Researchers have found a way to retrieve the private keys from Ledger devices once obtained a physical access to the device. A reseller could update the devices with malware designed to steal the private key and drain the users cryptocurrency accounts when the user will use it. The attack becomes incredibly lucrative if used when a legitimate firmware update is released, as was the case two weeks ago. The company has released a new firmware update that addresses the vulnerability. The vulnerability was discovered by Saleem Rashid and published a research paper on the flaw.”]
Source: https://securityaffairs.co/wordpress/70516/hacking/ledger-wallet-flaw.html

