Ledger A.I CyberSecurity Scoring
Ledger
Company Information
Website:https://www.ledger.com
Employees number:824
Number of followers:91,625
NAICS:541514
Industry Type:Computer and Network Security
Homepage:ledger.com
Ledger Risk Score (AI oriented)
Between 0 and 549
LedgerComputer and Network Security
Updated:
01/08/2026
01/08/2026
475/1000
Critical
C
Ledger Global Score (TPRM)
xxxx
LedgerComputer and Network Security
Score locked

LedgerCritical
Current Score
475C (CRITICAL)
01000
11 incidents
-32.62 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
495
Cyber Attack
01 Aug 2026 • Ledger
Ledger: MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
MacSync Malware Campaign Targets macOS Users via Fake Claude AI Guides
475
CRITICAL-20
LED1785572706
MacSync Malware Campaign Targets macOS Users via Fake Claude AI Guides
A newly uncovered macOS malware campaign, dubbed MacSync, exploits fake Claude AI installation guides to deploy a sophisticated six-stage stealer and remote access trojan (RAT). Discovered by Huntress, the attack targets browser credentials, keychain secrets, cryptocurrency wallets, and other sensitive data.
The campaign begins when victims search for "how to install Claude on a Mac" and click a malicious Google-sponsored ad, redirecting them to a weaponized claude.ai/share page disguised with a fake "Shared by Apple Support" badge. The page instructs users to execute a Base64-obfuscated curl command in Terminal, which fetches a loader from domains like agenticsora[.]com or malwareaudit[.]com while bypassing certificate validation.
The malware unfolds in six stages, starting with a polymorphic zsh loader that establishes persistence via a background daemon. Subsequent stages include an AppleScript that tricks users into granting Full Disk Access, harvests credentials, and installs a Mach-O RAT written in C++ with OpenSSL. The RAT persists through a LaunchAgent mimicking legitimate updaters (e.g., Google Keystone, Adobe ARM) and deploys a helper app named "Screen Recording" to gain screen-capture permissions.
The final stage trojanizes hardware-wallet companion apps including Ledger Live, Ledger Wallet, and Trezor Suite to phish seed phrases. Huntress reports the stealer targets 60+ wallet browser extensions, 21 desktop wallet apps, and three trojanized hardware wallet tools, indicating cryptocurrency theft as the primary objective.
Infrastructure spans Cloudflare-fronted delivery domains, an operator panel at 103.216.221[.]95, and a raw-IP TLS channel (85.206.161[.]241:8443) for RAT control. Stolen data is exfiltrated to domains like sdhomeinspectors[.]com and southcarolinacounselor[.]com. Russian-language comments in the source code and collection techniques suggest ties to the AMOS/Atomic Stealer lineage, though researchers note this as a family resemblance rather than confirmed shared authorship.
Detection relies on behavioral indicators, including curl commands piped into zsh, osascript bridges executing stealer logic, and unexpected Full Disk Access or Screen Recording grants tied to newly signed apps. Persistence artifacts include paths like ~/.local/com.apple.<8hex>.hcpi and mutex files at /tmp/macsync_<token>.lock.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
489
JUNE 2026
502
Cyber Attack
01 Jun 2026 • Ledger
Electrum, Exodus, Ledger and Trezor: Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain
483
CRITICAL-19
ELEEXOLEDTRE1784199019
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain
Security researchers at SlowMist have uncovered a sophisticated macOS-focused infostealer designed to harvest credentials, wallet databases, and session data for offline cryptocurrency theft. Detected by the MistEye monitoring system, the malware casts a wide net, extracting sensitive information from Apple Keychain, Safari and Chromium browsers, Telegram Desktop, Apple Notes, and multiple wallet applications including Electrum, Exodus, Atomic, Wasabi, Monero, Bitcoin Core, Ledger Live, and Trezor Suite.
The malware’s primary threat lies in its ability to pair stolen wallet databases with potential unlocking material, such as passwords from Keychain or browser stores. While most wallet apps encrypt data locally, attackers can test harvested credentials against exfiltrated wallet files in an isolated environment, bypassing the limitations of online password-guessing attacks. SlowMist demonstrated this by successfully decrypting Atomic Wallet data using a password obtained from the victim’s Keychain. Once a wallet’s recovery phrase or private key is extracted, simply reinstalling the app or changing its password offers no protection.
