How a spyware implant in Ledger cold wallets work
• Attackers opens a real Ledger and solders a second board onto the wires between the secure chip and the screen
• Original secure chip stays untouched (important: so the device can still pass Ledger's authenticity check)
• The hidden malicious board has three parts: an eSIM, a small CPU, and an LTE modem
• During setup, your 24-word seed is shown on the OLED screen
• The extra CPU watches that screen signal, reads each 24 word as they appear and stores the full phrase
• The LTE module and eSIM then send the seed out over mobile data to the attacker (does not need to be plugged in)
Source
Post #25117
674
Ahboyash Reads A user investigates potential hardware issues, hackers are allegedly putting spy implants in affected Ledger devices If you bought hardware wallets from 3rd party resellers, please don’t do that again and throw it away Source
- 👍 6