cryptd.in

암호화폐 친화적인 인재를 위한 대체 링크드인

Fake Ledger Wallet Exposed With Hidden Chip Stealing Seed Phrases and PINs

A cybersecurity researcher from Brazil exposed a large-scale scam operation after buying a “Ledger” hardware wallet from a Chinese marketplace listing that looked legitimate and was priced the same as the official store. The packaging appeared original from a distance, but the device was counterfeit.

When the researcher connected it to Ledger Live installed from ledger.com, it failed the Genuine Check, confirming it was not a real Ledger device. This failure led the researcher to open the device and examine its internal hardware and firmware.

Cloned Websites and Malicious Apps

Inside the shell, the researcher found a completely different chip, not the type used in a hardware wallet. The chip markings had been physically scraped off to hide identification. As per the researcher’s Reddit post, the device also contained a WiFi and Bluetooth antenna, which is not present in a real Ledger Nano S+. By analyzing the chip layout, they identified it as an ESP32-S3 with internal flash memory.

When the device booted, it initially masked itself as a Ledger Nano S+ 7704 with serial numbers and Ledger factory identity, but later revealed its true manufacturer as Espressif Systems.

After dumping the firmware and reverse engineering it, the researcher found that the PIN created on the device was stored in plaintext. The seed phrases from wallets generated on the device were also stored in plaintext. The firmware also contained multiple hardcoded domain references pointing to external command-and-control servers. These findings revealed that the device was designed to collect sensitive wallet data, with links to external servers.

The researcher also examined how the attack might work in practice. Although the hardware contained a WiFi and Bluetooth antenna, the firmware did not show evidence of wireless data transmission or WiFi access point connections. It also did not contain bad USB scripts for keystroke injection or terminal commands. Instead, the attack appeared to rely on user interaction outside the device itself.

According to them, the scam begins when a user scans a QR code included in the packaging. This QR code leads to a cloned website that looks like ledger.com. From there, users are prompted to download a fake “Ledger Live” application for Android, iOS, Windows, or Mac. The fake app shows a counterfeit Genuine Check screen that always passes. Users then create wallets and write down seed phrases, believing the setup is safe. Meanwhile, the fake app exfiltrates seed phrases to attacker-controlled servers.

The researcher decompiled the Android APK version of the fake Ledger Live app and found additional malicious behavior. The app was built with React Native and the Hermes engine. It was signed with an Android debug certificate instead of a proper signing key. It intercepted APDU commands between the app and device, made stealth requests to external servers, and continued running in the background for several minutes after being closed.

It also requested location permissions and monitored wallet balances using public keys, which allowed attackers to track deposits and amounts.

Not A Flaw in Ledger Security

The researcher stated that this is not a zero-day vulnerability and not a flaw in Ledger’s security design. Ledger’s Genuine Check and Secure Element were confirmed to work correctly. Instead, this is described as a phishing operation combining counterfeit hardware, malicious apps, and external infrastructure. The full operation includes hardware devices with ESP32-S3 chips, trojanized apps for Android and other platforms, and command-and-control servers used for data exfiltration.

The researcher also added that fake Ledger devices have been reported before, but this case is different because it maps the full system, including hardware, apps, infrastructure, and distribution through a shell company linked to marketplace listings. The researcher has submitted a report to Ledger’s Customer Success team and is preparing a full technical breakdown with further analysis of Windows, macOS, and iOS versions of the malware.

A few years back, another Reddit user 보고 receiving a Ledger Nano X in an authentic-looking package, but a letter inside raised concerns due to spelling and grammar errors. The letter claimed it was a replacement after a data breach.

A security expert later found the device had a flash drive wired to the USB connector, which was intended for malware delivery and potential theft.

게시물 Fake Ledger Wallet Exposed With Hidden Chip Stealing Seed Phrases and PINs 에 처음 등장 크립토포테이토.


댓글

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다

최신 피드

인기 카테고리

웹사이트 검색

인기 스토리

태그

#AlexeyPertsev (1) #BidenCryptoBan (1) #BidenElection (1) #BinanceVsCoinbase (1) #B비트코인 (435) #BitcoinETF (3) #B비트코인기초 (1) #B비트코인 취급 (1) #B비트코인가격 (5) #B비트코인가격수준 (1) #B비트코인펌프 (1) #B비트코인예치 (1) #B비트코인서지 (1) #BitcoinTop (1) #Bitfinex (1) #B비트 단위 (1) #브레이스브리지캐피털 (1) #BRC20토큰 (1) #BTC취득 (1) #B울리스틱 예측 (1) #BullishSentiment (1) #C중국광업 (1) #CPIP리뷰 (1) #CryptoAsset (2) #CryptoBattle (1) #CryptoBoom (1) #CryptoExpert (1) #CryptoInsights (1) #CryptoMania (1) #CryptoMarket (4) #CryptoPrediction (1) #CryptoPredictions (1) #CryptoRegulation (2) #CryptoTakeoff (1) #CryptoTiming (1) #CryptoTips (1) #CryptoTreasury (1) #CryptoUncertainty (1) #DerivativeJump (1) #Dogecoin (73) #DogecoinGains (1) #DogecoinVolume (1) #DutchCourt (2) #ECommerce (1) 1TP5테엘살바도르비트코인 (1) 1TP5테더리움 (69) 1TP5테더리움통증 (1) 1TP5테더리움가격 (1) 1TP5전문가 의견 (1) #FedRateCut (1) #FiatCurrency (1) #FinancialImpact (1) #FinancialPrivacy (1) #FirmShutdown (1) #FrozenAccounts (1) #IllicitFunds (1) #인플레이션데이터 (1) #투자 (1) #투자손실 (1) #일본기업 (1) #LegalAction (1) #LegalImpact (1) #법률 (1) #라이트닝 네트워크 (1) 1TP5시장분석 (3) 1TP5시장 모니터링 (1) 1TP5시장 예측 (1) 1TP5시장 예측 (1) #MarketProjection (1) 1TP5마켓지원 (1) 1TP5시장변동성 (1) #M결혼 (1) #MemeCoin (5) #MemeCoins (2) #M광부수익성 (1) #MoneyLaundering (2) #MtGox (4) 1TP5북한암호화 (1) 1TP5노보그라츠예측 (1) #P가격 마일스톤 (1) #P가격 예측 (2) #P가격 질문 (1) #PriceSurge (1) #P형량 (1) #QuantAnalysis (1) 1TP5규제압력 (1) #SEC안티크립토 (1) #ShibaInu (5) #SocialBuzz (1) 1TP5기술분석 (1) #Toncoin (3) #TornadoCash (3) #TornadoCashDev (1) 1TP5토네이도캐시개발자 (1) #UKCrypto (1) #업사이드 잠재력 (1) #USCongress (1) #와이오밍랜드 (1) #XRP가격 (1) #XRP업스윙 (1)

유용한 링크

유용하다고 생각되어 공유하고 싶은 링크.