The malware also employs social engineering tactics, including a fake "Google API Connector" update prompt to capture the victim’s macOS password. It validates credentials using the `dscl` authentication utility, ensuring attackers obtain the correct login details. Additionally, it targets Chrome Safe Storage secrets from Keychain, which can decrypt stored browser logins and cookies.
Telegram users face a separate risk: the stealer copies the `tdata` directory, containing encryption keys and session state. In lab tests, restoring these files on a compatible Mac immediately granted access to the victim’s account without requiring SMS codes or two-factor authentication effectively hijacking an active session. Stolen `tdata` artifacts could also be converted into programmable Telegram API sessions, enabling full chat access.
For Ledger Live and Trezor Suite users, the malware deploys phishing pages disguised as legitimate wallet applications. After removing the real software, it installs lookalike WebView loaders that connect to attacker-controlled sites, tricking victims into entering recovery phrases or PINs under the guise of trusted desktop apps.
The campaign highlights how infostealers exploit the interplay between credentials, encrypted local stores, and user trust. While a stolen wallet database alone may be secure, pairing it with Keychain secrets and reused passwords creates a portable target for offline decryption. Indicators of compromise (IOCs) include malicious domains and IP addresses linked to the phishing infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
498
APRIL 2026
503
Vulnerability
17 Apr 2026 • Ledger
Espressif Systems and Ledger: Fake Ledger Hardware Wallets on Chinese Marketplaces Steal Crypto Seeds and PINs
Sophisticated Supply Chain Attack Targets Crypto Users with Counterfeit Ledger Wallets
494
LOW-9
ESPLED1776435883
Sophisticated Supply Chain Attack Targets Crypto Users with Counterfeit Ledger Wallets
A Brazilian cybersecurity researcher uncovered a large-scale supply chain scam involving counterfeit Ledger Nano S Plus hardware wallets sold on a Chinese marketplace. The fake devices, designed to drain cryptocurrency across 20 blockchains, were engineered with tampered hardware, trojanized software, and cross-platform malware creating a seamless phishing pipeline.
The researcher, u/Past_Computer2901, purchased the device at the same price as the official Ledger store, with packaging that appeared authentic. Suspicion arose only after the device failed Ledger’s Genuine Check when connected to a legitimate Ledger Live installation. A physical teardown revealed the original secure element chip had been replaced with an ESP32-S3 microcontroller, a generic IoT component from Espressif Systems, with its markings scraped off to avoid detection. The counterfeit device also included a WiFi/Bluetooth antenna, absent in genuine Ledger wallets.
Firmware analysis exposed the full extent of the compromise: every PIN entry and seed phrase was stored in plaintext and transmitted to attacker-controlled command-and-control (C2) servers, including the domain kkkhhhnnn[.]com. The fake firmware, labeled "Nano S+ V2.1" a version that doesn’t exist in Ledger’s official releases was designed to impersonate a legitimate update.
The scam extended beyond the hardware. The counterfeit device shipped with a QR code directing users to a cloned phishing site, where they downloaded a trojanized Ledger Live app. The fake app bypassed security warnings with a hardcoded "Genuine Check" that always returned a success screen, ensuring victims remained unaware of the breach. The malware also exfiltrated wallet data upon use and was distributed across Android, Windows, macOS, and iOS, with the iOS variant spread via Apple’s TestFlight to evade App Store reviews.
Infrastructure analysis linked the operation to a Shanghai-based shell company, with three C2 servers, a cloned website, and a QR code redirect chain. While Ledger’s official Genuine Check can detect the counterfeit device, the scam’s success relied on victims never using the legitimate Ledger Live app.
The researcher submitted a full technical report to Ledger’s security team, with further analysis pending. The attack has already resulted in confirmed financial losses exceeding $9.5 million across more than 50 victims, marking one of the most advanced hardware wallet supply chain attacks documented to date.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
498
FEBRUARY 2026
509
Cyber Attack
01 Feb 2026 • Ledger
OpenClaw, Coinbase, MetaMask, 1Password and Ledger Live: Hackers Use Fake OpenClaw Installer to Steal Crypto Wallet and Password Manager Credentials
Hologram Infostealer Campaign Targets Crypto Wallets and Password Managers via Fake OpenClaw Installer
489
CRITICAL-20
METLED1PACOIOPE1778262200
New "Hologram" Infostealer Campaign Targets Crypto Wallets and Password Managers via Fake OpenClaw Installer
A sophisticated infostealer campaign, dubbed "Hologram," has been active since at least February 2026, targeting sensitive data stored in 250+ browser extensions tied to crypto wallets and password managers. The malware spreads via a fake installer for OpenClaw, a legitimate open-source AI assistant, hosted on a convincing typosquat domain (openclaw-installer[.]com), registered on March 9, 2026.
