Donjon is the Security Research team at @Ledger. Follow us to get the the latest news from our research.
More info on our blog: https://t.co/Ugy5xfM4gX
Our applied PQC series continues.
This time, @k15ab_ and @6c656e69 attack masked Kyber768.
Masking defeats first-order SCA. But with a centered cross-product and the right covariance model, a second-order CPA recovers the secret coefficient.
https://t.co/ViCQ5KrKIf
🤖AI didn't just add a tool to the developer toolbox. It changed the economics of security itself.
Attackers can now explore faster, iterate cheaper, and scale offense at machine speed. They won't wait for the perfect model. Neither can defenders.
The tempting move is to wait for the next frontier model. But let's be honest, it's just a way to avoid doing the work. 😏
A model is not a security capability. A prompt is not an agent. Asking your IDE "is this secure?" will not build you an offensive security team.
This is why the @DonjonLedger built Cerberus. Not a model. A harness around models: iteration loops, memory, tools, backlog, triage, verification, auditability, budgets, and human control.
Security has never been one answer. It's a loop.
The hard part is the last mile. A hypothesis is not a finding. You have to reproduce it, exploit it, prove the impact, verify the preconditions, produce evidence an engineer can act on, then fix it.
AI has to take the team all the way, not stop at a plausible report. Plausibility is dangerous in security.
This is already producing real, exploitable vulnerabilities across very different stacks (C, .NET, Scala and more), responsibly disclosed. CVEs, PRs, fixes, real impact.
Both of these are true at once: AI floods the channel with noise, and buried in that noise are real attackers who know how to use these systems properly.
Security has always been cat and mouse. AI didn't create that reality. It made it visible, and it dropped the price of a cat to almost nothing. The cats are everywhere now.🐈🐈🐈
No fight, no chance.
Read more in the latest Donjon's article:
https://t.co/DQAzVZdHLW
AI is changing the economics of offensive security.
More scale. Lower cost. Faster iteration.
At Ledger Donjon, we’re building Cerberus: a team of agents that audit, triage, prove, and patch with humans in the loop.
No fight, no chance.
✍️ @b0l0k_
https://t.co/J2XGtEFD79
⚡"Breaking Post Quantum Cryptography with AI"
A non-profiled deep-learning side-channel attack on an unprotected reference implementation. The convolutionnal neural network just plays the role CPA's correlation used to play.
The @DonjonLedger 's PQC journey continues. They pointed their open-source deep-learning SCA tooling at the NIST-standardized ML-KEM reference.
No clone device. No profiling phase. No fixed leakage model.
Only EM traces, chosen ciphertexts, and a small MLP trained per key hypothesis. The correct key is the one under which the network actually learns. ~400 traces. Unprotected target, no masking, no shuffling.
- ML-KEM is mathematically sound and standardized.
- A reference implementation running on a real chip, without countermeasures, leaks the secret in minutes.
PQC security does not stop at standardization. It starts when implementations meet real-world attackers, with probes, not just headlines.
Read the article: https://t.co/YTdkS7S6oZ
We continue our series on applied PQC.
This time, a study of side-channel attacks on ML-KEM by @k15ab_ and Alain M.
Math is the foundation, but in the real world, attackers have other tricks.
https://t.co/LMIn7YeELM
Security is an economic game: make attacks too expensive to attempt. AI is breaking that equation. Exploits that took months and seven-figure budgets now take hours with an AI subscription. The old playbook won't cut it. The asymmetry that kept us secure is gone...
🚨Only days after Coruna, one of the first large-scale iOS exploit kits, DarkSword is already being exploited in the wild.
Coruna showed the pattern: state-grade iOS exploits don’t stay in government hands. They leak, spread, and end up in broader ecosystems. One visit to a compromised site, and your phone, including your crypto, is gone.
DarkSword confirms it.
- Another state-grade exploit chain.
- Already reused by multiple actors.
- Already deployed at scale via watering-hole attacks.
- Targets so far: Ukraine, Saudi Arabia, Turkey, Malaysia.
- Victim model: anyone who visits a compromised but legitimate website.
⚠️No click. No warning. Full device compromise.
Data exfiltration. Real-time surveillance. Total loss of control.
Affected: iOS 18.4 → 18.7.
This used to be rare. Targeted. Surgical.
Now it’s industrialized.
👉Two major iOS exploit chains in less than a week isn’t noise, it’s a shift.
From now, you should assume your phone is compromised,
Stop treating it like a safe.
https://t.co/JzDoiVOQzl
Our phones were never designed to be secure vaults. The @DonjonLedger proves that every single day.
For years, we’ve trusted our phones to protect everything: our data, our identity, our money. But smartphones are inherently fragile. They’re multipurpose, always-connected devices built for convenience first — not hardened security.
That model may have been enough for the early internet of information. It doesn’t work for the internet of value. When a single vulnerability can put hundreds of millions of devices at risk, it’s a reminder of a simple truth: the device you use every day should not be the final line of defense for your digital value.
875 million Android devices can be compromised in under 60 seconds. That’s exactly why your phone should never be where your value ultimately lives. Pair it with a @Ledger signer and use the Ledger Wallet app.
https://t.co/3MRDkd4ZqA
https://t.co/kytm5B7BSC
🚨 @DonjonLedger has struck again discovering a MediaTek vulnerability potentially impacting millions of Android phones. Another reminder that smartphones aren’t built for security. Even when powered off, user data - including pins & seeds - can be extracted in under a minute.
Exploiting Keyspace Reduction and Relay Attacks on NFC cards. 🔓📡
Proud to see @DonjonLedger’s name on this research — thanks to @doegox.
Go read it: https://t.co/24oUY0ZhU1
What if a hacker could gain total control of your smartphone, not via malware, but the hardware itself?
The @DonjonLedger discovered a potentially unpatchable flaw impacting MediaTek Dimensity 7300 - a popular Android phone SoC - enabling arbitrary code execution in minutes. Here’s how 🚨
⚠️ Our white hat team, the @DonjonLedger, discovered a flaw in Tangem cards that makes brute force attacks possible. As always, the Donjon followed responsible disclosure to inform Tangem, user protection is our priority. We can now reveal our findings in full: 🧵👇
Security leaves no room for error, a single variable mishandled, and the entire security model can collapse.
We're excited to share an illustration of this through our recent research on the Tangem card.
Big thanks to the @Tangem team for their responsiveness and collaboration!
🚨At Ledger Donjon, we don’t just secure our own products, we help make the entire crypto ecosystem safer.
As part of our ongoing security research and responsible disclosure efforts, we identified an important vulnerability in Tangem’s Android app.
👇🧵
Donjon is at @BlackHatEvents Asia this week! Karim (@k15ab_ ) is presenting his research on using deep learning attribution methods for fault injection attacks.
Don't miss his presentation:
https://t.co/wQEjEYcMvB