Anyone searching for the software for a Ledger hardware wallet through a search engine can currently land on a copy. On Saturday the security researcher Cyber Scrilla reported a counterfeit Ledger site together with a matching app, which appeared high up in Google's organic results and asks visitors for their 24 words. Those 24 words are the access to the entire balance. Anyone who types them in loses control of the wallet, even if nobody ever had the device itself in their hands.
For holders in Germany what follows is not another checklist for suspicious emails but a habit: wallet software is reached through a bookmark or an address typed in yourself, never through the search box. This article sets out what has been reported, how a counterfeit gets to the top at all, and what to do if the phrase has already been entered.
Counterfeit Ledger site in Google search: what security researchers have reported
The report goes back to the security researcher Cyber Scrilla, who on Saturday pointed to a rebuilt Ledger site and an app belonging to it. Both are designed to ask for the 24-word recovery phrase. Read Entire Article


English (US)