### How the Attack Works
1. Initial Infection
- Victims download OpenClaw_x64[.]7z, a 130MB Rust-based executable padded with fake documentation to evade antivirus scans and bypass sandbox upload limits.
- The dropper, named "Hologram" in its manifest, performs anti-analysis checks, including:
- Scanning for virtual machine BIOS strings and suspicious software libraries.
- Waiting for real mouse movement (automated sandboxes don’t trigger this).
- If checks pass, it disables Windows Defender, opens firewall ports, and downloads six modular components from an attacker-controlled Azure DevOps repository.
2. Credential Theft & Persistence
- The malware fetches a dynamic targeting list (hosted on Azure DevOps) covering:
- 201 crypto wallets (MetaMask, Phantom, Coinbase, Ledger Live, etc.).
- 49 password managers/authenticators (Bitwarden, LastPass, 1Password, Google Authenticator, etc.).
- The list is remotely updatable, allowing attackers to expand targets without recompiling the malware.
- Persistence mechanisms include:
- Registry autoruns.
- Windows logon hijacking.
- Scheduled tasks.
- Telegram-based droppers that survive even if the main implant is removed.
3. Evasive Infrastructure
- Command-and-control (C2) servers are never hardcoded instead, the malware retrieves them from Telegram channel descriptions, allowing rapid rotation if domains are blocked.
- Victim data (usernames, IPs, timestamps) is routed through Hookdeck, a legitimate webhook relay service, obscuring the attacker’s backend.
- Researchers observed infrastructure rotation during analysis, with domains and IPs changing before findings were published.
### Key Indicators of Compromise (IoCs)
- File Hashes: Multiple Rust-based droppers (e.g., `OpenClaw_x64[.]exe`, `svc_service[.]exe`) and secondary payloads (e.g., `onedrive_sync[.]exe`, `WinHealhCare[.]exe`).
- Domains:
- `openclaw-installer[.]com` (delivery).
- `hkdk.events` (C2 relay via Hookdeck).
- `dev.azure.com/sagonbretzpr` (payload staging).
- Hijacked Brazilian law firm domain (`frr.rubensbruno.adv.br`) and others.
- IPs: `193.202.84.14`, `45.55.35.48`, `188.114.97.3` (C2 beacons).
- Registry Keys & Paths:
- `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit` (logon hijack).
- `C:\Users\Public\` (stage-2 binary drop location).
- `%APPDATA%\Ledger Live` (targeted for wallet theft).
### Why This Campaign Stands Out
- Advanced Evasion: Uses Rust-based malware, in-memory .NET assembly loading (via `clroxide`), and Telegram for C2 rotation.
- Dynamic Targeting: The remote Git repository allows attackers to silently expand their target list without detection.
- Persistence: Multiple layers of registry, scheduled tasks, and Telegram-based backdoors ensure long-term access.
Researchers at Netskope Threat Labs identified this as a second, more advanced iteration of the campaign, following an earlier variant. The attack highlights the growing sophistication of infostealers, particularly in crypto and credential theft.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
567
Breach
05 Jan 2026 • Ledger
Ledger and Global-e: Crypto wallet firm Ledger faces new data breach through Global-e partner
Ledger Data Exposure via Third-Party Payment Processor Global-e
504
CRITICAL-63
LEDGLO1767622098
Ledger Customers Exposed in Third-Party Payment Processor Breach
Hardware wallet provider Ledger is addressing a data exposure incident tied to its third-party payment processor, Global-e. The breach, first reported by blockchain investigator ZachXBT on X, involved unauthorized access to Ledger users' personal details—including names and contact information—stored in Global-e’s cloud system.
Global-e detected the suspicious activity and launched an investigation, confirming that an unauthorized party accessed customer order data. While the exact number of affected users and the timeline of the breach remain undisclosed, forensic experts verified the improper access. The company stated that payment information was not compromised.
