DonjonLedger Profile Banner
Ledger Donjon Profile
Ledger Donjon

@DonjonLedger

Followers
6K
Following
75
Media
39
Statuses
171

The security research at Ledger.

Paris
Joined June 2019
Don't wanna be here? Send us removal request.
@DonjonLedger
Ledger Donjon
6 years
Donjon is the Security Research team at @Ledger. Follow us to get the the latest news from our research. More info on our blog: https://t.co/Ugy5xfM4gX
11
68
68
@P3b7_
Charles Guillemet
3 months
⚠️ Our white hat team, the @DonjonLedger, discovered a flaw in Tangem cards that makes brute force attacks possible. As always, the Donjon followed responsible disclosure to inform Tangem, user protection is our priority. We can now reveal our findings in full: 🧵👇
137
206
1K
@DonjonLedger
Ledger Donjon
3 months
Struggling to explore waveforms with millions of points? Discover TurboPlot ⚡ 👉 https://t.co/8qtvylIaCY
3
8
20
@DonjonLedger
Ledger Donjon
7 months
Security leaves no room for error, a single variable mishandled, and the entire security model can collapse. We're excited to share an illustration of this through our recent research on the Tangem card. Big thanks to the @Tangem team for their responsiveness and collaboration!
@P3b7_
Charles Guillemet
7 months
🚨At Ledger Donjon, we don’t just secure our own products, we help make the entire crypto ecosystem safer. As part of our ongoing security research and responsible disclosure efforts, we identified an important vulnerability in Tangem’s Android app. 👇🧵
3
5
23
@DonjonLedger
Ledger Donjon
8 months
Donjon is at @BlackHatEvents Asia this week! Karim (@k15ab_ ) is presenting his research on using deep learning attribution methods for fault injection attacks. Don't miss his presentation: https://t.co/wQEjEYcMvB
1
2
8
@IooNag
💻📡🛰️ IooNag
1 year
In this blog post, I share some dangerous practices in deploying Argo CD🦑. Enjoy reading! https://t.co/5kDk83q5Sn
Tweet card summary image
ledger.com
Despite such a strong security posture, Argo CD can be configured in ways creating vulnerabilities. This article studies on two examples where Argo CD is deployed in a way which unexpectedly enabled...
@DonjonLedger
Ledger Donjon
1 year
DevOps practices are all well and good, but beware of the configuration of the tools that access your production. Find out more about Argo CD misconfiguration in this new blog post. ⏬ https://t.co/56FTTAuR3C #argocd #security #devops #devsecops
0
6
14
@DonjonLedger
Ledger Donjon
1 year
DevOps practices are all well and good, but beware of the configuration of the tools that access your production. Find out more about Argo CD misconfiguration in this new blog post. ⏬ https://t.co/56FTTAuR3C #argocd #security #devops #devsecops
Tweet card summary image
ledger.com
Despite such a strong security posture, Argo CD can be configured in ways creating vulnerabilities. This article studies on two examples where Argo CD is deployed in a way which unexpectedly enabled...
0
6
14
@DonjonLedger
Ledger Donjon
1 year
Last week at @hardwear_io NL 2024, we showcased some of our attack tools we use in the Donjon, and a live demo of a double fault injection ⚡️⚡️ with the transportable laser bench! Our tools are open-source and presented on our webpage: https://t.co/ulu1YsAxZu
2
1
11
@DonjonLedger
Ledger Donjon
1 year
Last week, the Ledger Donjon team joined the NoLimitSecu 🇫🇷 podcast to share Ledger’s vision on wallet security in episode #475, titled 'Sécurité des wallets'. For English speakers, you can use auto-generated subtitles on https://t.co/0226xGWcp9 #ledger #donjon #CyberSecurity
@nolimitsecu
NoLimitSecu
1 year
#Podcast #Cybersécurité Épisode #475 consacré à la sécurité des Wallets, avec @IooNag et @b0l0k_ (@Ledger) https://t.co/PUZlJ3Iq1h
0
4
10
@DonjonLedger
Ledger Donjon
1 year
Last week, the Ledger Donjon team joined the NoLimitSecu 🇫🇷 podcast to share Ledger’s vision on wallet security in episode #475, titled 'Sécurité des wallets'. For English speakers, you can use auto-generated subtitles on https://t.co/0226xGWcp9 #ledger #donjon #CyberSecurity
@nolimitsecu
NoLimitSecu
1 year
#Podcast #Cybersécurité Épisode #475 consacré à la sécurité des Wallets, avec @IooNag et @b0l0k_ (@Ledger) https://t.co/PUZlJ3Iq1h
0
4
10
@DonjonLedger
Ledger Donjon
1 year
