Post
Topic
Board Hardware wallets
Merits 7 from 4 users
Re: Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties entities
by
o_e_l_e_o
on 16/05/2023, 13:50:51 UTC
⭐ Merited by LoyceV (4) ,vapourminer (1) ,HeRetiK (1) ,ETFbitcoin (1)
This is a paid feature so it's not sending your seed phrase anywhere unless you pay $9.99 per month for it (which is a dumb subscription).
It's still unsafe.

The whole point of a hardware wallet is to store your seed phrase and private keys safely and securely inside and prevent them from being extracted. The whole point of Ledger's secure element is that there is no possible way to extract the seed phrase from it. Now we have just discovered that a simple firmware update will permit the secure element to start sending your seed phrase across the internet. Ledger have just admitted that their entire design is deeply flawed.

We conveniently already have a name for a hardware wallet which can expose your seed phrase to the internet. It's called a hot wallet.