Ledger just told Bitcoin holders to touch nothing. Not a firmware update. Not an advisory note. A stark security bulletin: do not claim the fork coins. Do not transfer them. Do not sign on the BIP-110 chain.
Translation: a hardware wallet maker told users to decline free money. In all my years tracking this market, when a security company tells you to refuse an airdrop, the airdrop is the trap.
The bulletin, dated August 9th, is surgically precise. BIP-110, a Bitcoin soft fork proposal, lacks replay protection. Each transaction you sign on the proposed fork chain is simultaneously valid on Bitcoin's mainnet. The signature doesn't bind to a chain. It binds to a transaction — and that transaction can be rebroadcast anywhere the signature verifies.
The sequence hits hard. You hold BTC. The fork credits you an equal amount of BIP-110 coins, 1:1 with your Bitcoin balance. You decide to dump the "free" tokens. You build a transaction on the BIP-110 chain and sign it. It confirms. Then the exact same signed transaction — no changes, no re-signature, no second approval — appears on Bitcoin mainnet. Your mainnet BTC moves to the same destination as your fork coins.
You didn't get hacked. Your seed phrase wasn't leaked. The consensus layer simply failed to separate two chains that share one signature space.
Panic is a lagging indicator for the prepared. So let me unpack what BIP-110 actually is, why Ledger ended up waving this flag, and what you should do before the fork goes live.
The fork that skipped the memo
BIP-110 sits in Bitcoin's proposal archive, numbered in a range that points to roughly 2015-2016. It's a soft fork proposal designed to alter mainnet consensus rules. The implementation details matter less than the structural consequence: if this activates and splits the network, both chains inherit the identical transaction history and the identical set of addresses.
That's where replay attacks are born.
I watched the 2017 Bitcoin Cash split from the trading desk, three months after spending my nights tracking whale flows through the EOS pre-sale. That fork was a circus of ego and panic. But both sides got one critical thing right: replay protection. The BCH camp modified the signature hash format, effectively quarantining transactions to a single chain. Bitcoin Core added its own safeguards. Users could sell their BCH without their BTC getting yanked along.
Since that summer, replay protection has been the industry's minimum bar for any chain split. It's not a feature. It's the parachute on a skydiving trip.
BIP-110 skipped the parachute.
No chain-ID binding. No unique sighash prefix. The transaction format remains fully compatible across both chains. Ledger's own bulletin confirms its device CAN sign these transactions — nothing technically stops you from participating. And that permissiveness is exactly the danger.
We traded floor prices for floor stability in 2017. BIP-110 asks us to trade floor stability for a coin that never finished its own design.
The mechanics of replay (step by step)
Precision matters here.
When you sign a Bitcoin transaction, your signature commits to specific fields: inputs, outputs, amounts, certain flags. It does NOT commit to a chain identifier, because the standard never required one. On any network that accepts the same transaction format, your signature is valid.
Replay protection is the deliberate insertion of a chain-binding mechanism — usually a special sighash prefix — that invalidates the signature on any non-native chain.
Without that mechanism:
- The fork activates. Your BTC balance is mirrored on both chains.
- You hold fork coins on the BIP-110 chain.
- You build a transaction: send fork coins to a buyer's address.
- You sign and broadcast. The fork chain confirms the spend.
- That signed transaction is now public, sitting in the mempool.
- An attacker grabs it and rebroadcasts it to Bitcoin mainnet.
- Mainnet nodes validate the signature against your mainnet UTXO.
- It's valid. The transaction confirms. Your mainnet BTC is spent to the same buyer address.
Your fork coins are gone. Your Bitcoin is gone. The buyer paid for one asset and received both.
No zero-days. No private key theft. No malicious contract. Just a signature that was never told which chain it belonged to.
People call this a vulnerability. It's not. It's a structural guarantee. The only variables are time and effort. Every serious mempool eventually gets scanned for replayable transactions, and BIP-110's chain would be a goldmine for exactly that kind of script.
During the FTX collapse in 2022, I spent fourteen hours tracing Alameda's outflows while the lawyers were still drafting their first statements. The lesson from that forensic work is universal: if a structure has a hole, someone will exploit it. Not might. Will. And the attack scripts are always faster than proposal revision cycles.
Why your wallet can't save you
Here's the part most users misunderstand.
Ledger's bulletin is not a software fix. It's an admission that the fix is impossible from the wallet layer. The device can sign these transactions. The signatures are valid. The problem isn't the tool; it's the protocol's failure to differentiate chains.
A hardware wallet's job is to authorize spending. It receives a transaction, verifies it against your keys, and signs it if cryptographically correct. There is no "which chain is this for?" field in the data it validates. The wallet is structurally blind to replay risk.
That's the security responsibility vacuum in Bitcoin's open architecture:
- The consensus layer defines what a valid transaction looks like. It failed to require chain binding.
- The application layer (wallets) executes what consensus permits. It cannot compensate for a permission that shouldn't exist.
- The user layer absorbs the entire risk, whether they understand it or not.
Ledger can warn you. It cannot stop you. It cannot stop the attacker who rebroadcasts your transaction. It can only tell the truth about the gap — which is more than most infrastructure providers will do.
Smart contracts don't care about your intentions. They validate signatures and move value. BIP-110's transaction format is a signature that moves value on two ledgers at once.