This week the Donjon brought its transportable laser bench to the https://t.co/xrCRQEAv2a conference in Rennes by train 🚄. A proof that a functional Laser Fault Injection bench is not that impossible to see anywhere. Next step in the Village @hardwear_io NL 2024 conference!
0
9
35
@DonjonLedger
Ledger Donjon
1 year
During next @hardware_io conference, @DonjonLedger will showcase tools developed and used for Fault Injection Attacks! Pass by in the Village to see a part of our Tool Suite: Scaffold, Silicon Toaster, Laser Studio, QuickLog, Curmea… operating on our transportable laser bench!
@hardwear_io
hardwear.io
1 year
Unlock new levels of precision with hardware tools such as Scaffold, Silicon Toaster, and Curmea! 🛠️✨ Ideal for precise perturbations in operations including current regulations, signal generation, process disruption Join @mickm111 at #hw_ioNL2024 👉 https://t.co/aHPpdlCpST
0
1
6
@P3b7_
Charles Guillemet
2 years
🚀 Exciting news! The @DonjonLedger team proudly presents cargo-checkct, our new open-source tool designed to defend against timing attacks. 🛡️ 📖 In our latest blog post, we explore: The concept of timing attacks and their impact Why timing vulnerabilities in cryptography
0
3
18
@DonjonLedger
Ledger Donjon
2 years
We are thrilled to have open-sourced cargo-checkct, to help bridge the gap between academic research and industry practices for the early detection of timing vulnerabilities in cryptography libraries. Read more about it in our blog post.
Tweet card summary image
ledger.com
The Ledger Donjon team is thrilled to present cargo-checkct, our in-house tool designed to defend against timing attacks. In this article, we'll delve into the concept of timing attacks, explore why...
@Ledger
Ledger
2 years
Exciting news from @DonjonLedger! Introducing cargo-checkct, our cutting-edge tool to protect against timing attacks. Curious about what timing attacks are & why typical solutions don’t quite cut it in crypto? Dive into our latest article to learn more!
0
5
9
@0xor0ne
0xor0ne
2 years
Fault Injection (FI) and Side-Channel (SC) attacks targeting ESP32 SoC eFUSE encryption keys extraction Great research work by @DonjonLedger https://t.co/lgWFReCTay #espressif #cybersecurity
1
45
179
@b0l0k_
Vincent BOUZON
2 years
"There is no security on this earth; there is only opportunity." But, opportunity to improve security exists, and I'm excited to share one with you. 🔥🔥 🛡️ @DonjonLedger 🛡️ is opening one (and only one) position for an 🔰 internship 🔰 in our security software team. If you
0
3
8
@Ledger
Ledger
2 years
Smart contracts are an integral part of the crypto ecosystem - but interacting with them does involve some risk, as you could accidentally sign a malicious contract. 🚨 Not sure what red flags you should be looking out for? Ledger Academy has you covered: https://t.co/8lXv4UEdDg
14
17
108
@Ledger
Ledger
2 years
We are 100% focused on following up to last week’s security incident, making sure incidents like this are prevented in the future, and that the ecosystem remains safe. We are aware of approximately $600k in assets impacted, stolen from users blind signing on EVM DApps. Ledger
550
598
3K
@DonjonLedger
Ledger Donjon
2 years
Olivier’s talk on Triple Exploit Chain With Laser Fault Injection on the ATECC608B is available! Check it out: https://t.co/9zOx2BpliM #hw_ioNL2023 @hardwear_io
1
11
40
@web3carnival
Web3 Carnival
2 years
📢Introducing our next Web3 Carnival speaker🎤 📷Join us as, @P3b7_ , CTO: @Ledger , takes the stage to share their visionary perspectives and actionable tips!✨ Book your tickets Now: https://t.co/tOTgRaUEoD #web3carnival #Ledger #Crypto #NFT #web3 #w3c 🚀
7
4
20
@DonjonLedger
Ledger Donjon
2 years
Ever wondered about the basics of side-channel attacks? In the late @MISCRedac edition (in French), you can learn the underlying principles of such threats, and discover how to use our 🌈 Rainbow tool to assess the security of your code!
Tweet card summary image
github.com
Makes Unicorn traces. Generic Side-Channel and Fault Injection simulator - Ledger-Donjon/rainbow
@MISCRedac
MISCmag
2 years
Les attaques par canaux auxiliaires sont décortiquées dans notre nouveau numéro, en kiosque dès aujourd'hui & disponible également sur https://t.co/xbXlwCjoE9 #sidechannelattack #crypto
0
4
16