• bitcoinBitcoin (BTC) $ 61,884.00
  • ethereumEthereum (ETH) $ 3,410.58
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 410.37
  • solanaSolana (SOL) $ 130.48
  • xrpXRP (XRP) $ 0.620177
  • staked-etherLido Staked Ether (STETH) $ 3,404.71
  • usd-coinUSDC (USDC) $ 1.00
  • cardanoCardano (ADA) $ 0.726975
  • dogecoinDogecoin (DOGE) $ 0.134020
  • avalanche-2Avalanche (AVAX) $ 42.81
  • tronTRON (TRX) $ 0.140451
  • shiba-inuShiba Inu (SHIB) $ 0.000021
  • polkadotPolkadot (DOT) $ 9.13
  • chainlinkChainlink (LINK) $ 20.44
  • matic-networkPolygon (MATIC) $ 1.08
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 61,830.00
  • bitcoin-cashBitcoin Cash (BCH) $ 483.54
  • uniswapUniswap (UNI) $ 12.29
  • the-open-networkToncoin (TON) $ 2.66
  • litecoinLitecoin (LTC) $ 90.12
  • internet-computerInternet Computer (ICP) $ 13.18
  • daiDai (DAI) $ 1.00
  • filecoinFilecoin (FIL) $ 9.69
  • ethereum-classicEthereum Classic (ETC) $ 33.05
  • cosmosCosmos Hub (ATOM) $ 11.86
  • immutable-xImmutable (IMX) $ 3.26
  • nearNEAR Protocol (NEAR) $ 4.26
  • leo-tokenLEO Token (LEO) $ 4.75
  • blockstackStacks (STX) $ 3.05
  • aptosAptos (APT) $ 11.54
  • bittensorBittensor (TAO) $ 646.12
  • optimismOptimism (OP) $ 3.99
  • kaspaKaspa (KAS) $ 0.167940
  • stellarStellar (XLM) $ 0.134002
  • hedera-hashgraphHedera (HBAR) $ 0.112420
  • crypto-com-chainCronos (CRO) $ 0.141460
  • injective-protocolInjective (INJ) $ 41.13
  • vechainVeChain (VET) $ 0.048725
  • okbOKB (OKB) $ 56.92
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • the-graphThe Graph (GRT) $ 0.331168
  • render-tokenRender (RNDR) $ 7.98
  • lido-daoLido DAO (LDO) $ 3.34
  • mantleMantle (MNT) $ 0.891859
  • celestiaCelestia (TIA) $ 16.58
  • moneroMonero (XMR) $ 147.75
  • arbitrumArbitrum (ARB) $ 2.07
  • theta-tokenTheta Network (THETA) $ 2.34
  • bitcoin-svBitcoin SV (BSV) $ 115.46
  • sei-networkSei (SEI) $ 0.844877
  • arweaveArweave (AR) $ 32.90
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,752.06
  • fetch-aiFetch.ai (FET) $ 1.94
  • algorandAlgorand (ALGO) $ 0.241801
  • suiSui (SUI) $ 1.57
  • makerMaker (MKR) $ 2,069.03
  • elrond-erd-2MultiversX (EGLD) $ 69.97
  • pepePepe (PEPE) $ 0.000004
  • quant-networkQuant (QNT) $ 125.47
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,489.14
  • beam-2Beam (BEAM) $ 0.034575
  • flowFlow (FLOW) $ 1.16
  • thorchainTHORChain (RUNE) $ 5.60
  • aaveAave (AAVE) $ 112.37
  • ordinalsORDI (ORDI) $ 77.27
  • dogwifcoindogwifhat (WIF) $ 1.62
  • flare-networksFlare (FLR) $ 0.045799
  • dydx-chaindYdX (DYDX) $ 3.64
  • galaGALA (GALA) $ 0.043605
  • bonkBonk (BONK) $ 0.000023
  • the-sandboxThe Sandbox (SAND) $ 0.652007
  • havvenSynthetix Network (SNX) $ 4.39
  • fantomFantom (FTM) $ 0.511583
  • mina-protocolMina Protocol (MINA) $ 1.35
  • axie-infinityAxie Infinity (AXS) $ 10.25
  • axelarAxelar (AXL) $ 2.34
  • bittorrentBitTorrent (BTT) $ 0.000001
  • starknetStarknet (STRK) $ 1.87
  • chilizChiliz (CHZ) $ 0.151091
  • apecoinApeCoin (APE) $ 2.21
  • bitget-tokenBitget Token (BGB) $ 0.926811
  • singularitynetSingularityNET (AGIX) $ 1.02
  • true-usdTrueUSD (TUSD) $ 1.00
  • flokiFLOKI (FLOKI) $ 0.000130
  • heliumHelium (HNT) $ 8.81
  • corgiaiCorgiAI (CORGIAI) $ 0.004031
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000060
  • kucoin-sharesKuCoin (KCS) $ 12.96
  • tezosTezos (XTZ) $ 1.37
  • tokenize-xchangeTokenize Xchange (TKX) $ 15.36
  • eosEOS (EOS) $ 1.05
  • whitebitWhiteBIT Coin (WBT) $ 8.20
  • decentralandDecentraland (MANA) $ 0.633916
  • worldcoin-wldWorldcoin (WLD) $ 7.99
  • neoNEO (NEO) $ 16.20
  • klay-tokenKlaytn (KLAY) $ 0.312680
  • dydxdYdX (ETHDYDX) $ 3.64
  • oasis-networkOasis Network (ROSE) $ 0.161541
  • jasmycoinJasmyCoin (JASMY) $ 0.022003
  • blurBlur (BLUR) $ 0.729196
  • akash-networkAkash Network (AKT) $ 4.51
