Fake Ledger Wallet Exposed With Hidden Chip Stealing Seed Phrases and PINs

221 views
Default Post Cover

A cybersecurity researcher from Brazil exposed a large-scale scam operation after buying a “Ledger” hardware wallet from a Chinese marketplace listing that looked legitimate and was priced the same as the official store. The packaging appeared original from a distance, but the device was counterfeit.

When the researcher connected it to Ledger Live installed from ledger.com, it failed the Genuine Check, confirming it was not a real Ledger device. This failure led the researcher to open the device and examine its internal hardware and firmware.

Cloned Websites and Malicious Apps

Inside the shell, the researcher found a completely different chip, not the type used in a hardware wallet. The chip markings had been physically scraped off to hide identification. As per the researcher’s Reddit post, the device also contained a WiFi and Bluetooth antenna, which is not present in a real Ledger Nano S+. By analyzing the chip layout, they identified it as an ESP32-S3 with internal flash memory.

When the device booted, it initially masked itself as a Ledger Nano S+ 7704 with serial numbers and Ledger factory identity, but later revealed its true manufacturer as Espressif Systems.

After dumping the firmware and reverse engineering it, the researcher found that the PIN created on the device was stored in plaintext. The seed phrases from wallets generated on the device were also stored in plaintext. The firmware also contained multiple hardcoded domain references pointing to external command-and-control servers. These findings revealed that the device was designed to collect sensitive wallet data, with links to external servers.

The researcher also examined how the attack might work in practice. Although the hardware contained a WiFi and Bluetooth antenna, the firmware did not show evidence of wireless data transmission or WiFi access point connections. It also did not contain bad USB scripts for keystroke injection or terminal commands. Instead, the attack appeared to rely on user interaction outside the device itself.

According to them, the scam begins when a user scans a QR code included in the packaging. This QR code leads to a cloned website that looks like ledger.com. From there, users are prompted to download a fake “Ledger Live” application for Android, iOS, Windows, or Mac. The fake app shows a counterfeit Genuine Check screen that always passes. Users then create wallets and write down seed phrases, believing the setup is safe. Meanwhile, the fake app exfiltrates seed phrases to attacker-controlled servers.

The researcher decompiled the Android APK version of the fake Ledger Live app and found additional malicious behavior. The app was built with React Native and the Hermes engine. It was signed with an Android debug certificate instead of a proper signing key. It intercepted APDU commands between the app and device, made stealth requests to external servers, and continued running in the background for several minutes after being closed.

It also requested location permissions and monitored wallet balances using public keys, which allowed attackers to track deposits and amounts.

Not A Flaw in Ledger Security

The researcher stated that this is not a zero-day vulnerability and not a flaw in Ledger’s security design. Ledger’s Genuine Check and Secure Element were confirmed to work correctly. Instead, this is described as a phishing operation combining counterfeit hardware, malicious apps, and external infrastructure. The full operation includes hardware devices with ESP32-S3 chips, trojanized apps for Android and other platforms, and command-and-control servers used for data exfiltration.

The researcher also added that fake Ledger devices have been reported before, but this case is different because it maps the full system, including hardware, apps, infrastructure, and distribution through a shell company linked to marketplace listings. The researcher has submitted a report to Ledger’s Customer Success team and is preparing a full technical breakdown with further analysis of Windows, macOS, and iOS versions of the malware.

A few years back, another Reddit user reported receiving a Ledger Nano X in an authentic-looking package, but a letter inside raised concerns due to spelling and grammar errors. The letter claimed it was a replacement after a data breach.

A security expert later found the device had a flash drive wired to the USB connector, which was intended for malware delivery and potential theft.

The post Fake Ledger Wallet Exposed With Hidden Chip Stealing Seed Phrases and PINs appeared first on CryptoPotato.

Bitcoin coin symbol
Btc
Bitcoin
$77.157
price
red chart
decrease symbol0.32467%
price change
TRADE NOW

Article Source: cryptopotato.com

Previous

Rep. Sheri Biggs Discloses $250,000 Bitcoin ETF Buy Amid Reserve Bill Push

Next

Benjamin Cowen Reveals Why The Altcoin Season Never Came

Written by

crypto news

Crypto News

@cryptonews

11029 posts

Read the latest Crypto news on Bitcoin, Altcoins, Blockchain, Web3 and Market updates. Stay informed with Crypto Adventure our daily news.

