Post
Topic
Board Hardware wallets
Re: Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties entities
by
RickDeckard
on 16/05/2023, 11:20:26 UTC
(...)If this is true, i'll never point people towards ledger hardware ever again... FFS, if this is true, they're completely demolishing everything a hardware wallet stands for...
While these particular release notes do not appear on Ledger website, you can find them in Ledger Servers API[1] and, most importantly, /u/btchip - Ledger Co-Funder - has already admitted that this will indeed happen[2] setting a dangerous attack vector as o_e_l_e_o previously explained about:
Quote
The device sends encrypted shards of your seed to different companies if you decide to use the service. You can of course still choose to backup it yourself.
I wonder until how long will someone find an exploit to this "encrypted backup export system"? If this doesn't spell the depreciation of Ledger as a company, for sure that event will.

[1]https://manager.api.live.ledger.com/api/firmware_osu_versions
[2]https://safereddit.com/r/ledgerwallet/comments/13itm7u/is_there_a_backdoor_yes_or_no/jkbyyfp/