Authors

Ledger Donjon

Ledger's security research team. It ran the Capture the Fortress CTF in 2020 and one challenge left a funded Bitcoin address behind.
IDledger-donjon11 / 18organization · 1 collection · 2020-10-28
Subject

Ledger Donjon

bitcoin

Ledger's security research team, which ran the Capture the Fortress CTF in 2020.

Puzzles
1
Prize recorded
-
Still unsolved
0 · -
closed 1 / 1

Log

 

Introduced on 2018-12-11 by Ledger's CSO Charles Guillemet as an internal security evaluation lab of eight experts covering software, side channel and fault attacks.

ledger.com/blog/introducing-ledger-donjon
 

Says it open sources its attack tools and methodology and drives Ledger's bug bounty program.

ledger.com/blog/introducing-ledger-donjon
 

Capture the Fortress ran from 2020-10-28 to 2020-11-18 as a jeopardy CTF with more than 15 challenges. First prize was 400 dollars and a Ledger Backup Pack.

ledger.com/blog/Capture-the-Fortress
local dataset / no network · data 76d0 7b2c 1a2f

Who this is

The Donjon is the team inside Ledger that attacks Ledger's own products, and other people's. Charles Guillemet introduced it in December 2018 as eight experts in software attacks, side channels and fault injection, with a stated habit of open sourcing the tools. In October 2020 it ran a public CTF, Capture the Fortress: three weeks, more than fifteen challenges, first prize 400 dollars and a Backup Pack. Scissors Secret Sharing was the 100 point warm up, twelve BIP39 words with ten out of order and a real address at the end. That's why it's in a dataset of funded puzzles and the other challenges aren't.

What the record says

Two Ledger blog posts. The introduction, for what the team is and what it says about itself, cited twice because two different facts come from it. The CTF announcement, for the dates and the prizes. The profiles are the Donjon's own site and that announcement. No individual is on the record beyond the CSO who signed the founding post, because the challenges were published as the team's.

The record

src/collections/ledger_donjon.ts
static readonly author = party("Ledger Donjon", {
  key: "ledger-donjon",
  kind: PartyKind.Organization,
  about: "Ledger's security research team, which ran the Capture the Fortress CTF in 2020.",
  profiles: [
    profile("website", "https://donjon.ledger.com/"),
    profile("website", "https://www.ledger.com/blog/Capture-the-Fortress"),
  ],
  facts: [
    fact("Introduced on 2018-12-11 by Ledger's CSO Charles Guillemet as an internal security evaluation lab of eight experts …", "https://www.ledger.com/blog/introducing-ledger-donjon", { date: "2018-12-11" }),
    fact("Says it open sources its attack tools and methodology and drives Ledger's bug bounty program.", "https://www.ledger.com/blog/introducing-ledger-donjon", { date: "2018-12-11" }),
    fact("Capture the Fortress ran from 2020-10-28 to 2020-11-18 as a jeopardy CTF with more than 15 challenges. …", "https://www.ledger.com/blog/Capture-the-Fortress", { date: "2020-10-21" }),
  ],
});

@agntn/puzzles·MIT license· Public data about public puzzles. Balances come from the chains' explorers through the worker, cached for five minutes. Every key here was public before it landed in a record.