• bitcoinBitcoin (BTC) $ 62,854.00
  • ethereumEthereum (ETH) $ 2,441.23
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 568.96
  • solanaSolana (SOL) $ 146.05
  • usd-coinUSDC (USDC) $ 1.00
  • xrpXRP (XRP) $ 0.534344
  • staked-etherLido Staked Ether (STETH) $ 2,440.78
  • dogecoinDogecoin (DOGE) $ 0.111442
  • the-open-networkToncoin (TON) $ 5.33
  • tronTRON (TRX) $ 0.154757
  • cardanoCardano (ADA) $ 0.357368
  • avalanche-2Avalanche (AVAX) $ 26.89
  • shiba-inuShiba Inu (SHIB) $ 0.000018
  • wrapped-stethWrapped stETH (WSTETH) $ 2,874.62
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 62,730.00
  • wethWETH (WETH) $ 2,437.01
  • chainlinkChainlink (LINK) $ 11.28
  • bitcoin-cashBitcoin Cash (BCH) $ 324.82
  • polkadotPolkadot (DOT) $ 4.19
  • daiDai (DAI) $ 1.00
  • leo-tokenLEO Token (LEO) $ 6.02
  • nearNEAR Protocol (NEAR) $ 4.91
  • uniswapUniswap (UNI) $ 7.03
  • litecoinLitecoin (LTC) $ 67.46
  • suiSui (SUI) $ 1.83
  • bittensorBittensor (TAO) $ 599.51
  • aptosAptos (APT) $ 8.63
  • pepePepe (PEPE) $ 0.000010
  • wrapped-eethWrapped eETH (WEETH) $ 2,558.47
  • internet-computerInternet Computer (ICP) $ 8.48
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.46
  • kaspaKaspa (KAS) $ 0.143707
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.383139
  • ethereum-classicEthereum Classic (ETC) $ 18.78
  • stellarStellar (XLM) $ 0.092241
  • moneroMonero (XMR) $ 147.66
  • blockstackStacks (STX) $ 1.83
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • okbOKB (OKB) $ 41.71
  • dogwifcoindogwifhat (WIF) $ 2.53
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • immutable-xImmutable (IMX) $ 1.51
  • aaveAave (AAVE) $ 149.72
  • filecoinFilecoin (FIL) $ 3.70
  • crypto-com-chainCronos (CRO) $ 0.080520
  • render-tokenRender (RENDER) $ 5.39
  • optimismOptimism (OP) $ 1.67
  • hedera-hashgraphHedera (HBAR) $ 0.053831
  • injective-protocolInjective (INJ) $ 20.75
  • arbitrumArbitrum (ARB) $ 0.556747
  • mantleMantle (MNT) $ 0.605031
  • vechainVeChain (VET) $ 0.023267
  • fantomFantom (FTM) $ 0.651990
  • cosmosCosmos Hub (ATOM) $ 4.62
  • whitebitWhiteBIT Coin (WBT) $ 11.52
  • thorchainTHORChain (RUNE) $ 4.91
  • the-graphThe Graph (GRT) $ 0.163625
  • bitget-tokenBitget Token (BGB) $ 1.10
  • sei-networkSei (SEI) $ 0.434901
  • bonkBonk (BONK) $ 0.000022
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,436.15
  • popcatPopcat (POPCAT) $ 1.39
  • flokiFLOKI (FLOKI) $ 0.000139
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,727.35
  • theta-tokenTheta Network (THETA) $ 1.33
  • makerMaker (MKR) $ 1,463.22
  • arweaveArweave (AR) $ 19.57
  • heliumHelium (HNT) $ 7.34
  • pyth-networkPyth Network (PYTH) $ 0.336574
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,548.75
  • mantra-daoMANTRA (OM) $ 1.38
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 62,617.00
  • celestiaCelestia (TIA) $ 5.30
  • gatechain-tokenGate (GT) $ 8.70
  • jupiter-exchange-solanaJupiter (JUP) $ 0.787149
  • ondo-financeOndo (ONDO) $ 0.736847
  • algorandAlgorand (ALGO) $ 0.126937
  • matic-networkPolygon (MATIC) $ 0.380427
  • quant-networkQuant (QNT) $ 69.78
  • worldcoin-wldWorldcoin (WLD) $ 1.96
  • jasmycoinJasmyCoin (JASMY) $ 0.019950
  • lido-daoLido DAO (LDO) $ 1.08
  • kucoin-sharesKuCoin (KCS) $ 7.95
  • bitcoin-svBitcoin SV (BSV) $ 46.61
  • bittorrentBitTorrent (BTT) $ 0.00000094
  • wormholeWormhole (W) $ 0.343228
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,429.58
  • coredaoorgCore (CORE) $ 0.938044
  • flowFlow (FLOW) $ 0.552608
  • fasttokenFasttoken (FTN) $ 2.54
  • based-brettBrett (BRETT) $ 0.084473
  • beam-2Beam (BEAM) $ 0.016165
  • conflux-tokenConflux (CFX) $ 0.182436
  • galaGALA (GALA) $ 0.020808
  • ethenaEthena (ENA) $ 0.294376
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,482.65
  • notcoinNotcoin (NOT) $ 0.007658
  • klay-tokenKlaytn (KLAY) $ 0.133813
  • ordinalsORDI (ORDI) $ 36.79
  • starknetStarknet (STRK) $ 0.396949
  • msolMarinade Staked SOL (MSOL) $ 178.10
  • aerodrome-financeAerodrome Finance (AERO) $ 1.19
  • flare-networksFlare (FLR) $ 0.015649
