Meet Cerberus: How the Ledger Donjon Built an AI Security…
Meet Cerberus: How the Ledger Donjon Built an AI Security Harness...
We are the security research team at Ledger, dedicated to protecting your digital assets through cutting-edge security research, vulnerability discovery, and open-source tools.
Technical details of past security issues, their impact, and available patches.
Comprehensive documentation of security objectives and mechanisms.
Open-source security research tools for hardware and software analysis.
Report vulnerabilities and earn rewards for helping secure Ledger products.
Meet Cerberus: How the Ledger Donjon Built an AI Security Harness...
After uncovering a genuine check bypass on the Tangem Android application and a brute-force attack on the card's authentication protocol, the Ledger Donjon turned its attention to the card itself with more advanced tools and sophisticated techniques. What we found is a critical vulnerability that lets an attacker with physical access to a single Tangem card reset its password and steal all associated funds.
Part 3 of our series on side-channel attacks against post-quantum cryptography: masking defeats the first-order attack, but masked Kyber768 still falls to a second-order CPA.
Swap flow accepted a token approval in place of a payment
Clear-signing bypass via array-count truncation in the Ethereum app
Command interleaving during an on-screen review could desynchronise the display from the signature
We reward security researchers who help us protect our users. Join our bug bounty program and get recognized in our Hall of Fame.