The tweet was deleted by the author.
But we saved everything 🙂.
A developer deliberately tested Ledger's agent security by introducing a prompt injection instructing the agent to send funds to a fraudulent address.
The agent proceeded to build the transaction, but the Ledger device screen displayed the attacker's address to the user, who then refused to authorize the transfer. This sequence underscores the effectiveness of Ledger's architecture in requiring human verification for transactions, acting as a last line of defense against sophisticated attacks.
Ledger previously warned users that it will never request a secret recovery phrase and emphasized vigilance amid increasing scam activity, according to a recent advisory. The company also expanded its services by launching a cash-to-stablecoin feature for instant fiat-to-USDC conversion via IBAN payments, as detailed in an earlier announcement. These developments reflect Ledger’s ongoing focus on user protection and service integration.