Inside a Fake Ledger: How a 4G Modem is Secretly Embedded in a Hardware Wallet

cryptonews.ruPublished on 2026-08-09Last updated on 2026-08-09

Abstract

In a presentation at Hardwear.io 2026, hardware security expert Joe Grand detailed a sophisticated spy chip discovered inside counterfeit Ledger Nano X hardware wallets. Initially reported in 2021, these tampered devices reached victims through data leaked from Ledger in 2020 and subsequent phishing campaigns. The implanted board connects to the internal SPI bus, passively intercepting data between the Secure Element and the OLED display. Using pattern recognition, it "reads" the seed phrase words displayed during wallet setup or recovery, stores them in its flash memory, and then exfiltrates the data via a built-in 4G modem and eSIM, independent of the victim's computer. To fit the extra hardware, the attackers reduced the battery size and replaced a thermal sensor with a fixed resistor to fake a 100% charge reading. Grand noted this is not an isolated incident, with similar supply-chain attacks previously targeting Trezor devices where compromised firmware generated predictable seed phrases. The researcher plans to intercept and decrypt the chip's cellular traffic to learn more about the attackers. Ledger advises users to purchase devices directly from the manufacturer or authorized resellers, not third-party marketplaces, and to compare devices against official photos. The company is also considering enhanced physical security for future products. The article questions whether Ledger Live's Secure Element authentication would detect such a passive hardware implant and h...

Hardware security specialist Joe Grand, known by the alias Kingpin, presented a full breakdown of a spy chip found inside a counterfeit Ledger Nano X at the Hardwear.io 2026 conference in Santa Clara. The device originally surfaced in 2021 — Reddit users complained of receiving wallets with foreign electronics inside, and the devices themselves reached victims through the Ledger 2020 data breach and subsequent phishing campaigns.

How the Implant Reads the Seed Phrase

According to Grand, the implanted board connects to the internal SPI bus, which the Nano X's Secure Element uses to transmit data to the device's OLED screen. The implant intercepts this traffic and, using a built-in pattern recognition mechanism, matches the transmitted data with letter images — thus "reading" the words the owner sees on the screen during wallet generation or recovery. The extracted seed phrase is saved in the chip's flash memory and then transmitted to the outside world — not via Wi-Fi or Bluetooth, but over a fourth-generation cellular network, for which the implant contains its own modem and eSIM.

To fit the additional electronics inside the case, the attackers reduced the battery size and replaced the standard thermistor with a fixed resistor — this allows the charge indicator to always show 100%, masking the tampering with the design.

Not the First Case with Hardware Wallets

Grand reminded that such supply chain attacks have affected not only Ledger. Previously, a similar scheme was identified with Trezor One and Trezor Model T — in these devices, the original locked microcontroller was replaced with an unlocked version containing malicious firmware that generated not random, but pre-determined seed phrases known to the attackers. Counterfeit devices were sold through Russian marketplaces.

  • Compromise occurs at the sales stage — the buyer receives a physically altered device instead of the genuine one

  • Externally, such wallets are almost indistinguishable from real ones — only minor assembly details reveal the counterfeit

  • Data is stolen not via the USB interface or application, but through a hidden communication channel independent of the victim's computer

The researcher noted that new modifications of the implant have already been detected — meaning the attackers continue to refine the scheme. As a next step, Grand plans to intercept and decrypt the cellular traffic exchanged by the chip to learn more about who is behind the attack and how successful it has been.

What Ledger Recommends

The company recommends that owners compare the device's appearance with reference photos and buy wallets only directly from the manufacturer or authorized resellers, not through marketplaces and intermediaries. Ledger also stated they are considering additional physical protection measures for future products.

The question remains open as to whether the infected device passed the standard Secure Element authenticity check when connected to the Ledger Live application — this point is not covered in Grand's presentation. Judging by the described attack mechanics, the implant passively intercepts data on the SPI bus between the secure element and the screen, without interfering with the chip itself, so the verification could have proceeded independently of the spy module's operation.

The story of the implant in the Nano X shows that the risk affects not the software part of the wallet, but the physical supply chain itself — from the factory to the buyer's mailbox. Even a correctly working application and a genuine screen do not guarantee the absence of foreign electronics inside the case.

Ledger hardware wallets are freely sold on Russian marketplaces.

