OneKey Says Ledger Hack May Have Involved Hardware Tampering, Plans Security Boost

Bloomingbit

OneKey Says Ledger Hack May Have Involved Hardware Tampering, Plans Security Boost

Hardware wallet maker OneKey said it is moving to strengthen security after suggesting the recent Ledger wallet hack may have involved hardware tampering to steal recovery phrases.On Oct. 10, OneKey founder Yi He wrote on X, formerly Twitter, that the recent Ledger wallet hack may have used a method involving the insertion of a malicious device into the hardware. The company plans to tighten security from product packaging and internal design to distribution channels.The incident took place on Oct. 9, when assets belonging to Ledger hardware wallet users in Southeast Asia were stolen. Losses are estimated at about $90 million, though the exact amount and attack route are still under investigation.Yi said an attacker could install a separate device inside the wallet to intercept the recovery phrase displayed on the screen. He stressed, however, that there is still no evidence confirming that this method was actually used in the Ledger hack.In response, OneKey plans to introduce a feature that stores recovery phrases on a backup card through encrypted communication instead of showing them on the screen. The company also plans to encrypt internal wallet communications, add anti-tampering protections to product packaging and strengthen oversight of authorized sellers.