  • frax-etherFrax Ether (FRXETH) $ 3,395.09
  • pyth-networkPyth Network (PYTH) $ 0.677960
  • gnosisGnosis (GNO) $ 395.49
  • conflux-tokenConflux (CFX) $ 0.271589
  • cheeleeCheelee (CHEEL) $ 17.83
  • kavaKava (KAVA) $ 0.935638
  • osmosisOsmosis (OSMO) $ 1.60
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000173
  • iotaIOTA (IOTA) $ 0.318475
  • woo-networkWOO (WOO) $ 0.532892
  • wemix-tokenWEMIX (WEMIX) $ 2.60
  • astarAstar (ASTR) $ 0.164511
  • roninRonin (RON) $ 2.93
  • msolMarinade staked SOL (MSOL) $ 150.56
  • dymensionDymension (DYM) $ 6.00
  • ecasheCash (XEC) $ 0.000044
  • swethSwell Ethereum (SWETH) $ 3,480.65
  • jupiter-exchange-solanaJupiter (JUP) $ 0.600836
  • pancakeswap-tokenPancakeSwap (CAKE) $ 3.27
  • nexoNEXO (NEXO) $ 1.38
  • illuviumIlluvium (ILV) $ 120.37
  • curve-dao-tokenCurve DAO (CRV) $ 0.662204
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,652.31
  • manta-networkManta Network (MANTA) $ 2.94
  • usddUSDD (USDD) $ 0.999376
  • golemGolem (GLM) $ 0.734621
  • ondo-financeOndo (ONDO) $ 0.503975
  • gatechain-tokenGate (GT) $ 5.42
  • ribbon-financeRibbon Finance (RBN) $ 0.775808
  • enjincoinEnjin Coin (ENJ) $ 0.497215
  • nervos-networkNervos Network (CKB) $ 0.015998
  • ocean-protocolOcean Protocol (OCEAN) $ 1.18
  • holotokenHolo (HOT) $ 0.003911
  • bitcoin-goldBitcoin Gold (BTG) $ 38.96
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • frax-shareFrax Share (FXS) $ 8.81
  • ethereum-name-serviceEthereum Name Service (ENS) $ 21.96
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,613.79
  • superfarmSuperVerse (SUPER) $ 1.45
  • 1inch1inch (1INCH) $ 0.567999
  • fraxFrax (FRAX) $ 0.996802
  • coredaoorgCore (CORE) $ 0.739782
  • rocket-poolRocket Pool (RPL) $ 31.36
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.48
  • celoCelo (CELO) $ 1.15
  • compound-governance-tokenCompound (COMP) $ 89.15
  • xdce-crowd-saleXDC Network (XDC) $ 0.043650
  • lido-staked-solLido Staked SOL (STSOL) $ 150.33
  • altlayerAltLayer (ALT) $ 0.526849
  • metis-tokenMetis (METIS) $ 108.82
  • iotexIoTeX (IOTX) $ 0.060877
  • arkhamArkham (ARKM) $ 2.84
  • terra-luna-2Terra (LUNA) $ 0.822934
  • skaleSKALE (SKL) $ 0.105854
  • gmxGMX (GMX) $ 57.49
  • siacoinSiacoin (SC) $ 0.009652
  • stepnGMT (GMT) $ 0.309452
  • apenftAPENFT (NFT) $ 0.00000055
  • zetachainZetaChain (ZETA) $ 2.27
  • fasttokenFasttoken (FTN) $ 1.74
  • casper-networkCasper Network (CSPR) $ 0.044877
  • zilliqaZilliqa (ZIL) $ 0.029824
  • echelon-primeEchelon Prime (PRIME) $ 14.54
  • theta-fuelTheta Fuel (TFUEL) $ 0.079598
  • tether-goldTether Gold (XAUT) $ 2,074.71
  • chiaChia (XCH) $ 50.90
  • kujiraKujira (KUJI) $ 4.14
  • aelfaelf (ELF) $ 0.708393
  • zcashZcash (ZEC) $ 32.17
  • compound-wrapped-btccWBTC (CWBTC) $ 1,241.25
  • origintrailOriginTrail (TRAC) $ 1.23
  • kusamaKusama (KSM) $ 52.27
  • radixRadix (XRD) $ 0.044957
  • gasGas (GAS) $ 7.20
  • basic-attention-tokenBasic Attention (BAT) $ 0.312516
  • compound-ethercETH (CETH) $ 68.49
  • mask-networkMask Network (MASK) $ 4.69
  • dashDash (DASH) $ 37.44
  • livepeerLivepeer (LPT) $ 14.05
  • pixelsPixels (PIXEL) $ 0.570533
  • ankrAnkr Network (ANKR) $ 0.043240
  • nosanaNosana (NOS) $ 5.18
  • desoDecentralized Social (DESO) $ 40.56
  • stader-ethxStader ETHx (ETHX) $ 3,450.06
  • qtumQtum (QTUM) $ 4.06
  • neutron-3Neutron (NTRN) $ 1.51
  • moonbeamMoonbeam (GLMR) $ 0.491210
  • nemNEM (XEM) $ 0.045234
  • convex-financeConvex Finance (CVX) $ 4.94
  • strideStride (STRD) $ 4.51
  • loopringLoopring (LRC) $ 0.321387
  • dexeDeXe (DEXE) $ 6.99
  • decredDecred (DCR) $ 24.76
  • ethereum-pow-iouEthereumPoW (ETHW) $ 3.69
  • pax-goldPAX Gold (PAXG) $ 2,037.79
  • api3API3 (API3) $ 3.77
  • aleph-zeroAleph Zero (AZERO) $ 1.28
  • memecoin-2Memecoin (MEME) $ 0.039765

