{"id":20276,"date":"2025-05-12T00:29:20","date_gmt":"2025-05-12T00:29:20","guid":{"rendered":"https:\/\/gold.creditcard\/ledger-secures-discord-after-hacker-bot-tried-to-steal-seed-phrases\/"},"modified":"2025-05-12T00:29:20","modified_gmt":"2025-05-12T00:29:20","slug":"ledger-secures-discord-after-hacker-bot-tried-to-steal-seed-phrases","status":"publish","type":"post","link":"https:\/\/gold.creditcard\/es\/ledger-secures-discord-after-hacker-bot-tried-to-steal-seed-phrases\/","title":{"rendered":"Ledger secures Discord after hacker bot tried to steal seed phrases"},"content":{"rendered":"<p>Hardware wallet provider Ledger has confirmed its Discord server is secure again after an attacker compromised a moderator\u2019s account to post scam links on May 11 to trick users into revealing their seed phrases on a third-party website.<\/p>\n<p>\u201cOne of our contracted moderators had their account compromised, which allowed a malicious bot to post scam links in one channel,\u201d Ledger team member Quintin Boatwright <a href=\"https:\/\/discord.com\/channels\/885256081289379850\/1013722250857435157\/1370980446036299816\" target=\"null\" title=\"null\">wrote<\/a> on the Ledger Discord server.\u00a0<\/p>\n<p>\u201cThe issue was quickly contained: the compromised account was removed, the bot was deleted, the website was reported, and all relevant permissions were reviewed and secured.\u201d<\/p>\n<p>Some members in Ledger\u2019s Discord channel <a href=\"https:\/\/x.com\/SekureD\/status\/1921403124188598344\" target=\"null\" title=\"null\">claimed<\/a> the attacker abused moderator privileges to ban and mute them as they tried to report the breach, possibly slowing Ledger\u2019s reaction.<\/p>\n<p>Boatwright said the security breach was an isolated incident and that Ledger has taken additional measures to strengthen its security on Discord, a chat platform many crypto projects use to share protocol developments and engage with their community.\u00a0<\/p>\n<p>Using the compromised Ledger community manager account, the hacker told Ledger Discord members that there was a recently discovered vulnerability in the firm\u2019s security systems and strongly urged all users to verify their <a href=\"https:\/\/cointelegraph.com\/explained\/various-forms-of-bitcoin-custody-explained\" target=\"null\" title=\"https:\/\/cointelegraph.com\/explained\/various-forms-of-bitcoin-custody-explained\">recovery phrases<\/a> with a scam link, <a href=\"https:\/\/x.com\/ecurrencyhodler\/status\/1921401075430576149\" target=\"null\" title=\"https:\/\/x.com\/ecurrencyhodler\/status\/1921401075430576149\">according <\/a>to several screenshots shared on X.\u00a0<\/p>\n<p>Ledger users were asked to connect their wallets and follow on-screen instructions.<\/p>\n<p><em>Source: <\/em><a href=\"https:\/\/x.com\/ecurrencyhodler\/status\/1921401075430576149\" target=\"null\" title=\"null\"><em>ecurrencyholder<\/em><\/a><\/p>\n<p>It isn\u2019t clear whether anyone was affected by the security breach.\u00a0Cointelegraph has reached out to Ledger for comment. <\/p>\n<h2>Ledger scammers were sending physical letters last month\u00a0<\/h2>\n<p>In April, scammers were <a href=\"https:\/\/cointelegraph.com\/news\/ledger-scammers-send-letters-steal-recovery-seed-phrases\" target=\"null\" title=\"null\">mailing physical letters to owners<\/a> of Ledger hardware wallets, asking them to validate their private seed phrases in a bid to access and empty the wallets.<\/p>\n<p>The letter used Ledger\u2019s logo, business address and a reference number to feign legitimacy and asked users to scan a QR code and enter the wallet\u2019s <a href=\"https:\/\/cointelegraph.com\/explained\/what-is-a-seed-phrase-and-why-is-it-important\" target=\"null\" title=\"null\">recovery phrase.<\/a><\/p>\n<p>One Ledger user who received the letter speculated whether scammers were sending letters to Ledger customers whose data was leaked in July 2020.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/balancing-crypto-security-convenience-jameson-lopp-casa\" target=\"null\" title=\"null\"><em><strong>Jameson Lopp: Most don\u2019t realize how easy self-custody has become<\/strong><\/em><\/a><\/p>\n<p>That incident saw a hacker<a href=\"https:\/\/cointelegraph.com\/news\/ledger-data-leak-a-simple-mistake-exposed-270k-crypto-wallet-buyers\" target=\"null\" title=\"null\"> breach Ledger\u2019s database<\/a> and dump the personal information of over 270,000 of its customers online, which included names, phone numbers and home addresses.<\/p>\n<p>The following year, several Ledger users claimed to have been mailed<a href=\"https:\/\/cointelegraph.com\/news\/fake-ledger-live-app-sneaks-into-microsoft-app-store-as-victims-lose-half-a-million\" target=\"null\" title=\"null\"> fake Ledger devices<\/a> that were tampered with and designed to install malware upon use, Bleeping Computer <a href=\"https:\/\/www.bleepingcomputer.com\/news\/cryptocurrency\/criminals-are-mailing-altered-ledger-devices-to-steal-cryptocurrency\/\" target=\"null\" title=\"null\">reported<\/a> at the time.<\/p>\n<p><em><strong>Magazine: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/magazine\/ai-sycophancy-crazy-snowballing-psychosis-child-porn-jailbreak-fears-ai-eye\/\" target=\"null\" title=\"null\"><em><strong>ChatGPT a \u2018schizophrenia-seeking missile,\u2019 AI scientists prep for 50% deaths<\/strong><\/em><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Hardware wallet provider Ledger has confirmed its Discord server is secure again after an attacker compromised a moderator\u2019s account to post scam links on May 11 to trick users into revealing their seed phrases on a third-party website. \u201cOne of our contracted moderators had their account compromised, which allowed a malicious bot to post scam [&hellip;]<\/p>","protected":false},"author":0,"featured_media":20277,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[9],"tags":[],"class_list":["post-20276","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-finance"],"_links":{"self":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts\/20276","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/comments?post=20276"}],"version-history":[{"count":0,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/posts\/20276\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/media\/20277"}],"wp:attachment":[{"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/media?parent=20276"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/categories?post=20276"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gold.creditcard\/es\/wp-json\/wp\/v2\/tags?post=20276"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}