Inside a Fake Ledger: How a 4G Modem is Secretly Embedded in a Hardware Wallet

cryptonews.ruPublished on 2026-08-09Last updated on 2026-08-09

Abstract

In a presentation at Hardwear.io 2026, hardware security expert Joe Grand detailed a sophisticated spy chip discovered inside counterfeit Ledger Nano X hardware wallets. Initially reported in 2021, these tampered devices reached victims through data leaked from Ledger in 2020 and subsequent phishing campaigns. The implanted board connects to the internal SPI bus, passively intercepting data between the Secure Element and the OLED display. Using pattern recognition, it "reads" the seed phrase words displayed during wallet setup or recovery, stores them in its flash memory, and then exfiltrates the data via a built-in 4G modem and eSIM, independent of the victim's computer. To fit the extra hardware, the attackers reduced the battery size and replaced a thermal sensor with a fixed resistor to fake a 100% charge reading. Grand noted this is not an isolated incident, with similar supply-chain attacks previously targeting Trezor devices where compromised firmware generated predictable seed phrases. The researcher plans to intercept and decrypt the chip's cellular traffic to learn more about the attackers. Ledger advises users to purchase devices directly from the manufacturer or authorized resellers, not third-party marketplaces, and to compare devices against official photos. The company is also considering enhanced physical security for future products. The article questions whether Ledger Live's Secure Element authentication would detect such a passive hardware implant and h...

Hardware security specialist Joe Grand, known by the alias Kingpin, presented a full breakdown of a spy chip found inside a counterfeit Ledger Nano X at the Hardwear.io 2026 conference in Santa Clara. The device originally surfaced in 2021 — Reddit users complained of receiving wallets with foreign electronics inside, and the devices themselves reached victims through the Ledger 2020 data breach and subsequent phishing campaigns.

How the Implant Reads the Seed Phrase

According to Grand, the implanted board connects to the internal SPI bus, which the Nano X's Secure Element uses to transmit data to the device's OLED screen. The implant intercepts this traffic and, using a built-in pattern recognition mechanism, matches the transmitted data with letter images — thus "reading" the words the owner sees on the screen during wallet generation or recovery. The extracted seed phrase is saved in the chip's flash memory and then transmitted to the outside world — not via Wi-Fi or Bluetooth, but over a fourth-generation cellular network, for which the implant contains its own modem and eSIM.

To fit the additional electronics inside the case, the attackers reduced the battery size and replaced the standard thermistor with a fixed resistor — this allows the charge indicator to always show 100%, masking the tampering with the design.

Not the First Case with Hardware Wallets

Grand reminded that such supply chain attacks have affected not only Ledger. Previously, a similar scheme was identified with Trezor One and Trezor Model T — in these devices, the original locked microcontroller was replaced with an unlocked version containing malicious firmware that generated not random, but pre-determined seed phrases known to the attackers. Counterfeit devices were sold through Russian marketplaces.

  • Compromise occurs at the sales stage — the buyer receives a physically altered device instead of the genuine one

  • Externally, such wallets are almost indistinguishable from real ones — only minor assembly details reveal the counterfeit

  • Data is stolen not via the USB interface or application, but through a hidden communication channel independent of the victim's computer

The researcher noted that new modifications of the implant have already been detected — meaning the attackers continue to refine the scheme. As a next step, Grand plans to intercept and decrypt the cellular traffic exchanged by the chip to learn more about who is behind the attack and how successful it has been.

What Ledger Recommends

The company recommends that owners compare the device's appearance with reference photos and buy wallets only directly from the manufacturer or authorized resellers, not through marketplaces and intermediaries. Ledger also stated they are considering additional physical protection measures for future products.

The question remains open as to whether the infected device passed the standard Secure Element authenticity check when connected to the Ledger Live application — this point is not covered in Grand's presentation. Judging by the described attack mechanics, the implant passively intercepts data on the SPI bus between the secure element and the screen, without interfering with the chip itself, so the verification could have proceeded independently of the spy module's operation.

The story of the implant in the Nano X shows that the risk affects not the software part of the wallet, but the physical supply chain itself — from the factory to the buyer's mailbox. Even a correctly working application and a genuine screen do not guarantee the absence of foreign electronics inside the case.

Ledger hardware wallets are freely sold on Russian marketplaces.

