Log inSign up
Ledger Donjon
187 posts
Image
user avatar
Ledger Donjon
@DonjonLedger
The security research at Ledger.
Paris
donjon.ledger.com
Joined June 2019
1
Following
5,895
Followers
  • Pinned
    user avatar
    Ledger Donjon
    @DonjonLedger
    Jun 25, 2019
    Donjon is the Security Research team at @Ledger. Follow us to get the the latest news from our research. More info on our blog: ledger-donjon.github.io
    Image
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Jul 6, 2021
    All the passwords generated by Kaspersky Password Manager were predictable (CVE-2020-27020)! Here is why. donjon.ledger.com/kaspersky-pass…
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Sep 14, 2023
    Coinkite presented the results on their blog blog.coinkite.com/donjon-faults-… To give a precision, the seed can be practically extracted if an attacker combines our two attacks in SE2, SE1, and the MCU. You can find the two attacks: fdtc.deib.polimi.it/FDTC23/slides/… fdtc.deib.polimi.it/FDTC22/slides/…
    Image
    Donjon Faults SE2 on Mk4
    From blog.coinkite.com
    233K
  • user avatar
    Ledger Donjon
    @DonjonLedger
    May 18, 2020
    Our laser attack to extract all secrets from a Coldcard Mk2 hardware wallet. Details of the attack will be presented at the @SSTIC security conference on June 3 (100% online this year), stay tuned! donjon.ledger.com/coldcard-pin-c…
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Jun 25, 2019
    Extracting Private Keys from Ellipal Wallet. ledger-donjon.github.io/Ellipal-Securi… Ellipal is a hardware wallet based on air-gapped Android device. Our study also showed that communication interfaces could be re-enabled
    Image
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Aug 10, 2020
    Slides of our @BlackHatEvents talk "Black-Box Laser Fault Injection on a Secure Memory" are now available! Disclaimer: images of a chip attacked by laser shots inside. i.blackhat.com/USA-20/Thursda…
    Image
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Dec 1, 2020
    Ghostbuster is the sole challenge of the Donjon CTF which remained unsolved, but not unexplained. The exploit and the writeup are now public: donjon.ledger.com/ghostbuster. Lesson learned: CPUs are tricky! 👻 #spectre
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Feb 6, 2023
    We recently designed a new PIN-entry interface for our Ledger Nano X and S Plus. This new interface offers a strong security improvement against advanced targeted hardware spying attacks. Discover the rationales behind this design on
    Image
    New PIN screen on Ledger Nano products | Ledger
    From ledger.com
    48K
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Jul 26, 2022
    Breaking white-box implementations of public key cryptographic algorithms is rarely difficult. In this article, we explain how to break them automatically, with a full black-box approach. Open source tool is also provided.
    Image
    Black-box attacks on white-box ECDSA | Ledger
    From ledger.com
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Jun 7, 2022
    Last week, we presented our research on Intel Wi-Fi chips at @sstic. Our talk and our slides are now available: sstic.org/2022/presentat…. It features a demo of a DMA attack from the Wi-Fi chip! We also published our tools to interact with some Intel chips: github.com/Ledger-Donjon/…
    Image
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Nov 18, 2021
    Ledger Donjon CTF is back! Cryptography, hardware security, exploitation, reverse engineering, embedded security, side channel attacks... Show your skills and win a limited edition of Ledger Nano X and cryptocurrencies! CTF starts on Nov 30. Register now: donjon-ctf.io
    Image
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Nov 19, 2021
    Dear Twitterverse, does anyone know of a security contact from @booba's crew? We found a vulnerability in BOOBA TN NFTs but our DMs remain unanswered. We would prefer to avoid full disclosure if possible. (Please RT for visibility)
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Aug 4, 2021
    Double fun with double fault attacks! Today at #BHUSA, Olivier Hériveaux will show how to defeat a secure element (ATECC608A) using multiple laser fault injections. blackhat.com/us-21/briefing…
    Image
  • user avatar
    Ledger Donjon
    @DonjonLedger
    Nov 28, 2023
    Olivier’s talk on Triple Exploit Chain With Laser Fault Injection on the ATECC608B is available! Check it out: youtube.com/watch?v=Hd_K2y… #hw_ioNL2023 @hardwear_io
    4.5K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up