  • usddUSDD (USDD) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • eosEOS (EOS) $ 0.476244
  • neoNEO (NEO) $ 10.24
  • axie-infinityAxie Infinity (AXS) $ 4.69
  • elrond-erd-2MultiversX (EGLD) $ 25.74
  • nervos-networkNervos Network (CKB) $ 0.015738
  • ecasheCash (XEC) $ 0.000036
  • tokenize-xchangeTokenize Xchange (TKX) $ 8.63
  • tezosTezos (XTZ) $ 0.676413
  • tether-goldTether Gold (XAUT) $ 2,658.15
  • fraxFrax (FRAX) $ 0.999149
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 62,565.00
  • akash-networkAkash Network (AKT) $ 2.52
  • pendlePendle (PENDLE) $ 3.86
  • mina-protocolMina Protocol (MINA) $ 0.531040
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000029
  • the-sandboxThe Sandbox (SAND) $ 0.256918
  • eigenlayerEigenlayer (EIGEN) $ 3.24
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,493.47
  • mog-coinMog Coin (MOG) $ 0.000002
  • roninRonin (RON) $ 1.65
  • chilizChiliz (CHZ) $ 0.063582
  • dydx-chaindYdX (DYDX) $ 0.886732
  • ethereum-name-serviceEthereum Name Service (ENS) $ 17.17
  • nexoNEXO (NEXO) $ 0.993033
  • decentralandDecentraland (MANA) $ 0.294733
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.006086
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,438.26
  • axelarAxelar (AXL) $ 0.657263
  • aioz-networkAIOZ Network (AIOZ) $ 0.466863
  • neiro-3Neiro (NEIRO) $ 0.001232
  • pax-goldPAX Gold (PAXG) $ 2,682.38
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.88
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000090
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 62,882.00
  • true-usdTrueUSD (TUSD) $ 1.00
  • apecoinApeCoin (APE) $ 0.734837
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 2,634.61
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 151.65
  • raydiumRaydium (RAY) $ 1.80
  • oasis-networkOasis (ROSE) $ 0.070438
  • zksyncZKsync (ZK) $ 0.128098
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,432.09
  • safeSafe (SAFE) $ 0.954833
  • havvenSynthetix Network (SNX) $ 1.43
  • layerzeroLayerZero (ZRO) $ 4.22
  • dexeDeXe (DEXE) $ 8.14
  • echelon-primeEchelon Prime (PRIME) $ 9.57
  • superfarmSuperVerse (SUPER) $ 1.02
  • astarAstar (ASTR) $ 0.061674
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.08
  • book-of-memeBOOK OF MEME (BOME) $ 0.006504
  • metaplexMetaplex (MPLX) $ 0.444706
  • xdce-crowd-saleXDC Network (XDC) $ 0.029378
  • gigachad-2Gigachad (GIGA) $ 0.045185
  • zcashZcash (ZEC) $ 28.82
  • livepeerLivepeer (LPT) $ 12.43
  • frax-etherFrax Ether (FRXETH) $ 2,428.67
  • iotaIOTA (IOTA) $ 0.124578
  • blurBlur (BLUR) $ 0.224063
  • l2-standard-bridged-weth-blastL2 Standard Bridged WETH (Blast) (WETH) $ 2,432.36
  • theta-fuelTheta Fuel (TFUEL) $ 0.063062
  • gnosisGnosis (GNO) $ 163.10
  • beldexBeldex (BDX) $ 0.063300
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 1.00
  • arkhamArkham (ARKM) $ 1.48
  • celoCelo (CELO) $ 0.744013
  • apenftAPENFT (NFT) $ 0.00000041
  • usdbUSDB (USDB) $ 0.998263
  • dydxdYdX (ETHDYDX) $ 0.885401
  • bitcoin-goldBitcoin Gold (BTG) $ 22.51
  • compound-governance-tokenCompound (COMP) $ 44.40
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.003900
  • turboTurbo (TURBO) $ 0.005659
  • aleoALEO (ALEO) $ 3.70
  • stepnGMT (GMT) $ 0.133909
  • pepecoin-2PepeCoin (PEPECOIN) $ 3.17
  • osmosisOsmosis (OSMO) $ 0.544563
  • constitutiondaoConstitutionDAO (PEOPLE) $ 0.073842
  • kavaKava (KAVA) $ 0.342779
  • binance-peg-busdBinance-Peg BUSD (BUSD) $ 1.00
  • dogs-2Dogs (DOGS) $ 0.000704
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 2,435.12
  • safepalSafePal (SFP) $ 0.730428
  • reserve-rights-tokenReserve Rights (RSR) $ 0.006885
  • iotexIoTeX (IOTX) $ 0.037681
  • bitcoin-avalanche-bridged-btc-bBitcoin Avalanche Bridged (BTC.b) (BTC.B) $ 62,702.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.07
  • wemix-tokenWEMIX (WEMIX) $ 0.834915
  • super-oethSuper OETH (SUPEROETHB) $ 2,430.60
  • ethereum-pow-iouEthereumPoW (ETHW) $ 3.16
  • golemGolem (GLM) $ 0.339185
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 62,569.00
  • 1inch1inch (1INCH) $ 0.262763
  • mx-tokenMX (MX) $ 3.32