Ledger clarified that the incident occurred at Global-e, not within its own systems, and emphasized that no hardware, software, or cryptocurrency-related data—such as seed phrases or wallet balances—was exposed. As the data controller, Global-e issued notifications to impacted customers. The breach also affected other brands using Global-e’s services, as the compromised cloud system contained order data from multiple retailers.
This is not Ledger’s first security incident. In 2020, a breach via e-commerce partner Shopify exposed data from 270,000 customers, and in 2023, a hack resulted in nearly $500,000 in losses for decentralized finance applications. Ledger has stated it is collaborating with Global-e to provide updates to affected users.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
587
Cyber Attack
01 Jan 2026 • Ledger
Microsoft, Trezor, Audacity, GitHub and Ledger: OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases
New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics
567
CRITICAL-20
LEDGITMICAUDTRE1784125944
New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics
A sophisticated malware framework, OkoBot, has emerged as a major threat to cryptocurrency users, employing a multi-stage attack chain to steal recovery phrases, credentials, and wallet data. First observed in January 2026, the campaign builds on the TookPS downloader, which has been active since March 2025.
OkoBot operates as a modular platform with over 202,020 payloads, allowing attackers to deploy capabilities remotely via SSH infrastructure. Initial infections occur through ClickFix social-engineering attacks and trojanized applications hosted on GitHub, including a fake Microsoft SQL Server Management Studio (SSMS) repository that delivered a malicious Audacity installer.
Once executed, TookPS installs an SSH service, establishes a tunnel to attacker-controlled servers, and conducts system reconnaissance identifying security software, harvesting browser data, and preparing for deeper compromise. The malware also enables remote desktop (RDP) access by modifying firewall rules, creating backdoor user accounts, and patching termsrv.dll to allow concurrent sessions.
A key component, HDUtil, bypasses User Account Control (UAC) using Windows RPC and msconfig.exe, while SeedHunter targets Ledger Live, Ledger Wallet, and Trezor Suite by injecting fake recovery prompts. When a victim enters their seed phrase, it is exfiltrated to moonsand[.]store and stored locally in an RC4-encrypted file.
Additional plugins include:
- MC Keylogger – Logs clipboard data, USB devices, and screenshots.
- OkoSpyware – Records keystrokes and video streams from wallet apps and password managers.
Kaspersky researchers detected hundreds of victims across 25+ countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye. While attribution remains unclear, Russian-language artifacts, Rilide stealer usage, and CIS geoblocking suggest ties to Russian-speaking cybercrime groups.
The malware’s ability to bypass security controls, maintain persistence, and exfiltrate sensitive data makes it a significant risk for cryptocurrency holders and organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
665
NOVEMBER 2025
684
Cyber Attack
19 Nov 2025 • Ledger
Ledger / Trezor (Cryptocurrency Wallet Providers)
Nova Stealer macOS Malware Campaign Targeting Cryptocurrency Users
664
CRITICAL-20
LED5093550111925
The Nova Stealer malware campaign targets macOS users by replacing legitimate Ledger Live and Trezor Suite cryptocurrency wallet applications with malicious counterparts. The attack begins with a dropper downloading a shell script (`mdriversinstall.sh`) from a C2 server, establishing persistence via a hidden directory (`~/.mdrivers`) and a LaunchAgent (`application.com.artificialintelligence`). The malware operates stealthily using detached `screen` sessions, ensuring survival across reboots.Key modules include:- `mdriversfiles.sh`: Exfiltrates wallet data (e.g., Trezor’s `IndexedDB`, Exodus’ `passphrase.json`, Ledger’s `app.json`).- `mdriversswaps.sh`: Replaces genuine wallet apps with unsigned FAT Mach-O executables (Swift-based) that render phishing pages (`wheelchairmoments[.]com`, `sunrisefootball[.]com`). These pages use BIP-39/SLIP-39 validation to harvest recovery phrases (12–33 words) via keystroke logging (200–400ms debounce) and real-time tracking (`/track` endpoints).- `mdriversmetrics.sh`: Conducts system reconnaissance (installed apps, processes).Victims unknowingly interact with counterfeit apps (registered in Dock via `PlistBuddy`), leading to full compromise of cryptocurrency assets. The modular design allows remote updates, extending the campaign’s lifespan while evading static detection. The attack focuses on high-value targets (crypto users), with potential for mass financial loss and irreversible asset theft due to exposed recovery phrases.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
684
SEPTEMBER 2025
682
AUGUST 2025
681
Breach
18 Aug 2025 • Ledger
Canadian Investment Regulatory Organization: 750,000 Impacted by Data Breach at Canadian Investment Watchdog
CIRO Data Breach Exposes Personal Information of 750,000 Individuals
591
CRITICAL-90
CIR1768585990
CIRO Data Breach Exposes Personal Information of 750,000 Individuals
The Canadian Investment Regulatory Organization (CIRO) disclosed a data breach on August 18, 2025, revealing that hackers accessed the personal information of approximately 750,000 individuals in an August cyberattack. The breach stemmed from a sophisticated phishing incident, which led to temporary system shutdowns, though CIRO confirmed its critical regulatory functions remained unaffected.
