Ledger has confirmed the restoration of control over its Discord server after a moderator's account was hacked and used to distribute phishing links.
Discovery of the Hack
The breach occurred on May 11 when an attacker took over a contracted moderator's account. An official post on Ledger's Discord confirmed the attack and described the measures taken.
Methods of Attack
The attacker leveraged enhanced privileges to deploy a bot that posted scam links directing users to a phishing site mimicking a Ledger verification page. Users were prompted to enter their 24-word seed phrases under the guise of a critical update.
Preventive Measures
The issue was swiftly contained: the compromised account was removed, the bot was deleted, the website reported, and all relevant permissions were reviewed and secured. It remains unclear if any users were victimized by the attack.
This phishing incident highlights the importance of account security and staying informed about the security practices related to hardware wallets.