VIEW AUTHOR

Publish your own article

Guest post article. Guaranteed publishing with just a few clicks

START PUBLISHING ADVERTISE WITH US

Browse categories

Explore trending topics in the crypto community right now.

Bitcoin

Osmosis Pauses Alloyed BTC After Nomic Double-Spend Exploit

Osmosis has suspended deposits, withdrawals, minting and redemptions for Alloyed BTC after a vulnerability on Nomic allowed an attacker to double-spend nBTC and send unbacked vouchers into Osmosis. The Nomic security failure affected 39.84 nBTC held inside Alloyed BTC, representing roughly 36% of the asset’s backing. Osmosis and the Inter-Blockchain Communication protocol were not compromised, with the vulnerability isolated to Nomic’s custom forwarding mechanism. Emergency Upgrade Freezes 22.65 BTC Osmosis’ management subDAO halted Nomic and Alloyed BTC inflows and outflows...

Iran Turns to Bitcoin and USDT for Trade as U.S. Sanctions Tighten

Iranian businesses are increasingly using Bitcoin and Tether’s USDT to settle cross-border trade as the country loosens foreign-exchange controls and seeks alternative payment routes outside the global banking system. The Central Bank of Iran has quietly allowed exporters to receive cryptocurrency payments and settle transactions through domestic crypto exchanges, according to Iranian businesses, regime insiders and industry participants interviewed by the Financial Times. The central bank has not publicly formalized the change and declined to comment on the policy. Exporters...

Mexican Musician Jonathan Meléndez Killed in Suspected Bitcoin Cold-Wallet Robbery

Mexican musician Jonathan Meléndez, his pregnant wife, their three-year-old daughter and a household worker were killed in an alleged robbery targeting a cold wallet that the attackers believed contained millions of dollars in Bitcoin. Estado de México prosecutors arrested Diego Sebastián “N” and Gerardo “N” over the September 1 killings in Atizapán de Zaragoza. Meléndez’s six-year-old son survived the attack, while the family’s dog was also killed. Suspects Allegedly Searched for Bitcoin Cold Wallet Investigators allege that Diego Sebastián had...

Strategy Buys Back $176M STRC as Strive Adds 1,375 BTC

Strategy made no Bitcoin purchases or sales between August 31 and September 7, leaving its treasury at 845,050 BTC acquired for $63.73 billion at an average cost of $75,412 per coin. The pause came immediately after Strategy returned to Bitcoin buying with a 4,603 BTC acquisition during the previous week. Capital instead moved into Strategy's preferred securities. The company repurchased 1,810,885 STRC shares for $176.3 million, with the entire amount funded from USD Cash rather than Bitcoin sales or new...

MORE ARTICLES

Ethereum

Ledger Patches Ethereum Signing Flaw Before Researchers Disclose It

Ledger has patched a vulnerability in its Ethereum hardware-wallet app that could allow a malicious dApp to replace a transaction during the approval process while the device continued showing users the transaction they originally reviewed. Security firm TestMachine disclosed the signature-substitution flaw on August 21 after reproducing it on Ledger hardware. Ledger had already shipped Ethereum app version 1.22.2 on August 12, with its release history listing security fixes for the update. Malicious dApp Could Change the Transaction Before Signing...

Jesse Pollak Pushes Back On Coinbase ETH Selling Criticism, Points To 150K ETH Treasury

Base creator Jesse Pollak has pushed back against criticism that Coinbase is selling ETH while benefiting from Ethereum, pointing to the exchange’s roughly 150,000 ETH corporate position and years of investment across the network. Pollak argued that Coinbase has held about 150,000 ETH through multiple market cycles, while describing the company as the largest ETH holder outside dedicated digital asset treasury companies by a wide margin. Coinbase’s latest regulatory filing backs up the scale of that position. The company held...

Tornado Cash Phishing Frontend Drains 1,010 ETH From User

A crypto user lost 1,010 ETH after following an old Tornado Cash bookmark into a phishing frontend that captured the private withdrawal credentials needed to access the deposited funds. The victim deposited the ETH into legitimate Tornado Cash contracts, but the malicious interface obtained the private note generated during the process. The attacker then used those credentials to withdraw the assets within roughly 12 hours without compromising the underlying Tornado Cash smart contracts. Phishing Frontend Targeted Private Withdrawal Notes Tornado...

