Hacker News new | ask | show | jobs
by neom 921 days ago
I thought the whole point of ledger was that it's a physical wallet that can't easily be compromised. Not your keys not your crypto and all that?
1 comments

This was a UI popup that got injected into the middleware provided by Ledger that is used to make it easy for apps to prompt Ledger users for a signature. The keys aren't compromised by this attack, this is more similar to a phishing attack, but via supply chain to increase fake legitimacy.