Inside a Fake Ledger: How a 4G Modem is Secretly Embedded in a Hardware Wallet

cryptonews.ruPublicado a 2026-08-09Actualizado a 2026-08-09

Resumen

In a presentation at Hardwear.io 2026, hardware security expert Joe Grand detailed a sophisticated spy chip discovered inside counterfeit Ledger Nano X hardware wallets. Initially reported in 2021, these tampered devices reached victims through data leaked from Ledger in 2020 and subsequent phishing campaigns. The implanted board connects to the internal SPI bus, passively intercepting data between the Secure Element and the OLED display. Using pattern recognition, it "reads" the seed phrase words displayed during wallet setup or recovery, stores them in its flash memory, and then exfiltrates the data via a built-in 4G modem and eSIM, independent of the victim's computer. To fit the extra hardware, the attackers reduced the battery size and replaced a thermal sensor with a fixed resistor to fake a 100% charge reading. Grand noted this is not an isolated incident, with similar supply-chain attacks previously targeting Trezor devices where compromised firmware generated predictable seed phrases. The researcher plans to intercept and decrypt the chip's cellular traffic to learn more about the attackers. Ledger advises users to purchase devices directly from the manufacturer or authorized resellers, not third-party marketplaces, and to compare devices against official photos. The company is also considering enhanced physical security for future products. The article questions whether Ledger Live's Secure Element authentication would detect such a passive hardware implant and h...

Hardware security specialist Joe Grand, known by the alias Kingpin, presented a full breakdown of a spy chip found inside a counterfeit Ledger Nano X at the Hardwear.io 2026 conference in Santa Clara. The device originally surfaced in 2021 — Reddit users complained of receiving wallets with foreign electronics inside, and the devices themselves reached victims through the Ledger 2020 data breach and subsequent phishing campaigns.

How the Implant Reads the Seed Phrase

According to Grand, the implanted board connects to the internal SPI bus, which the Nano X's Secure Element uses to transmit data to the device's OLED screen. The implant intercepts this traffic and, using a built-in pattern recognition mechanism, matches the transmitted data with letter images — thus "reading" the words the owner sees on the screen during wallet generation or recovery. The extracted seed phrase is saved in the chip's flash memory and then transmitted to the outside world — not via Wi-Fi or Bluetooth, but over a fourth-generation cellular network, for which the implant contains its own modem and eSIM.

To fit the additional electronics inside the case, the attackers reduced the battery size and replaced the standard thermistor with a fixed resistor — this allows the charge indicator to always show 100%, masking the tampering with the design.

Not the First Case with Hardware Wallets

Grand reminded that such supply chain attacks have affected not only Ledger. Previously, a similar scheme was identified with Trezor One and Trezor Model T — in these devices, the original locked microcontroller was replaced with an unlocked version containing malicious firmware that generated not random, but pre-determined seed phrases known to the attackers. Counterfeit devices were sold through Russian marketplaces.

  • Compromise occurs at the sales stage — the buyer receives a physically altered device instead of the genuine one

  • Externally, such wallets are almost indistinguishable from real ones — only minor assembly details reveal the counterfeit

  • Data is stolen not via the USB interface or application, but through a hidden communication channel independent of the victim's computer

The researcher noted that new modifications of the implant have already been detected — meaning the attackers continue to refine the scheme. As a next step, Grand plans to intercept and decrypt the cellular traffic exchanged by the chip to learn more about who is behind the attack and how successful it has been.

What Ledger Recommends

The company recommends that owners compare the device's appearance with reference photos and buy wallets only directly from the manufacturer or authorized resellers, not through marketplaces and intermediaries. Ledger also stated they are considering additional physical protection measures for future products.

The question remains open as to whether the infected device passed the standard Secure Element authenticity check when connected to the Ledger Live application — this point is not covered in Grand's presentation. Judging by the described attack mechanics, the implant passively intercepts data on the SPI bus between the secure element and the screen, without interfering with the chip itself, so the verification could have proceeded independently of the spy module's operation.

The story of the implant in the Nano X shows that the risk affects not the software part of the wallet, but the physical supply chain itself — from the factory to the buyer's mailbox. Even a correctly working application and a genuine screen do not guarantee the absence of foreign electronics inside the case.

Ledger hardware wallets are freely sold on Russian marketplaces.

AI Opinion

From the perspective of machine data analysis, the story of the implant in the Ledger Nano X is just one facet of the broader issue of trust in hardware wallets. The vulnerability here affected the physical channel for transmitting the seed phrase via the SPI bus, but a similar effect in terms of consequences is also caused by a firmware-level defect: in the Coldcard wallet, a five-year-old bug in the random number generator led to predictable keys and losses amounting to hundreds of millions of dollars. The situation demonstrates that the protection of the seed phrase relies not on a single link — the chip manufacturer, supply channel, or firmware code — but on the entire chain simultaneously.

A technical aspect that remains outside the article's field of view is the independent verification of the Secure Element's integrity when connecting to the Ledger Live application. How reliable is such a mechanism against a passive interceptor that does not interfere with the chip's own operation?

end-content

Criptos en tendencia

Preguntas relacionadas

QWhat was the key finding presented by Joe Grand regarding a counterfeit Ledger Nano X?