Researcher finds data harvesting inside Ledger Live app

0 43

Researcher finds data harvesting inside Ledger Live app

  protos.com 18 h

Researcher finds data harvesting inside Ledger Live app

Sleuths have discovered a vast data harvesting operation by the world’s largest hardware wallet manufacturer, Ledger. For reasons that are difficult to comprehend, Ledger Live software transmits information about clicks, page visits, redirects, crypto transactions, page scrolls, numbers of accounts, crypto asset names, session durations, hardware device types, and firmware versions to Ledger’s analytics provider.

Ledger Live is the official software for interfacing with any Ledger hardware wallet. The vast majority of PC users download this software in order to set up their hardware wallet and sign transactions. While inspecting its code, REKTbuildr found that user tracking is built into the entire software suite. He called it a “gigantic user tracking system.”

Cleaning user tracking code from Ledger Live code and JFC the whole thing is a gigantic user tracking system

There’s analytics trackers for nearly all events, on most screens.

Ledger Live is a user data collection tool

How is this system even accepted by the crypto community?

— REKTBuildr 🔺🔺🔺 (@rektbuildr) December 6, 2023

The application is sending tracking data to a service called segment.io. This data includes information on digital assets and NFTs stored on Ledger wallets.

A risky Ledger Live default setting

The Protos team did find that there is an option to turn off at least some of these analytics in Ledger Live’s settings. The settings tab of Ledger Live says enabling analytics will send data on “clicks, page visits, redirections, actions (send, receive, lock, etc), end of page scrolls, (un)installing and app version, number of accounts, crypto assets and operations, session durations, the Ledger device type and firmware.”

Researcher finds data harvesting inside Ledger Live app

Ledger Live’s data harvester is a JSON object with a properties key. It transmits user ID and a ‘writeKey,’ which can uniquely identify the PC. It can also send segment.io account information including names of digital assets owned and other information about users’ computers.

Although Ledger Live doesn’t send private keys or recovery phrases to segment.io, it sends plenty of information about a user that could subject users to extortion attacks. Any segment.io hacker, for example, could easily identify any user with substantial crypto holdings — including timestamps of crypto activities and other terrifyingly detailed information about assets.

Aggregating Ledger users as a high-value audience package

A likely commercial explanation for all the data harvesting, REKTbuildr speculated, is that Ledger wants to resell anonymized data to third-party advertisers. Prepackaged IP or cookie ‘audiences’ with thousands of users who have engaged in a recent digital action, such as clicking a button within a crypto app, for example — are commonly resold to advertisers by data aggregators like Google, Bluekai, or eXelate.

Alternatively, the data could be used internally for user experience (UX) and user interface (UI) workers at Ledger.

As a courtesy to the community, REKTbuildr forked Ledger Live software, removed its tracking codes, and uploaded the patched software to GitHub.

Naturally, Ledger had very little to say about analytics harvesting on its social media. Its disinterest comes as little surprise to the digital asset community.

Ledger has already shocked the community’s trust in its hardware wallets. In May, it announced a controversial Recover service that shared abilities to remotely decipher the private keys on one’s hardware wallet. It unapologetically pushed that update live, eliminating years of perception that private keys never left a hardware wallet.

Another lowlight in Ledger’s history includes its email database. Hackers exposed millions of its users’ emails, which led to users receiving fake wallets in a likely phishing attack. Experts quickly posted warnings.

In summary, Ledger is tracking user data, possibly for its own UI/UX workers, or to profit from resale. Luckily, users have alternatives, including tracker-free forked versions of the software, or using the hardware wallet itself without installing Ledger Live software at all.

Source

Leave A Reply

Your email address will not be published.