Head of Brand Development // Curator @Ledger | My views are my own. Banner by @agoriamusic

Web3
Mo retweeted
Ledger 🤝 @Payward (parent company of @krakenfx) Ledger and Payward are joining forces to close the gap between secure self-custody and global liquidity. Interact with global markets seamlessly, without ever giving up control of your keys. Here’s what is coming 👇
25
49
257
30,972
I've listened to the podcast by @P3b7_ and @Mo_RELS about 2 to 3 times now not gonna lie, it's actually a really solid breakdown so I turned it into a thread for anyone who wants the key ideas in a clean, easy read
"The biggest risk isn't quantum arriving early. It's crypto starting late." No quantum computer is breaking Bitcoin today. But recent research from Google has made the question harder to ignore. Ledger CTO @P3b7_ and Head of Brand Development @Mo_RELS break it down, without the doom.
37
24
140
3,412
Mo retweeted
Your $ZEC can stay shielded, and you can still see exactly what you're approving 🔐 Shielded @Zcash is now supported in Ledger Wallet, with every transaction approved on your Ledger signer. Shielded or transparent: how are you holding your Zcash? 👇
77
108
522
65,143
Mo retweeted
Ledger Wallet CLI has Ledger's "genuine check" built in. Proof of Ledger is effectively Proof of Human today, and we will be building around this promise to make sure this stays true and Proof of Human is a primitive provided by all of Ledger's secure hardware. Point your agent at developers.ledger.com and give it a test.
12
12
112
6,591
Mo retweeted
USDC on @arc is live in Ledger Wallet™, secured from Day 1. We're giving the community a reason to spread the word. To enter: 🔁 Repost this 👥 Follow @Ledger 💬 Tag someone still leaving their hard-earned dollars unsecured on software wallets.
258
289
518
30,408
Coruna / DarkSword is being used in the wild. Attackers socially engineer a Safari click, then walk the full chain: WebKit/JSC memory corruption → PAC bypass → sandbox escape → kernel/root. From there they pull Keychain + wallet data and drain seeds / private keys. In plaintext, you visit a website and lose your crypto. If your seed lives on an iPhone, treat this as a wake-up. Get a hardware wallet. (and update iOS).
Urgent security advisory for iOS users! Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones. The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges. With that access, attackers can pull data from the device Keychain and from local crypto wallet apps. The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.
23
31
243
40,980
Mo retweeted
Your phone is brilliant at holding your attention and hopeless at protecting your value. That’s a job for a different device. October 15, 2026.
36
28
214
21,017
⚛️ Bitcoin does not have a quantum computer problem today. It has a migration problem, and migrations could take years to get right. SHRINCS is the first Bitcoin-specific post-quantum proposal I have seen that makes a serious end-to-end trade-off, and it deserves to be read carefully rather than cheered or dismissed. Their work is the proposal. I wrote an analysis of the challenges that come with it, the ones that only become visible when you look past the signature scheme and into the wallets that have to run it. The migration really has three questions: - which scheme Bitcoin should support - what that scheme does to the protocol and the wallet ecosystem - what happens to coins that have never been moved by their owner. Almost all of the public discussion is still on the first one, which is probably the easiest of the three. SHRINCS is conservative where it matters. It is hash-based, so it leans on the SHA-256 that Bitcoin already depends on instead of stacking a lattice assumption on top. A single 48-byte public key commits to both a compact stateful path (Flexible XMSS and WOTS+C) and a stateless SLH-DSA fallback. Verification is the pleasant surprise. It is mostly SHA-256, and the draft reports a worst-case cost per signature byte below BIP340 Schnorr. The stateful path uses one-time keys, and each one must sign exactly once. The counter must never move backwards, it must be committed to persistent storage before the signature leaves the device, and it must never be restored from a backup. Sign two different messages from the same slot and an observer can steal your fund. SHRINCS handles this better than a purely stateful scheme. If the state is lost or merely uncertain, the seed still derives the stateless key, so you lose efficiency rather than funds. The cost is that wallet state stops being application data and becomes cryptographic state whose rollback can take user funds: hundreds of counters for hundreds of UTXOs, across several devices and several software wallets, on hardware where hash-based keygen already takes minutes. There are also capabilities we do not get back. Non-hardened BIP32 derivation, and with it watch-only wallets as we build them today. Compact Schnorr-style threshold signing. None of this makes SHRINCS a bad proposal, and the spec is honest about its own status: non-standard SLH-DSA parameters, constructions outside the NIST standard, security proof pending. It does mean the cost of this migration cannot be only measured in signature bytes. The stateful aspect of SHRINCS would be very challenging in terms of security and UX. The uncomfortable part is that picking the signature scheme may be the easiest question here. ledger.com/blog-shrincs-bitc…
16
24
123
16,659
Arc is fully live on @Ledger swapping ETH on mainnet to USDC on @arc is literally this easy. swap, send, receive all from Ledger Wallet, with your keys in your hands the whole time. takes a minute. try it out
USDC on Arc. Secured by Ledger from Day 1 🔐 Arc is live, and your USDC on @Arc is fully usable in Ledger Wallet™ from the moment it launches. Send, receive, and swap and put our USDC to work with your keys in your hand the whole time. Getting in early shouldn't mean compromising. Open Ledger Wallet and add your USDC on Arc today.
