Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    8 Best No-Code Development Platforms

    May 12, 2025

    Colle AI Strengthens Solana Strategy to Scale NFT Development and Liquidity

    May 12, 2025

    Pluto Bio vs SciNote: The Ultimate Bioinformatics Tool Guide 2025

    May 12, 2025
    Facebook X (Twitter) Instagram
    Monday, May 12
    • About
    • Contact us
    • Privacy Policy
    Facebook X (Twitter) LinkedIn YouTube
    Blockchain Echo
    Banner
    • Lithosphere News Releases
    • Bitcoin
    • Crypto
    • Ethereum
    • Litecoin
    • Altcoins
    • Blockchain
    Blockchain Echo
    Home » Crypto wallet maker Ledger regains control of Discord after phishing attack
    Crypto

    Crypto wallet maker Ledger regains control of Discord after phishing attack

    John SmithBy John SmithMay 12, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Hardware wallet maker Ledger has regained control of its Discord server after a moderator’s compromised account was used to spread phishing links targeting users’ seed phrases.

    According to an announcement on the official Discord server, the breach occurred on May 11 after an attacker took over a contracted moderator’s account.

    Using the elevated privileges, the attacker deployed a bot to post scam links in one of the channels, directing users to a malicious website that mimicked a Ledger verification page.

    “The issue was quickly contained: the compromised account was removed, the bot was deleted, the website was reported, and all relevant permissions were reviewed and secured,” said Ledger staff member Quintin Boatwright in the May 11 Discord post.

    To target users, the attacker issued a fake security warning that claimed a vulnerability had been discovered in Ledger’s systems. Users were urged to “verify” their recovery phrases via a provided link, which led to a fraudulent third-party website.

    The phishing site mimicked an official Ledger interface and instructed users to connect their wallets and enter their 24-word seed phrases under the guise of a critical update. The setup was designed to harvest sensitive credentials and gain full access to a victim’s crypto assets.

    Screenshots of the scam post quickly circulated on X, prompting warnings from security analysts and further scrutiny of Ledger’s community management protocols. See below.

    According to some community members, the attacker used moderator rights to mute and ban users who attempted to warn others about the scam, possibly delaying Ledger’s initial response.

    While it remains unclear whether any users fell victim to the phishing attempt, the incident follows a string of similar scams targeting hardware wallet customers.

    As previously reported by crypto.news, Ledger customers were recently targeted in a phishing campaign involving fake letters sent by mail bearing Ledger’s branding, a return address, and a fabricated reference number. 

    It urged recipients to scan a malicious QR code and enter their 24-word recovery phrase, under the false pretext of a required security update.

    Ledger is not the only wallet provider that has dealt with security threats. In March, Ledger’s security research team, Donjon, disclosed a vulnerability in rival manufacturer Trezor’s Safe hardware wallets, warning that the devices could still be physically hacked due to a vulnerability in the microcontroller used to perform critical cryptographic operations.

    Notably, the chip is vulnerable to voltage glitching attacks, which can allow an attacker to extract or manipulate data stored in the device by briefly altering power input during operations.

    Several crypto influencers have since commented on the exploit, including former Binance CEO Changpeng Zhao.

    Just got this security warning.

    Ledger’s Discord admin account was hacked. The scammer falsely claimed a security flaw and urged users to enter their recovery phrases on a phishing site.

    Lessons:
    1. Never give up your private key recovery phrases no matter who is doing the…

    — CZ 🔶 BNB (@cz_binance) May 12, 2025





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleTokyo-listed Beat Holdings to boost its Bitcoin ETF exposure fivefold, seeks $34m cap
    Next Article Metaplanet adds 1,241 Bitcoin, total holdings now 6,796 BTC
    John Smith

    Related Posts

    8 Best No-Code Development Platforms

    May 12, 2025

    Pluto Bio vs SciNote: The Ultimate Bioinformatics Tool Guide 2025

    May 12, 2025

    Top 6 Bitsgap Alternatives 2025

    May 12, 2025
    Leave A Reply Cancel Reply

    Top Posts

    🐍 Lunar New Year Scratch & Win Campaign Is Live with a Grand Prize of 8,888,888 VERSE (~$1800) | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Trade VERSE/USDT on KuCoin to Earn your Share of $8400 in Rewards! | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Boost Your Crypto: Up to 30% Cash Back! | by Bitcoin.com | Jan, 2025

    January 24, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    About Us

    Stay updated on the world of cryptocurrency
    Your one-stop source for daily crypto news and insights
    Blockchainecho.info: Your trusted daily crypto companion

    Most Popular

    🐍 Lunar New Year Scratch & Win Campaign Is Live with a Grand Prize of 8,888,888 VERSE (~$1800) | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Trade VERSE/USDT on KuCoin to Earn your Share of $8400 in Rewards! | by Bitcoin.com | Jan, 2025

    January 24, 2025

    Boost Your Crypto: Up to 30% Cash Back! | by Bitcoin.com | Jan, 2025

    January 24, 2025
    Copyright © 2025
    • Home
    • Buy Now

    Type above and press Enter to search. Press Esc to cancel.