According to CIRO, the compromised data includes sensitive details such as annual income, dates of birth, government-issued ID numbers, phone numbers, investment account numbers, social insurance numbers, and account statements information collected during routine regulatory and compliance activities. The organization clarified that passwords, PINs, and security questions were not exposed, as CIRO does not store such data.
While CIRO reported no evidence of data misuse or dark web exposure, it continues to monitor for malicious activity. Impacted individuals clients and former clients of CIRO dealer members are being notified and offered two years of free credit monitoring and identity theft protection services. An FAQ page has also been published to provide further details.
CIRO, a pan-Canadian self-regulatory body overseeing investment and mutual fund dealers, stated that the incident is contained with no active threat remaining in its environment. The breach follows a series of recent cybersecurity incidents affecting financial and healthcare sectors globally.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2024
663
Cyber Attack
01 Jan 2024 • Ledger
Ledger
13% Increase in Ransomware Attacks on European Organizations (2024-2025)
638
CRITICAL-25
LED1832718110325
In January 2025, Ledger, a Paris-based crypto-wallet vendor, fell victim to a Violence-as-a-Service (VaaS) attack orchestrated by Russia-linked groups Renaissance Spider and The Com. The co-founder of Ledger was kidnapped in France as part of an extortion scheme tied to cryptocurrency theft. The attack was executed via Telegram-coordinated networks, leveraging physical violence, arson threats, and ransom demands. This incident was among 17 recorded VaaS attacks since January 2024, with 13 occurring in France alone, prompting Europol to establish a dedicated taskforce to counter the escalating threat. The attack not only endangered the executive’s life but also exposed Ledger to reputational damage, operational disruption, and potential financial losses due to ransom pressures. The incident underscores the convergence of cyber extortion and physical violence, targeting high-profile individuals in the crypto sector to exploit digital and real-world vulnerabilities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2023
725
Breach
01 Dec 2023 • Ledger
Ledger
Phishing Attack on Ledger Connect Kit Software
661
HIGH-64
LED743221223
The Ledger Connect Kit software of the Paris-based business was compromised by a phishing attempt targeting a former worker.
During transactions using decentralised applications, or dapps, that utilised the compromised software, the hacker released malicious code that routed user funds to their own wallet.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JUNE 2020
757
Data Leak
01 Jun 2020 • Ledger
Ledger
Ledger Data Breach
680
CRITICAL-77
LED213813123
Major cryptocurrency hardware wallet provider Ledger experienced a data breach.
The company said it was made aware of the breach on July 14 when a researcher participating in its bounty program reached out with details of a potential vulnerability on their website.
While they were able to fix the breach immediately, a further investigation found that an authorized third party carried out a similar action on June 25.
The individual used an API key to access the marketing and e-commerce database the company used to send promotional emails.
This compromised the email addresses of almost one million people.
For a subset of 9,500 customers, details such as first and last name, postal address, and phone number were also exposed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Ledger ??
What was Ledger's A.I Rankiteo Cyber Score in July 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in June 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in May 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in April 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in March 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in February 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in January 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in December 2025 ??
What was Ledger's A.I Rankiteo Cyber Score in November 2025 ??
What was Ledger's A.I Rankiteo Cyber Score in October 2025 ??
What was Ledger's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Ledger's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Ledger ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Ledger's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?