The economics of "free" fork coins
Strip the code down to incentives, and this becomes an absurd economic proposition.
The nominal acquisition cost of the BIP-110 airdrop is zero. It materializes in your address as a 1:1 match to your Bitcoin. But the effective cost of claiming it is the full value of your mainnet BTC, weighted by the probability of replay. Even a conservative 1% chance of losing a $60,000 position wipes out any possible profit from a few hundred dollars of fork tokens.
This is a negative expected value asset. The act of claiming it is a transfer of wealth from you to whoever is on the other side of the trade.
Fork coins as a class have no revenue, no treasury, no team, no roadmap. BIP-110's token is no exception. Its entire price is a speculative bet that someone will buy it while ignoring the structural hazard attached to the claim.
The rational move, in any sober portfolio analysis, is to not claim at all.
The exit liquidity was already gone before the fork activated. The only exit is the trap.
What this means for the market
The immediate reaction to Ledger's warning will be defensive. Bitcoin holders who understand replay risk will do two things: move coins into cold storage and stop transacting until the fork narrative resolves. On-chain activity dips. Wallets go quiet. Settlement velocity slows.
That's not a crash signal. It's a survival reflex.
Listings are the bigger question. Centralized exchanges need to decide whether to support BIP-110 tokens. A compliant exchange faces a nightmare: if it lets users claim fork coins and a replay drains their Bitcoin, the exchange is legally exposed. Most venues will stay silent. They might quietly wait for the fork to add replay protection, or they might ignore it entirely.
That pushes fork-coin volume into OTC channels — where counterparties are opaque, settlement is manual, and replay risk compounds every step. Even the most aggressive arbitrageur in Dubai or Singapore will pass on an asset whose claiming process can trigger a mainnet loss.
Volatility is just velocity without direction. BIP-110 is generating volatility in both directions without establishing any positive value proposition.
The governance story beneath the surface
Here's what I find most telling.
A hardware wallet manufacturer — not Bitcoin Core developers, not the BIP-110 authors, not any consensus-level authority — set the safety boundary for this fork. Ledger's bulletin, if taken seriously, determines the fork coin's market viability before the fork even activates.
That is enormous informal power.
It means Bitcoin governance isn't just about miners and core devs. Infrastructure providers — wallet vendors, exchanges, custody services — hold an effective veto over a fork's legitimacy. They can't force code changes. But they can steer market behavior with a single announcement.
BIP-110's missing replay protection also exposes a flaw in the proposal process itself. The BIP workflow is voluntary, and no formal gatekeeper reviews proposals for security completeness. A fork that ships without replay protection passed through whatever informal discussions happened and reached the public anyway. The process failed, so the market had to self-correct through an application-layer company.
Speed eats strategy for breakfast. BIP-110's authors took their time, but their strategy was missing the single ingredient that makes a fork non-lethal.
Regulatory and compliance backdrop
The regulatory angle is quieter but real. Ledger is a French company, bound by EU standards around financial security and consumer protection. Its warning serves double duty: safeguarding users and limiting its own exposure down the line.
If a user got replayed because Ledger issued no warning, the brand would be devastated and liability questions would follow. The bulletin is the cheapest insurance either side can buy.
For the BIP-110 fork coin itself, regulatory clarity is nonexistent. It's not a registered security, but it's not clearly a commodity either. If the team behind the fork holds a large supply, or introduces a treasury or foundation, the token drifts toward security territory — with all the compliance problems that brings. No exchange wants to be the test case for listing a replay-vulnerable asset.
Every layer of this situation leads to the same advice: distance.
The contrarian read
The consensus take is simple: BIP-110 is dangerous; avoid it. That's true. But the sharper insight is that this event is about the shifting locus of control in Bitcoin, not about one flawed proposal.
By issuing this warning, Ledger has become the de facto security regulator for the Bitcoin fork narrative. Not because it was elected, but because it moved first. Competitors — other wallet makers, custody providers, even exchanges — will now be measured against Ledger's speed. Did you warn your users? Did you warn them in time? Did you have the technical sophistication to identify the replay vector before the fork went live?
That's the new competitive battleground: who detects the structural flaw first.
The second angle is uncomfortable. BIP-110's failure exists because the proposal process has no security bar. In 2017, the industry learned what replay protection was and why it mattered. Eight years later, a proposal still reaches a public warning stage without it. That's not a single project's failure. It's a systemic gap in how Bitcoin proposals are reviewed.
And the market should watch what that gap produces next. If replay protection becomes the dividing line, then Bitcoin governance just gained a de facto review board made of wallet makers and custodians. That's either a healthy evolution or an uncomfortable concentration of power.
Time will tell.
The takeaway
Three signals determine what happens next.
First: BIP-110's next revision. If the authors add replay protection, the risk profile collapses and the fork becomes a normal, if unexciting, network event. If they don't, treat the fork as an active threat.
Second: exchange behavior. Major venues quietly staying silent tells you everything about how the market truly appraises this asset. No listing means no legitimacy.
Third: your own habits. If you hold BTC, move it to a wallet you control, verify its firmware, and wait. Don't test the airdrop. Don't claim tokens on an unprotected fork. Don't be the transaction that teaches an attacker the fork is live.
The charts blinked, but the liquidity didn't. Not this time. And the next time a proposal forgets replay protection, you'll already know the drill.
Keep your signatures on one chain only.