Security Advisory

Bloom III Sync Leak Ledger Live host-side sync · Public Service Announcement

Active Issue

The Bloom III filter bug affects Ledger Live's host-side sync. The secure element remains secure — however, your address set is exposed during re-sync operations.

Ledger is aware of the issue. No patch has been released yet. Users are advised to re-attest their device to verify exposure.

Affected component Ledger Live host-side sync (Bloom III filter)
Secure element Not affected — private keys remain secure
Exposure vector Address set leaks during re-sync
Patch status Pending — no firmware flash required
Re-attest your device
Your Ledger will display the attestation on its screen. No seed phrase is required and no firmware flash will occur. This check is read-only.
Click the button above to run a simulated attestation check.