AI Opinion

From the perspective of machine data analysis, the story of the implant in the Ledger Nano X is just one facet of the broader issue of trust in hardware wallets. The vulnerability here affected the physical channel for transmitting the seed phrase via the SPI bus, but a similar effect in terms of consequences is also caused by a firmware-level defect: in the Coldcard wallet, a five-year-old bug in the random number generator led to predictable keys and losses amounting to hundreds of millions of dollars. The situation demonstrates that the protection of the seed phrase relies not on a single link — the chip manufacturer, supply channel, or firmware code — but on the entire chain simultaneously.

A technical aspect that remains outside the article's field of view is the independent verification of the Secure Element's integrity when connecting to the Ledger Live application. How reliable is such a mechanism against a passive interceptor that does not interfere with the chip's own operation?

end-content

Trending Cryptos

Related Questions

QWhat was the key finding presented by Joe Grand regarding a counterfeit Ledger Nano X?

AJoe Grand presented a detailed breakdown of a spy chip found inside a counterfeit Ledger Nano X. The implanted device connects to the internal SPI bus to intercept the seed phrase as it is displayed on the OLED screen, stores it, and then transmits it via a built-in 4G modem and eSIM.

QHow does the implanted spy chip in the fake Ledger Nano X extract the seed phrase?

AThe chip connects to the SPI bus between the Secure Element and the OLED screen. It intercepts this data traffic and uses a built-in pattern recognition mechanism to match the transmitted data with character images, effectively 'reading' the words shown on the screen during wallet generation or recovery.

QWhat modifications did the attackers make to the hardware to fit the implant?

ATo fit the additional electronics, the attackers reduced the size of the battery and replaced the standard thermistor with a fixed resistor. This causes the battery charge indicator to always show 100%, masking the physical tampering.

QWhat is the primary recommended way to avoid receiving a compromised hardware wallet according to Ledger?

ALedger recommends purchasing wallets only directly from the manufacturer or authorized resellers, not through marketplaces or intermediaries. Users should also check the device's physical appearance against reference photos.

QAccording to the article's 'AI Opinion,' what broader issue does the Ledger implant case highlight?

AThe case highlights the broader problem of trust in hardware wallets, where security depends on the entire chain—the chip manufacturer, the supply channel, and the firmware code—simultaneously, not just on one single link like software or a specific component.

Related Reads

FBI Agent Steals from Within: Millions in Cryptocurrency Stolen by Memorizing Recovery Phrases

A criminal complaint filed in the U.S. District Court for the Eastern District of Virginia details the case of Patrick Steven Yaroch, a former FBI supervisory special agent. Yaroch is accused of using his position to steal nearly $1 million in cryptocurrency from accounts associated with a "foreign adversary" (reportedly Russia) that were under FBI monitoring. He allegedly accessed the accounts' seed phrases from an FBI system, memorized them, and transferred the funds to personal wallets over 10-12 transactions in late 2024 or early 2025. Some stolen assets were held on the Kraken exchange and others were deposited into the Suilend DeFi protocol to earn yield. Despite his senior GS-14 position and high security clearance, Yaroch claimed his actions stemmed from frustration with the FBI's perceived inaction against the monitored accounts. However, evidence from his phone, including ChatGPT conversations from May and June 2026, revealed plans to move to Europe (specifically Portugal) with $1 million and retire early. He booked flights for his family and initiated steps for Portuguese residency. Tormented by guilt, Yaroch voluntarily confessed to the Justice Department and FBI in late July 2026, surrendering the seed phrase and a hardware wallet. He was immediately fired and arrested. He faces charges of interstate transportation of stolen property and receipt of stolen goods. The case highlights vulnerabilities within law enforcement, including excessive access to sensitive data like seed phrases, inadequate internal oversight, and the difficulty of detecting such insider theft on-chain. It echoes past corruption cases, such as those involving agents Carl Force and Shaun Bridges during the Silk Road investigation, where officials misappropriated Bitcoin. The incident underscores that human fallibility remains a critical risk in managing digital assets, even within heavily monitored agencies.

marsbit57m ago

FBI Agent Steals from Within: Millions in Cryptocurrency Stolen by Memorizing Recovery Phrases

marsbit57m ago

Trading

Spot

Hot Articles

How to Buy JOE

Welcome to HTX.com! We've made purchasing TraderJoe (JOE) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy TraderJoe (JOE) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your TraderJoe (JOE)After purchasing your TraderJoe (JOE), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade TraderJoe (JOE)Easily trade TraderJoe (JOE) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

3.1k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy JOE

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of JOE (JOE) are presented below.

活动图片