Ethereum New Address Growth Jumps 75% As Network Activity Accelerates

Ethereum’s network-growth metric has accelerated sharply in August, with new daily ETH addresses climbing from 121,210 on August 8 to 212,560 on August 16. The increase represents roughly 75.4% growth in eight days and adds another signal that activity is returning to the network. New-address creation measures the number of addresses appearing onchain for the first time rather than the number of unique people using Ethereum. A single user or automated system can control multiple addresses, so the metric is...

MORE ARTICLES

Trading

5 Best Crypto APIs for Trading Bots in 2026

A crypto trading bot is a chain of dependencies. It reads a position, prices it, decides, places an order, and confirms settlement. Every one of those steps is an API call, and a failure at any single step stops the strategy. The provider choice shapes what a bot can actually do more than the strategy logic does. The common mistake is searching for one API that covers everything. No such API exists in 2026. Market data providers do not route...

Best Prediction Markets Alternatives: Outpoll, Limitless, Myriad, Manifold

Polymarket and Kalshi helped turn prediction markets into a mainstream trading category, but neither platform fits every trader. Access varies by country, market selection can lean heavily toward certain topics, and the tools available for entering, managing, and automating positions differ sharply across platforms. The strongest alternatives are not identical copies. Some emerging prediction markets platforms focus on professional order controls, some concentrate on fast crypto and financial markets, and others use onchain infrastructure or play-money forecasting. Users unfamiliar with...

How to Get a Funded Crypto Trading Account in 2026 Step by Step

A funded crypto trading account gives a trader access to more notional capital after they prove they can follow a firm’s risk rules. The usual route starts with a paid crypto prop firm challenge that requires a profit target without breaching daily or overall loss limits. Passing is not only about making money. Drawdown control, minimum trading days and rule compliance determine whether the account survives. The evaluation fee can be lost, and crypto prop firms use different account models,...

How To Trade Tokenized Stock Perps: Leverage, Funding And Risks

Tokenized stock perps allow traders to take long or short exposure to companies, ETFs and equity indexes through crypto-native derivatives markets. Positions can use stablecoin collateral, remain open without an expiry date and continue trading when the main stock exchange is closed. The trader receives price exposure, not ownership of the referenced shares. The interface often looks identical to a crypto perpetual futures market. The risk does not. A stock-linked contract can remain active overnight, through weekends and during holidays...

MORE ARTICLES

Tech

Nasdaq Invests $100M in Kraken Parent Payward at $21B Valuation

Nasdaq is investing $100 million in Payward, the parent company of Kraken, in a transaction valuing the private financial infrastructure company at $21 billion. The investment is being made through Nasdaq's venture arm and deepens a partnership already centered on moving regulated equities onto blockchain-based settlement infrastructure. The $21 billion valuation places Payward above the $20 billion equity value used in several transactions earlier this year and comes as Kraken continues preparations for a potential public listing. The exchange confidentially...

Circle Agrees to Buy Tazapay for $400M to Expand Global USDC Payments

Circle has agreed to acquire Singapore-based payments infrastructure company Tazapay for $400 million, bringing a business processing more than $25 billion in annualized payments into the USDC issuer’s global settlement network. The $400 million transaction will be paid in Circle Class A common stock, with the final share count based on Circle’s volume-weighted average closing price during the 20 trading days preceding completion. Adjustments will account for Tazapay debt, transaction expenses and cash. Tazapay Brings $25B in Payment Volume Tazapay...

Orionx Shuts Down After $7M Crypto Custody Shortfall

Chilean cryptocurrency exchange Orionx has begun permanently closing its operations after a forensic audit identified more than $7 million in custodial assets that had moved to wallets outside the company’s control. Withdrawals are temporarily suspended while Orionx reconciles customer balances and implements a five-stage closure and asset-restitution process. Full repayment is not guaranteed, with available assets expected to be distributed under equal and proportional treatment rather than allowing earlier withdrawals to receive priority. Bitcoin Accounts for Most of the Confirmed...

Trezor ShipMonk Breach Expands to 67,000 More U.S. Customers

Trezor has expanded the scope of its ShipMonk data breach after discovering that personal information belonging to approximately 67,000 additional U.S. customers was exposed from orders dating back as far as 2019. The newly identified customers ordered Trezor devices between November 2019 and August 2021. Exposed records include names, email addresses, phone numbers, shipping addresses and order numbers, substantially widening an incident initially believed to be limited largely to recent purchases. ShipMonk Retained Data Trezor Expected Deleted The discovery conflicts...

MORE ARTICLES