Crypto wallet maker Ledger dug itself into a deeper public relations hole on Wednesday when its support team said in a now-deleted tweet that "technically speaking it is and always has been possible to write firmware that facilitates key extraction," thus allowing the company to extract its users' keys.
While answering queries about the firm's new wallet recovery service, Ledger Support sent a couple of tweets that likely did little to assuage its users' concerns, suggesting that it could make its customers' assets vulnerable in any way it wanted to, but has – thus far – not done so.
"You have always trusted Ledger not to deploy such firmware whether you knew it or not," the company said in the tweet. "It's important to understand that at the end of the day, any hardware wallet solution a user chooses to go with will always require that person to trust this developer to build and maintain a secure device to store your assets."
After erasing the tweets, Chief Technology Officer Charles Guillemet tweeted in an attempt to clarify the situation and downplay the initial tweets. A Ledger spokesperson also reached out to CoinDesk to say that the company can't extract users' keys and any action related to keys needs to be approved by the customers first.
"Any action that interacts with a user's keys needs to be approved by the user through their Ledger. We cannot extract their keys, and will not extract keys," the spokesperson said.
Ledger's "Recover" service was met with consternation from the crypto community earlier this week on grounds that it undermines the firm's brief of privacy and security. The optional recovery service would allow users to backup their seed recovery phrase (a random string of words) through encrypting it in fragments with third parties.
Users fear that splitting the key between third parties could leave it vulnerable, effectively negating the main purpose of a hardware wallet against other storage options.
Ledger has argued that this sort of backup option is in fact popular as the possibility of assets becoming irrecoverable simply by mislaying a random set of words could prove a deterrent to investing in crypto.
"This is what future customers want,” CEO Pascal Gauthier said during a Twitter Space. “This is the way that the next hundreds of millions of people will actually onboard to crypto.”
Justin Sun, founder of Tron and stakeholder in crypto exchange Huobi, also defended Ledger, describing the company as a "reliable partner time and time again," in a Twitter post.
"I am confident that Ledger will persist in their dedication to serving their customers with the highest quality hardware wallets," he added. "Their commitment to security and customer service is unparalleled."
UPDATE (May 18, 15:30 UTC): Adds Justin Sun comments.
UPDATE (May 18, 17:46 UTC): Updates to include comments from spokesperson and follow up tweet by the CTO.
CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk offers all employees above a certain salary threshold, including journalists, stock options in the Bullish group as part of their compensation.