Ethereum

Ledger's BIP-110 Replay Warning: A Ghost Fork With a Borrowed Name

HasuTiger
The most dangerous sentence in crypto this week came from a hardware wallet. Ledger — the French firm holding signing keys for millions of self-custody users — declared that a Bitcoin fork named "BIP-110" is coming, that it lacks replay protection, and that its devices can technically sign the fork's transactions. Stop. Read that again. Ledger didn't say "we blocked it." They said "we can sign it." That's not a warning. That's a confession. A hardware wallet doesn't test against nonexistent chains. If Ledger's firmware can sign these transactions, the fork's code has already passed internal compatibility testing. It exists. It runs. It's waiting. We audited the silence between the lines of code. What surfaced isn't a new proposal. It's a ghost with a borrowed name — an old soft fork's identity recycled for a chain that shouldn't exist, with no replay protection, no disclosure, and no accountable developer. Here's where the story bends in a direction nobody's covering. BIP-110 isn't new. In Bitcoin's actual history, BIP-110 is CHECKSEQUENCEVERIFY — CSV — the opcode that enabled relative timelocks. It shipped alongside BIP-68, BIP-112, and BIP-113, and activated on mainnet in November 2016, months before SegWit. That soft fork is baked into Bitcoin's consensus layer. It's been running for nearly a decade, quietly and entirely uncontroversially. So when a security advisory describes "BIP-110" as an emerging fork chain, alarm bells should ring. Not because forks are dangerous — all forks are. But because the label doesn't match history. The most plausible reading is a reversion fork. Some group — miners, political opponents of SegWit-era upgrades, ideological purists — threatening to run node software with those upgrades stripped out. A chain sharing Bitcoin's entire history but rejecting its recent rule changes. A chain with identical transaction format. A chain with zero replay protection. This matters because of where Ledger sits. Hardware wallets are the security gatekeepers of the Bitcoin ecosystem. Exchange users get migration paths; self-custody users are on their own. When Ledger shifts from "we're monitoring" to "here's how you avoid losing assets on both chains simultaneously," something in the background is already moving. Bitcoin forks were a 2017 narrative — BCH, BSV, BTG all rode that wave and all bled out. The attention cycle moved on. So why is Ledger resurrecting the category now? The answer hides in the missing metadata. The advisory carries no activation height, no block number, no node client repository, no GitHub organization, no testnet status, no miner commitments, no developer identities. Nothing. The fork's creators are absent from the conversation. The only entity confirming the fork exists is a wallet vendor warning you not to touch it. Let's get the mechanism precise, because this is where the emotional fog lifts and the actual math appears. Replay attacks work because a fork shares its full pre-fork history. The ownership proof for a Bitcoin is a private key controlling an address with one signature scheme. If chain A and chain B accept identical transaction formats — same sighash, same script rules, no chain identifier — then a transaction signed on one chain is valid on the other. An attacker sniffs the raw signed transaction, rebroadcasts it on the second chain, and the victim watches the same coin burn twice. One signature. Two catastrophes. This is exactly why BCH implemented SIGHASH_FORKID in 2017. That flag altered the sighash algorithm to include a fork identifier, rendering BCH transactions structurally invalid on the BTC chain. It wasn't elegant. It was survival — and it set the industry standard for responsible forks. The BIP-110 fork, as presented, meets zero elements of that standard. No replay protection. No fork ID. No OP_RETURN chain marker. No deviation from Bitcoin's transaction structure. Every transaction signed on the fork chain is a potential mainnet replay. Every claim interaction is a potential liquidation event. Based on my audit experience, I've seen this exact profile before. In 2017, during the ICO sprint, I spent three weeks auditing an ERC-20 token contract and found an integer overflow in the transfer function that could have drained millions. That project launched anyway, with a ticking bomb in its bytecode. The pattern is unmistakable now: when a project ships without the most basic protective mechanism, it's not an oversight. It's a tell. Either the developers don't understand the threat model, or they understand it perfectly and are proceeding anyway. And there's a second tell inside Ledger's own statement. If the device can "technically sign" these transactions, the fork's transaction format has been validated against the world's most distributed hardware wallet. That means the fork's codebase is real, testable, executable. It's not a whitepaper. It's a running implementation. The question nobody in the coverage has asked: who submitted that code to Ledger — and why does the warning confirm compatibility instead of blocking it? I learned to feel