Researcher finds data harvesting inside Ledger Live app

0 118

Researcher finds data harvesting inside Ledger Live app

  protos.com 18 h

Researcher finds data harvesting inside Ledger Live app

Sleuths have discovered a vast data harvesting operation by the world’s largest hardware wallet manufacturer, Ledger. For reasons that are difficult to comprehend, Ledger Live software transmits information about clicks, page visits, redirects, crypto transactions, page scrolls, numbers of accounts, crypto asset names, session durations, hardware device types, and firmware versions to Ledger’s analytics provider.

Ledger Live is the official software for interfacing with any Ledger hardware wallet. The vast majority of PC users download this software in order to set up their hardware wallet and sign transactions. While inspecting its code, REKTbuildr found that user tracking is built into the entire software suite. He called it a “gigantic user tracking system.”

Cleaning user tracking code from Ledger Live code and JFC the whole thing is a gigantic user tracking system

There’s analytics trackers for nearly all events, on most screens.

Ledger Live is a user data collection tool

How is this system even accepted by the crypto community?

— REKTBuildr 🔺🔺🔺 (@rektbuildr) December 6, 2023

The application is sending tracking data to a service called segment.io. This data includes information on digital assets and NFTs stored on Ledger wallets.

A risky Ledger Live default setting

The Protos team did find that there is an option to turn off at least some of these analytics in Ledger Live’s settings. The settings tab of Ledger Live says enabling analytics will send data on “clicks, page visits, redirections, actions (send, receive, lock, etc), end of page scrolls, (un)installing and app version, number of accounts, crypto assets and operations, session durations, the Ledger device type and firmware.”

Researcher finds data harvesting inside Ledger Live app

Ledger Live’s data harvester is a JSON object with a properties key. It transmits user ID and a ‘writeKey,’ which can uniquely identify the PC. It can also send segment.io account information including names of digital assets owned and other information about users’ computers.

Although Ledger Live doesn’t send private keys or recovery phrases to segment.io, it sends plenty of information about a user that could subject users to extortion attacks. Any segment.io hacker, for example, could easily identify any user with substantial crypto holdings — including timestamps of crypto activities and other terrifyingly detailed information about assets.

Aggregating Ledger users as a high-value audience package

A likely commercial explanation for all the data harvesting, REKTbuildr speculated, is that Ledger wants to resell anonymized data to third-party advertisers. Prepackaged IP or cookie ‘audiences’ with thousands of users who have engaged in a recent digital action, such as clicking a button within a crypto app, for example — are commonly resold to advertisers by data aggregators like Google, Bluekai, or eXelate.

Alternatively, the data could be used internally for user experience (UX) and user interface (UI) workers at Ledger.

As a courtesy to the community, REKTbuildr forked Ledger Live software, removed its tracking codes, and uploaded the patched software to GitHub.

Naturally, Ledger had very little to say about analytics harvesting on its social media. Its disinterest comes as little surprise to the digital asset community.

Ledger has already shocked the community’s trust in its hardware wallets. In May, it announced a controversial Recover service that shared abilities to remotely decipher the private keys on one’s hardware wallet. It unapologetically pushed that update live, eliminating years of perception that private keys never left a hardware wallet.

Another lowlight in Ledger’s history includes its email database. Hackers exposed millions of its users’ emails, which led to users receiving fake wallets in a likely phishing attack. Experts quickly posted warnings.

In summary, Ledger is tracking user data, possibly for its own UI/UX workers, or to profit from resale. Luckily, users have alternatives, including tracker-free forked versions of the software, or using the hardware wallet itself without installing Ledger Live software at all.

Source

Leave A Reply

Your email address will not be published.