Hackers strike Ledger’s Discord

-

Ledger’s Discord server just got hit, and not by some small-time crook. A hacker took over a moderator’s account and started spreading phishing links like wildfire.

The target? Your precious wallet seed phrases.

Access

On the weekend, the attacker hijacked a moderator’s account and blasted out messages claiming there was a fresh vulnerability in Ledger’s system.

ledger
X

The scam urged users to verify their seed phrases by clicking a dodgy link.

If you fell for it, you’d be handing over the keys to your crypto vault, no questions asked.

Ledger’s own guy, Quintin Boatwright, said they jumped on it fast, kicked out the compromised mod, nuked the malicious bot, reported the scam site, and tightened security like Fort Knox.

But it gets messier. Some people in the community say the hacker used those mod powers to ban and mute users trying to sound the alarm.

So, instead of a quick heads-up, the scam got a little runway to spread. Classic move, silence the whistleblowers, delay the response.

And screenshots of those fake warnings were all over X, making the rounds like wildfire.

Infection

Now, this isn’t Ledger’s first rodeo with scammers. Back in April, bad actors sent out physical letters to Ledger customers.

These weren’t your grandma’s spam flyers, they looked legit, branded with Ledger’s logo, and pushed users to scan QR codes and enter recovery phrases for security checks.

Many reckon these mailings tie back to a 2020 data breach where hackers leaked personal info of over 270,000 Ledger customers, names, phone numbers, addresses, every freakin’ thing.

And if that wasn’t enough, some users even reported receiving fake Ledger devices loaded with malware the following year. Talk about being targeted by pros.

Vulnerabilities

And while Ledger’s battling phishing storms, the crypto industry’s got its own drama. Ethereum’s latest Pectra upgrade brought in EIP-7702, which security experts are calling a critical vulnerability.

It lets hackers potentially take over wallets without the user’s say-so.

On the BNB Chain front, Mobius Token got drained for $2.15 million thanks to a malicious smart contract that swapped stolen tokens for stablecoins. Yeah, the bad guys are busy, no doubt.


Disclosure:This article does not contain investment advice or recommendations. Every investment and trading move involves risk, and readers should conduct their own research when making a decision.

Kriptoworld.com accepts no liability for any errors in the articles or for any financial loss resulting from incorrect information.

LATEST POSTS

MediaTek Vulnerability Exposed Crypto Seed Phrases on Android Phones

A MediaTek vulnerability allowed attackers to steal crypto seed phrases from some Android phones in about 45 seconds, according to Ledger’s Donjon security team. The...

Binance.US CEO Change Puts Stephen Gregory at Center of US Expansion Plan

Binance.US has named Stephen Gregory as its new chief executive officer as the crypto exchange moves deeper into its next phase in the US crypto...

Tether Invests $50M in Eight Sleep as AI Sleep Tracking Startup Reaches $1.5B Valuation

Tether led a $50 million investment round in Eight Sleep, an AI sleep tracking and sleep technology startup. The round valued Eight Sleep at $1.5...

Binance Says Sanctions Exposure Fell 97% Since 2024 as Iran Links Come Under Fresh Focus

Binance said its Binance sanctions exposure dropped about 97% since January 2024. The exchange said its exchange volume exposure tied to sanctioned entities now sits...
123FollowersFollow

Most Popular

Guest posts