim to offer a safeguard if a user loses access to their private keys, many are sceptical of the feature. According to the Ledger website:
“When you subscribe to Ledger Recover, a pre-BIP39 version of your private key is encrypted, duplicated and divided into three fragments, with each fragment secured by a separate company – Coincover, Ledger and an independent backup service provider. Each of these encrypted fragments is useless on its own. When you want to get access to your wallet, 2 of the 3 parties will send fragments back to your Ledger device, reassembling them to build your private key.”
It is a paid for subscription service which aims to give an additional layer of protection, making use of a technique where a users seed phrase is divided into three encrypted fragments, with each sent to different external entities. These fragments are kept separate, but once combined and decrypted, they can be used to recreate the original seed phrase. It is an optional service which users need not avail of, but according to Ledger CEO Pascal Gauthier during a Twitter Space, it is something users have been asking for:
"You’re saying this is not what customers want. Actually, this is what future customers want,” he said. “This is the way that the next hundreds of millions of people will actually onboard to crypto.”
The wallet provider shared that Ledger Recover is an optional subscription for users who want to back up their secret recovery phrase. “You don’t have to use it, and can continue managing your recovery phrase yourself if that’s why you bought a Ledger,” the company explained.
Nevertheless, the concept has enraged many in the crypto community, including security specialists.
Mudit Gupta, the chief information security officer at Polygon Labs, shared, “It’s a horrendous idea, DON’T enable this feature.” Gupta expanded further in his Twitter thread that “[t]he problem here is that the encrypted keys parts are sent to 3 corporations and they can reconstruct your keys.”
Reaction
The reaction on Reddit and Twitter has been very interesting to say the least. Most users are unhappy, while others are furious. Many are claiming that Ledger have basically been lying and they are immediately putting an end to use of their ledger. Some funny videos have been made to lighten the situation, although it is distressing news for anybody who uses the devices.
Below is from @AshleyDCan where she makes a mock video of Ledger Support at the moment.
Here is user @oklahodl1 who shows his ledger being smashed and burnt after he has discovered it is not as safe as he expected.
Basically the biggest worry for users is that Ledger have basically put a 'backdoor' system in place for hackers and bad actors to try steal the phrases for wallets. When a user purchases a wallet, they purchase it under the knowledge that when their secret key is created it is only revealed to them. Now that hackers will know they have a way of getting the secret keys via a digital means, this indeed poses a threat. Ledger has also got a somewhat shady past in terms of security with their servers, as noted by @iamDCinvestor below.
Indeed users now have a big decision to make. Do they continue to make use of their Ledger devices, or is it perhaps time to look elsewhere? You know when Binance founder CZ starts to comment things are not looking well.
Only time will tell if Ledger do indeed go ahead with this, whether it does it automatically even if you don't subscribe to the service, and really just how secure all of this is. Hopefully answers will emerge as more information does, but for every Ledger user out there, keep an eye on the development.
"Not your keys, not your crypto" as they say.
Have a great day.
Peace. CryptoGod-1.
Referral Links and Follow Me: