Donjon CTF 2020: Capture the Fortress 21 October 2020 We are thrilled to officially announce the Ledger Donjon CTF, which will begin next week on October 28 10:00 CEST! We encourage participants to register and find about the details on the dedicated
Tech Raising the bar for security with Ledger Swap 13 October 2020 With Ledger Swap you can exchange coins in Ledger Live, easily and securely. Swapping coins is as easy as sending a transaction. It requires no address verification while enhancing the state of the
Donjon Follow-up on PIN verification against side-channel attack: KeepKey Hardware Wallet Under The Scope 18 May 2020 We mounted a 2-steps side-channel attack on the PIN verification function storage_isPinCorrect_impl of the KeepKey hardware wallet. If an attacker has a physical access to the device, the attack exposes the user PIN
Donjon Lit by Laser: PIN Code Recovery on Coldcard Mk2 Wallets 18 May 2020 Coldcard is a Bitcoin hardware wallet from Coinkite manufacturer. The platform runs on a standard STM32 microcontroller paired with a secure memory which provides secure storage of the seed behind authentication protection. Relying
Tech Developing Nano apps in Rust 29 November 2019 Bringing a modern language and memory safety into our applications.
Donjon Ledger's CTF 2018 and side-channels 10 September 2019 In this article we will showcase one use of our tool named Rainbow: breaking a ‘whiteboxed’ AES encryption using Differential Computation Analysis.
Donjon Everybody be Cool, This is a Robbery! 9 August 2019 The Ledger Donjon spends significant time and effort to assess the security of every piece of Ledger technology — along with our industry’s. During a recent security audit we uncovered vulnerabilities in a
Donjon OLED screen (minor) vulnerability 7 August 2019 On May 7, security researcher Christian Reitter contacted us through our Bounty program to inform us of a side-channel vulnerability which could potentially allow an attacker to spy on users of hardware wallets,
Donjon Funds are SSSAFU - Stealing the funds of all HTC EXODUS 1 users 16 July 2019 HTC EXODUS 1 phones come with an integrated hardware wallet. This wallet allows to backup its [master seed](https://bitcoin.org/en/glossary/hd-wallet-seed) by splitting it and sending it to "trusted contacts". Three trusted contacts are normally required
Donjon Unfixable Seed Extraction on Trezor - A practical and reliable attack 1 July 2019 An attacker with a stolen device can extract the seed from the device. It takes less than 5 minutes and the necessary materials cost around 100$. This vulnerability affects Trezor One, Trezor T,