The security research at Ledger.

Paris
Donjon is the Security Research team at @Ledger. Follow us to get the the latest news from our research. More info on our blog: ledger-donjon.github.io/
11
68
81
We regularly communicate about the results we achieve. But sometimes, the journey matters just as much as the result. We recently managed to bypass the RP2350-A4 debug protection using an innovative approach combining two techniques: photon emission imaging and laser fault injection. Here our technical blogpost: donjon.ledger.com/blog/rp235… A big thank you to @Raspberry_Pi for the collaboration and for highlighting this work. 💥
Lasers. Microscopes. $250K. One secured chip. Ledger Donjon just showed how they cracked debug access on RP2350-A4, a break worthy of Raspberry Pi's own Hacking Challenge. Respin or no respin? Raspberry Pi says no. Read why: raspberrypi.com/news/everyth…
2
10
62
24,871
We’re releasing an open EM side-channel dataset for ML-KEM (Kyber) 🔓 • 200k traces × 3 implementations (ref, pqm4, masked mkm4) • Windowed on the pair-pointwise polynomial multiplication • Per-share traces for 2nd-order analysis • STM32F407 Cortex-M4, NumPy format Lowering the barrier to PQC side-channel research. We’ll be presenting the work at OPTIMIST, a CHES 2026 workshop, come and discuss it with us in Antalya! 📜 Paper: eprint.iacr.org/2026/1851 📅 OPTIMIST: optimist-ose.org/ches26
1
9
38
2,947
Ledger Donjon retweeted
As I said the other day: reproducing an already-patched bug is not "hacking Ledger." What this thread describes is a vulnerability in an outdated version of the Ethereum app. It was identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post. No user was hacked. No exploitation in the wild. Running an exploit against an old version after the fix has shipped is a lab exercise, not a finding. And the takeaway hasn't changed. All software has bugs; the question is what happens next. Our model: bugs get found, by @DonjonLedger and by external researchers, they get fixed on every device in the field, and every fix gets a public bulletin. Update your apps to the latest version, Ethereum app 1.22.3+, via Ledger Wallet, and verify the app version on your device, not just the firmware. They update separately. Stay safe.
No Ledger user was hacked. What's described here is a lab reproduction of a vulnerability in an outdated version of the Ethereum app. The issue was already identified through our security process and fixed in Ethereum app 1.22.2, released August 13, before this post. The security bulletin has been public since then: donjon.ledger.com/lsb/. There is no evidence of exploitation in the wild. A word on how this works, because it matters: All software has bugs. Hardware wallets are no exception. That's why updateability is a core part of Ledger's security architecture: when a vulnerability is found, whether by our own Donjon team or by external researchers, we can patch every device in the field. A wallet that can't be updated can't be fixed. This is a process we run continuously, not a one-off. We ship regular security updates, publish a security bulletin on the Ledger Donjon site donjon.ledger.com, and work with external researchers through our bug bounty program. That track record, finding, fixing, and disclosing, is what security maturity looks like. The alternative isn't wallets without bugs; it's wallets where you never hear about them. What to do: update your firmware applications to the latest available and Ethereum app to 1.22.3+ via Ledger Wallet, and verify the app version on your device, not just the firmware. Apps and firmware update separately.
20
20
151
21,422
Our applied PQC series continues. This time, @k15ab_ and @6c656e69 attack masked Kyber768. Masking defeats first-order SCA. But with a centered cross-product and the right covariance model, a second-order CPA recovers the secret coefficient. donjon.ledger.com/blog/secon…
1
4
17
4,493
Ledger Donjon retweeted
🤖AI didn't just add a tool to the developer toolbox. It changed the economics of security itself. Attackers can now explore faster, iterate cheaper, and scale offense at machine speed. They won't wait for the perfect model. Neither can defenders. The tempting move is to wait for the next frontier model. But let's be honest, it's just a way to avoid doing the work. 😏 A model is not a security capability. A prompt is not an agent. Asking your IDE "is this secure?" will not build you an offensive security team. This is why the @DonjonLedger built Cerberus. Not a model. A harness around models: iteration loops, memory, tools, backlog, triage, verification, auditability, budgets, and human control. Security has never been one answer. It's a loop. The hard part is the last mile. A hypothesis is not a finding. You have to reproduce it, exploit it, prove the impact, verify the preconditions, produce evidence an engineer can act on, then fix it. AI has to take the team all the way, not stop at a plausible report. Plausibility is dangerous in security. This is already producing real, exploitable vulnerabilities across very different stacks (C, .NET, Scala and more), responsibly disclosed. CVEs, PRs, fixes, real impact. Both of these are true at once: AI floods the channel with noise, and buried in that noise are real attackers who know how to use these systems properly. Security has always been cat and mouse. AI didn't create that reality. It made it visible, and it dropped the price of a cat to almost nothing. The cats are everywhere now.🐈🐈🐈 No fight, no chance. Read more in the latest Donjon's article: donjon.ledger.com/blog/ai-se…
9
6
29
3,194
AI is changing the economics of offensive security. More scale. Lower cost. Faster iteration. At Ledger Donjon, we’re building Cerberus: a team of agents that audit, triage, prove, and patch with humans in the loop. No fight, no chance. ✍️ @b0l0k_ donjon.ledger.com/blog/ai-se…
3
18
2,341
Ledger Donjon retweeted
⚡"Breaking Post Quantum Cryptography with AI" A non-profiled deep-learning side-channel attack on an unprotected reference implementation. The convolutionnal neural network just plays the role CPA's correlation used to play. The @DonjonLedger 's PQC journey continues. They pointed their open-source deep-learning SCA tooling at the NIST-standardized ML-KEM reference. No clone device. No profiling phase. No fixed leakage model. Only EM traces, chosen ciphertexts, and a small MLP trained per key hypothesis. The correct key is the one under which the network actually learns. ~400 traces. Unprotected target, no masking, no shuffling. - ML-KEM is mathematically sound and standardized. - A reference implementation running on a real chip, without countermeasures, leaks the secret in minutes. PQC security does not stop at standardization. It starts when implementations meet real-world attackers, with probes, not just headlines. Read the article: donjon.ledger.com/blog/non-p…
46
20
79
5,372
We continue our series on applied PQC. This time, a study of side-channel attacks on ML-KEM by @k15ab_ and Alain M. Math is the foundation, but in the real world, attackers have other tricks. ledger.com/blog-risk-side-ch…
3
6
23
2,477
Ledger Donjon retweeted
Security is an economic game: make attacks too expensive to attempt. AI is breaking that equation. Exploits that took months and seven-figure budgets now take hours with an AI subscription. The old playbook won't cut it. The asymmetry that kept us secure is gone...