38
11
82
3,602
Mo retweeted
C-level access isn't something students usually get. Our CTO @P3b7_ sat down with Blockchain at Berkeley for an hour on post-quantum and AI agents. @CalBlockchain
How secure is your crypto in cold storage? 🔐 We sat down with Charles Guillemet (@P3b7_), CTO of @Ledger, to discuss hardware wallet security, post-quantum cryptography, and exploit-resilient agentic payments. Full podcast out now. 🎙️
1
2
5
4,684
Mo retweeted
A year ago, we launched Ledger N3XT: our education program for university blockchain clubs. Conferences, workshops, brunches, dinners, a hackathon, a research competition, and a lot of campuses later, here's a look back at the first year of Ledger N3XT.
15
9
96
21,268
Mo retweeted
Security used to depend on flaws being expensive to find. AI made them cheap. High-severity flaws flagged in 2026 are already 6x the four-year average. Our CTO @P3b7_ sits down with @Mo_RELS, Head of Brand Development, to discuss what that does to the threat model, why secure hardware holds where connected software folds, and the ethics of finding bugs at machine speed. Full episode here 👇
31
22
177
22,953
Everyone I talk to is asking about AI and jobs. Nobody's asking what it's doing to security. If you've been around here recently, that is obviously the bigger story.. so I asked @P3b7_ . Next week 👇
Finding a security flaw used to take an expert months. It now just takes a prompt. High-severity vulnerabilities flagged in 2026 are already 6x the four-year average. And we're just getting started. But there is hope. Our CTO @P3b7_ sits down with @Mo_RELS on what changed, why secure hardware holds where software folds, and what you can do about it. Subscribe wherever you get your podcasts. Full episode next week.
3
9
608
Mo retweeted
Fun fact: you can trade 39,000+ tokens with Ledger Wallet
37
16
130
22,892
Mo retweeted
You can now stake @Monad directly in the Ledger Wallet™ app. Your keys secured by hardware. Rewards in your wallet. 🔒
68
46
290
41,137
AI is eating software cyber-security, making responsible disclosure more important than ever. Coordinated disclosure protects users today. Hardware-anchored security is the structural answer for tomorrow. Both matter. Together.
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional. Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers. Which is exactly why the process around disclosure matters more than ever. How it works, and it is not complicated: ➤ A researcher finds a bug and contacts the vendor privately. ➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix... ➤ During that window both sides keep it secret while the vendor fixes and ships. ➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid. The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience: ❗Presenting a reproduction of an already-fixed bug as a live compromise. ❗Full disclosure of a bug that is not fixed yet. ❗"Critical vulnerability found" teasers, dripping details for engagement. Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem. So I have three asks: 1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more 2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth. 3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together. Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others Spread the message.
9
3
29
2,105
Mo retweeted
gm everyone. it's monday. the markets moving. are we ready to lock in?
63
13
203
20,861
Mo retweeted
For years, the @DonjonLedger has found vulnerabilities across the ecosystem, and disclosed every one of them the right way: privately, patched, then published. Today that standard becomes a shared industry commitment, alongside @Trezor, @FoundationHQ, @AnchorWatch and @_SEAL_Org. Responsible disclosure protects users. Attention farming doesn't. 👇
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional. Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers. Which is exactly why the process around disclosure matters more than ever. How it works, and it is not complicated: ➤ A researcher finds a bug and contacts the vendor privately. ➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix... ➤ During that window both sides keep it secret while the vendor fixes and ships. ➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid. The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience: ❗Presenting a reproduction of an already-fixed bug as a live compromise. ❗Full disclosure of a bug that is not fixed yet. ❗"Critical vulnerability found" teasers, dripping details for engagement. Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem. So I have three asks: 1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more 2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth. 3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together. Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others Spread the message.
21
17
197
34,347
Genuinely optimistic take on this: a wave of new researchers with AI tooling could be great for the ecosystem. It only works if disclosure stays coordinated, though. Patched bug ≠ live compromise, and panic isn't a security contribution. Worth reading in full 👇
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional. Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers. Which is exactly why the process around disclosure matters more than ever. How it works, and it is not complicated: ➤ A researcher finds a bug and contacts the vendor privately. ➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix... ➤ During that window both sides keep it secret while the vendor fixes and ships. ➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid. The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience: ❗Presenting a reproduction of an already-fixed bug as a live compromise. ❗Full disclosure of a bug that is not fixed yet. ❗"Critical vulnerability found" teasers, dripping details for engagement. Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem. So I have three asks: 1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more 2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth. 3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together. Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others Spread the message.
4
8
508
Oregon Blockchain saw this bounty and ran with it! Our members published papers across every available track and have already generated hundreds of engagements We appreciate @Ledger and @college_xyz for creating opportunities like this. You give students the chance to learn, grow, and connect with others in the space Check out the incredible work from some of our analysts below:
9
6
31
5,493