this hesitation in DeFi summer 2020, when I dropped 50 ETH into a Uniswap V2 liquidity pool and felt the heat of the interface before I understood the math. The texture of those one-click claim flows — the smooth dashboards, the engineered sense of safety — was designed. Fork claim interfaces carry the same design language. The button says "Claim." The flow says "Free." And the signature you sign is identical to the one your Bitcoin mainnet validates. That's not a UX bug. That's a hunting pattern. Now the economics, because the rational case is even more brutal than the technical one. A fork token doled out 1:1 against BTC sounds like free money. It isn't. Its expected economic value sits near zero, and the arithmetic is blunt. First, no DeFi ecosystem. A chain that only moves value has no native demand, no yield source, no place for capital to work. Second, the liquidity deadlock. No replay protection means exchanges won't list it. Exchanges spent years cleaning up replay contamination — Ethereum Classic's chain still crawls with it. No listing means no controlled sell environment. No controlled sell environment means DEXs and OTC desks, channels with even weaker replay defenses. Third, the claim itself is the trap. To receive the fork token, you must sign a transaction on the fork chain. If the fork lacks replay protection and your signature pattern is identical, you've potentially authorized the same transaction to be replayed against mainnet BTC. The cost of claiming a worthless token is losing the most valuable coin in crypto. The asymmetry isn't debatable. It's the worst trade in the history of value transfer. Add the market lens, because timing is everything. We're in a bull market, which means the default retail response to a "new Bitcoin fork" is not caution — it's FOMO. A new ticker. A 1:1 airdrop. A promise of free coins. The ETF era compounds the problem: institutional custodians holding spot Bitcoin cannot touch a fork claim without triggering fiduciary reviews, tax events, and custody infrastructure changes. The rational institutional move is to ignore the fork entirely. The rational retail move is the same. But rational isn't the default state in a bull run — which is exactly why Ledger issued this warning. This is also a psychological crisis profile, and FTX taught me to read those. In 2022, I watched smart people paralyze themselves chasing failed bridges and collapsed protocols while the emotional story stayed simpler: loss aversion converts panic into inaction. The group Ledger warns is the self-custody, security-anxious, long-term holder base. These are not degen traders. They're disciplined savers. And disciplined savers are precisely the demographic most vulnerable to a "free claim" narrative. They will follow a third-party tutorial. They will connect a hot wallet to an unknown interface. They will configure custom network settings. Ledger's warning isn't aimed at the reckless. It's aimed at the careful. That's what makes it urgent. Now the angle nobody's covering. Ledger's advisory isn't primarily protecting you. It's protecting Ledger. When a hardware wallet manufacturer preemptively declares "we can sign it, but you shouldn't claim it," they're immunizing themselves against future liability. "We warned you in writing" is a legal moat — it converts a potential class of lawsuits into a folder of receipts. Follow the incentive, and the advisory reads differently: not as alarm, but as architecture. Second blind spot: the name. If BIP-110 is already activated, the fork's label is either an error or a weapon. An error means the technical credibility collapses instantly — you cannot fork a chain correctly if you misread the BIP registry. A weapon means the intent is manufactured legitimacy through confusion. Either conclusion eliminates the reason to trust the fork's leadership. And there is no leadership. No named developers. No community. No advocacy. Just a warning from a wallet vendor. Compare that to BCH — it had exchange backing, celebrity miners, and a working narrative before the split. BSV had a legal drama. BTG had a marketing budget. This "BIP-110" has a warning label. That's the entire product. And the timing of this advisory is its own signal. Issued in the empty window before a rumored activation date — the exact moment users would start receiving "claim your fork coins" tutorials — the warning reads less like a discovery and more like a scheduled intervention. So here's the watchlist, and it's short. First: do not claim the fork token. The cheapest trade is the one you don't sign. Second: monitor Ledger's competitors. If other vendors issue copycat advisories within days, this fork is a real, testable codebase — and the window to study it is closing. Third: track exchange listings. If no major venue lists this coin within a month of any activation, the verdict writes itself. A ghost chain. And the only thing surviving will be the lesson: when a wallet vendor warns you about a chain you've never heard of, the silence between the lines is the entire story. The code never lied. The marketing did.

Ledger's BIP-110 Replay Warning: A Ghost Fork With a Borrowed Name