Ledger Donjon
@DonjonLedger
Followers
6K
Following
75
Media
39
Statuses
171
The security research at Ledger.
Paris
Joined June 2019
Donjon is the Security Research team at @Ledger. Follow us to get the the latest news from our research. More info on our blog: https://t.co/Ugy5xfM4gX
11
68
68
⚠️ Our white hat team, the @DonjonLedger, discovered a flaw in Tangem cards that makes brute force attacks possible. As always, the Donjon followed responsible disclosure to inform Tangem, user protection is our priority. We can now reveal our findings in full: 🧵👇
137
206
1K
Struggling to explore waveforms with millions of points? Discover TurboPlot ⚡ 👉 https://t.co/8qtvylIaCY
3
8
20
Security leaves no room for error, a single variable mishandled, and the entire security model can collapse. We're excited to share an illustration of this through our recent research on the Tangem card. Big thanks to the @Tangem team for their responsiveness and collaboration!
🚨At Ledger Donjon, we don’t just secure our own products, we help make the entire crypto ecosystem safer. As part of our ongoing security research and responsible disclosure efforts, we identified an important vulnerability in Tangem’s Android app. 👇🧵
3
5
23
Donjon is at @BlackHatEvents Asia this week! Karim (@k15ab_ ) is presenting his research on using deep learning attribution methods for fault injection attacks. Don't miss his presentation: https://t.co/wQEjEYcMvB
1
2
8
In this blog post, I share some dangerous practices in deploying Argo CD🦑. Enjoy reading! https://t.co/5kDk83q5Sn
ledger.com
Despite such a strong security posture, Argo CD can be configured in ways creating vulnerabilities. This article studies on two examples where Argo CD is deployed in a way which unexpectedly enabled...
DevOps practices are all well and good, but beware of the configuration of the tools that access your production. Find out more about Argo CD misconfiguration in this new blog post. ⏬ https://t.co/56FTTAuR3C
#argocd #security #devops #devsecops
0
6
14
DevOps practices are all well and good, but beware of the configuration of the tools that access your production. Find out more about Argo CD misconfiguration in this new blog post. ⏬ https://t.co/56FTTAuR3C
#argocd #security #devops #devsecops
ledger.com
Despite such a strong security posture, Argo CD can be configured in ways creating vulnerabilities. This article studies on two examples where Argo CD is deployed in a way which unexpectedly enabled...
0
6
14
Last week at @hardwear_io NL 2024, we showcased some of our attack tools we use in the Donjon, and a live demo of a double fault injection ⚡️⚡️ with the transportable laser bench! Our tools are open-source and presented on our webpage: https://t.co/ulu1YsAxZu
2
1
11
Last week, the Ledger Donjon team joined the NoLimitSecu 🇫🇷 podcast to share Ledger’s vision on wallet security in episode #475, titled 'Sécurité des wallets'. For English speakers, you can use auto-generated subtitles on https://t.co/0226xGWcp9
#ledger #donjon #CyberSecurity
0
4
10
Last week, the Ledger Donjon team joined the NoLimitSecu 🇫🇷 podcast to share Ledger’s vision on wallet security in episode #475, titled 'Sécurité des wallets'. For English speakers, you can use auto-generated subtitles on https://t.co/0226xGWcp9
#ledger #donjon #CyberSecurity
0
4
10
This week the Donjon brought its transportable laser bench to the https://t.co/xrCRQEAv2a conference in Rennes by train 🚄. A proof that a functional Laser Fault Injection bench is not that impossible to see anywhere. Next step in the Village @hardwear_io NL 2024 conference!
0
9
35
During next @hardware_io conference, @DonjonLedger will showcase tools developed and used for Fault Injection Attacks! Pass by in the Village to see a part of our Tool Suite: Scaffold, Silicon Toaster, Laser Studio, QuickLog, Curmea… operating on our transportable laser bench!
Unlock new levels of precision with hardware tools such as Scaffold, Silicon Toaster, and Curmea! 🛠️✨ Ideal for precise perturbations in operations including current regulations, signal generation, process disruption Join @mickm111 at #hw_ioNL2024 👉 https://t.co/aHPpdlCpST
0
1
6
🚀 Exciting news! The @DonjonLedger team proudly presents cargo-checkct, our new open-source tool designed to defend against timing attacks. 🛡️ 📖 In our latest blog post, we explore: The concept of timing attacks and their impact Why timing vulnerabilities in cryptography
0
3
18
We are thrilled to have open-sourced cargo-checkct, to help bridge the gap between academic research and industry practices for the early detection of timing vulnerabilities in cryptography libraries. Read more about it in our blog post.
ledger.com
The Ledger Donjon team is thrilled to present cargo-checkct, our in-house tool designed to defend against timing attacks. In this article, we'll delve into the concept of timing attacks, explore why...
Exciting news from @DonjonLedger! Introducing cargo-checkct, our cutting-edge tool to protect against timing attacks. Curious about what timing attacks are & why typical solutions don’t quite cut it in crypto? Dive into our latest article to learn more!
0
5
9
Fault Injection (FI) and Side-Channel (SC) attacks targeting ESP32 SoC eFUSE encryption keys extraction Great research work by @DonjonLedger
https://t.co/lgWFReCTay
#espressif #cybersecurity
1
45
179
"There is no security on this earth; there is only opportunity." But, opportunity to improve security exists, and I'm excited to share one with you. 🔥🔥 🛡️ @DonjonLedger 🛡️ is opening one (and only one) position for an 🔰 internship 🔰 in our security software team. If you
0
3
8
Smart contracts are an integral part of the crypto ecosystem - but interacting with them does involve some risk, as you could accidentally sign a malicious contract. 🚨 Not sure what red flags you should be looking out for? Ledger Academy has you covered: https://t.co/8lXv4UEdDg
14
17
108
We are 100% focused on following up to last week’s security incident, making sure incidents like this are prevented in the future, and that the ecosystem remains safe. We are aware of approximately $600k in assets impacted, stolen from users blind signing on EVM DApps. Ledger
550
598
3K
Olivier’s talk on Triple Exploit Chain With Laser Fault Injection on the ATECC608B is available! Check it out: https://t.co/9zOx2BpliM
#hw_ioNL2023 @hardwear_io
1
11
40
📢Introducing our next Web3 Carnival speaker🎤 📷Join us as, @P3b7_ , CTO: @Ledger , takes the stage to share their visionary perspectives and actionable tips!✨ Book your tickets Now: https://t.co/tOTgRaUEoD
#web3carnival #Ledger #Crypto #NFT #web3 #w3c 🚀
7
4
20
Ever wondered about the basics of side-channel attacks? In the late @MISCRedac edition (in French), you can learn the underlying principles of such threats, and discover how to use our 🌈 Rainbow tool to assess the security of your code!
github.com
Makes Unicorn traces. Generic Side-Channel and Fault Injection simulator - Ledger-Donjon/rainbow
Les attaques par canaux auxiliaires sont décortiquées dans notre nouveau numéro, en kiosque dès aujourd'hui & disponible également sur https://t.co/xbXlwCjoE9
#sidechannelattack #crypto
0
4
16