130
56
181
29,078
Ledger Donjon retweeted
🚨Only days after Coruna, one of the first large-scale iOS exploit kits, DarkSword is already being exploited in the wild. Coruna showed the pattern: state-grade iOS exploits don’t stay in government hands. They leak, spread, and end up in broader ecosystems. One visit to a compromised site, and your phone, including your crypto, is gone. DarkSword confirms it. - Another state-grade exploit chain. - Already reused by multiple actors. - Already deployed at scale via watering-hole attacks. - Targets so far: Ukraine, Saudi Arabia, Turkey, Malaysia. - Victim model: anyone who visits a compromised but legitimate website. ⚠️No click. No warning. Full device compromise. Data exfiltration. Real-time surveillance. Total loss of control. Affected: iOS 18.4 → 18.7. This used to be rare. Targeted. Surgical. Now it’s industrialized. 👉Two major iOS exploit chains in less than a week isn’t noise, it’s a shift. From now, you should assume your phone is compromised, Stop treating it like a safe. x.lingyaoai.com/P3b7_/status/202956506…
🚨 All it takes is one website and your crypto disappears: Coruna may be the EternalBlue moment for iOS exploits. For years, large-scale exploitation of iPhones was considered impractical. Coruna proves otherwise. Recently exposed by the Google Threat Intelligence Group, Coruna is a modular, state-grade iOS exploit kit that shows how sophisticated cyber capabilities developed by governments or surveillance actors can eventually leak into criminal ecosystems. The framework contains five complete exploit chains built from 23 vulnerabilities targeting Apple devices. These chains combine: - WebKit remote code execution - Privilege escalation - PAC (Pointer Authentication) bypass (!!) - Sandbox escape - Page Protection Layer bypass Together, they enable full compromise of an iPhone from a simple website visit. The implications are immediate. Coruna has already been used primarily for cryptocurrency theft. The attack path is brutally simple: your keys sit in a software wallet on your iPhone, you visit a compromised website, and your crypto is gone. Once inside the device, the malware can: - Steal assets from software wallets - Extract seed phrases stored in Apple Notes or in your photos - Harvest photos, emails, and other sensitive data Researchers observed the toolkit targeting 18 cryptocurrency apps, including MetaMask, Trust Wallet, and Exodus Wallet. Coruna works out of the box against devices running iOS 13 through iOS 17.2.1, covering releases from 2019 to 2023. That represents hundreds of millions of potentially vulnerable devices worldwide. So far, researchers estimate that tens of thousands of iPhones have actually been infected. More recent iOS versions are also actively targeted by nation-state actors, though not exploited yet at this scale. But the trajectory is clear: as exploit development accelerates, particularly with the assistance of AI, these capabilities will become cheaper and more widely available. Large-scale mobile compromise will become more common. The lesson is straightforward: Storing valuable secrets on general-purpose devices is fundamentally risky. When a single browser visit can compromise the entire mobile phone, relying on software wallets to protect high-value assets is no longer a defensible security model. For those interested by the technical details, I recommend this excellent report from Google Threat Intelligence group. cloud.google.com/blog/topics…
4
15
52
22,000
Ledger Donjon retweeted
Our phones were never designed to be secure vaults. The @DonjonLedger proves that every single day. For years, we’ve trusted our phones to protect everything: our data, our identity, our money. But smartphones are inherently fragile. They’re multipurpose, always-connected devices built for convenience first — not hardened security. That model may have been enough for the early internet of information. It doesn’t work for the internet of value. When a single vulnerability can put hundreds of millions of devices at risk, it’s a reminder of a simple truth: the device you use every day should not be the final line of defense for your digital value. 875 million Android devices can be compromised in under 60 seconds. That’s exactly why your phone should never be where your value ultimately lives. Pair it with a @Ledger signer and use the Ledger Wallet app. shop.ledger.com/?srsltid=Afm… forbes.com/sites/daveywinder…
124
42
150
4,908
Ledger Donjon retweeted
🚨 @DonjonLedger has struck again discovering a MediaTek vulnerability potentially impacting millions of Android phones. Another reminder that smartphones aren’t built for security. Even when powered off, user data - including pins & seeds - can be extracted in under a minute.
104
112
428
155,935