AI Opinion

From the perspective of machine data analysis, the story of the implant in the Ledger Nano X is just one facet of the broader issue of trust in hardware wallets. The vulnerability here affected the physical channel for transmitting the seed phrase via the SPI bus, but a similar effect in terms of consequences is also caused by a firmware-level defect: in the Coldcard wallet, a five-year-old bug in the random number generator led to predictable keys and losses amounting to hundreds of millions of dollars. The situation demonstrates that the protection of the seed phrase relies not on a single link — the chip manufacturer, supply channel, or firmware code — but on the entire chain simultaneously.

A technical aspect that remains outside the article's field of view is the independent verification of the Secure Element's integrity when connecting to the Ledger Live application. How reliable is such a mechanism against a passive interceptor that does not interfere with the chip's own operation?

end-content

Trending Cryptos

Related Questions

QWhat was the key finding presented by Joe Grand regarding a counterfeit Ledger Nano X?

AJoe Grand presented a detailed breakdown of a spy chip found inside a counterfeit Ledger Nano X. The implanted device connects to the internal SPI bus to intercept the seed phrase as it is displayed on the OLED screen, stores it, and then transmits it via a built-in 4G modem and eSIM.

QHow does the implanted spy chip in the fake Ledger Nano X extract the seed phrase?

AThe chip connects to the SPI bus between the Secure Element and the OLED screen. It intercepts this data traffic and uses a built-in pattern recognition mechanism to match the transmitted data with character images, effectively 'reading' the words shown on the screen during wallet generation or recovery.

QWhat modifications did the attackers make to the hardware to fit the implant?

ATo fit the additional electronics, the attackers reduced the size of the battery and replaced the standard thermistor with a fixed resistor. This causes the battery charge indicator to always show 100%, masking the physical tampering.

QWhat is the primary recommended way to avoid receiving a compromised hardware wallet according to Ledger?

ALedger recommends purchasing wallets only directly from the manufacturer or authorized resellers, not through marketplaces or intermediaries. Users should also check the device's physical appearance against reference photos.

QAccording to the article's 'AI Opinion,' what broader issue does the Ledger implant case highlight?

AThe case highlights the broader problem of trust in hardware wallets, where security depends on the entire chain—the chip manufacturer, the supply channel, and the firmware code—simultaneously, not just on one single link like software or a specific component.

Related Reads

AI Creates New Virus, Science Paper Confirms, Capable of Unlimited Self-Replication

AI Designs Novel, Self-Replicating Viruses in Groundbreaking Science Study A landmark study published in Science by researchers from Stanford University and the Arc Institute demonstrates that an AI model, Evo, has successfully designed novel, functional viruses from scratch. Trained on trillions of nucleotides across diverse life forms, Evo generated 700,000 candidate viral genomes. From these, 285 were synthesized as DNA and tested in E. coli bacteria. Remarkably, 16 of these AI-designed viruses were not only viable and self-replicating but some also outperformed their natural counterpart, the bacteriophage ΦX174, in the speed of bacterial lysis. One variant, Evo-Φ36, even incorporated a structural protein from a distantly related virus, showcasing the AI's ability to combine functional elements in novel ways. This research marks the first time a complete, functional life-form genome has been designed de novo by artificial intelligence. It represents a pivotal shift into the era of generative genomic design. A key application demonstrated is in combating antibiotic-resistant bacteria. While naturally occurring bacteriophages often fail against resistant strains, a cocktail of AI-generated phages successfully killed three different resistant E. coli variants. The study suggests AI could revolutionize fields like phage therapy by rapidly generating new antimicrobial agents, potentially keeping pace with bacterial evolution in a way traditional drug development cannot. This work signifies a profound step in humanity's ability to read and now write the code of life.

marsbit22m ago

AI Creates New Virus, Science Paper Confirms, Capable of Unlimited Self-Replication

marsbit22m ago

Trading

Spot

Hot Articles

How to Buy JOE

Welcome to HTX.com! We've made purchasing TraderJoe (JOE) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy TraderJoe (JOE) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your TraderJoe (JOE)After purchasing your TraderJoe (JOE), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade TraderJoe (JOE)Easily trade TraderJoe (JOE) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

3.2k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy JOE

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of JOE (JOE) are presented below.

活动图片