AJoe Grand presented a detailed breakdown of a spy chip found inside a counterfeit Ledger Nano X. The implanted device connects to the internal SPI bus to intercept the seed phrase as it is displayed on the OLED screen, stores it, and then transmits it via a built-in 4G modem and eSIM.

QHow does the implanted spy chip in the fake Ledger Nano X extract the seed phrase?

AThe chip connects to the SPI bus between the Secure Element and the OLED screen. It intercepts this data traffic and uses a built-in pattern recognition mechanism to match the transmitted data with character images, effectively 'reading' the words shown on the screen during wallet generation or recovery.

QWhat modifications did the attackers make to the hardware to fit the implant?

ATo fit the additional electronics, the attackers reduced the size of the battery and replaced the standard thermistor with a fixed resistor. This causes the battery charge indicator to always show 100%, masking the physical tampering.

QWhat is the primary recommended way to avoid receiving a compromised hardware wallet according to Ledger?

ALedger recommends purchasing wallets only directly from the manufacturer or authorized resellers, not through marketplaces or intermediaries. Users should also check the device's physical appearance against reference photos.

QAccording to the article's 'AI Opinion,' what broader issue does the Ledger implant case highlight?

AThe case highlights the broader problem of trust in hardware wallets, where security depends on the entire chain—the chip manufacturer, the supply channel, and the firmware code—simultaneously, not just on one single link like software or a specific component.

Lecturas Relacionadas

FBI Agent Steals from Within: Millions in Cryptocurrency Stolen by Memorizing Recovery Phrases

A criminal complaint filed in the U.S. District Court for the Eastern District of Virginia details the case of Patrick Steven Yaroch, a former FBI supervisory special agent. Yaroch is accused of using his position to steal nearly $1 million in cryptocurrency from accounts associated with a "foreign adversary" (reportedly Russia) that were under FBI monitoring. He allegedly accessed the accounts' seed phrases from an FBI system, memorized them, and transferred the funds to personal wallets over 10-12 transactions in late 2024 or early 2025. Some stolen assets were held on the Kraken exchange and others were deposited into the Suilend DeFi protocol to earn yield. Despite his senior GS-14 position and high security clearance, Yaroch claimed his actions stemmed from frustration with the FBI's perceived inaction against the monitored accounts. However, evidence from his phone, including ChatGPT conversations from May and June 2026, revealed plans to move to Europe (specifically Portugal) with $1 million and retire early. He booked flights for his family and initiated steps for Portuguese residency. Tormented by guilt, Yaroch voluntarily confessed to the Justice Department and FBI in late July 2026, surrendering the seed phrase and a hardware wallet. He was immediately fired and arrested. He faces charges of interstate transportation of stolen property and receipt of stolen goods. The case highlights vulnerabilities within law enforcement, including excessive access to sensitive data like seed phrases, inadequate internal oversight, and the difficulty of detecting such insider theft on-chain. It echoes past corruption cases, such as those involving agents Carl Force and Shaun Bridges during the Silk Road investigation, where officials misappropriated Bitcoin. The incident underscores that human fallibility remains a critical risk in managing digital assets, even within heavily monitored agencies.

marsbitHace 57 min(s)

FBI Agent Steals from Within: Millions in Cryptocurrency Stolen by Memorizing Recovery Phrases

marsbitHace 57 min(s)

Trading

Spot

Artículos destacados

Cómo comprar JOE

¡Bienvenido a HTX.com! Hemos hecho que comprar TraderJoe (JOE) sea simple y conveniente. Sigue nuestra guía paso a paso para iniciar tu viaje de criptos.Paso 1: crea tu cuenta HTXUtiliza tu correo electrónico o número de teléfono para registrarte y obtener una cuenta gratuita en HTX. Experimenta un proceso de registro sin complicaciones y desbloquea todas las funciones.Obtener mi cuentaPaso 2: ve a Comprar cripto y elige tu método de pagoTarjeta de crédito/débito: usa tu Visa o Mastercard para comprar TraderJoe (JOE) al instante.Saldo: utiliza fondos del saldo de tu cuenta HTX para tradear sin problemas.Terceros: hemos agregado métodos de pago populares como Google Pay y Apple Pay para mejorar la comodidad.P2P: tradear directamente con otros usuarios en HTX.Over-the-Counter (OTC): ofrecemos servicios personalizados y tipos de cambio competitivos para los traders.Paso 3: guarda tu TraderJoe (JOE)Después de comprar tu TraderJoe (JOE), guárdalo en tu cuenta HTX. Alternativamente, puedes enviarlo a otro lugar mediante transferencia blockchain o utilizarlo para tradear otras criptomonedas.Paso 4: tradear TraderJoe (JOE)Tradear fácilmente con TraderJoe (JOE) en HTX's mercado spot. Simplemente accede a tu cuenta, selecciona tu par de trading, ejecuta tus trades y monitorea en tiempo real. Ofrecemos una experiencia fácil de usar tanto para principiantes como para traders experimentados.

118 Vistas totalesPublicado en 2024.12.11Actualizado en 2026.06.02

Cómo comprar JOE

Discusiones

Bienvenido a la comunidad de HTX. Aquí puedes mantenerte informado sobre los últimos desarrollos de la plataforma y acceder a análisis profesionales del mercado. A continuación se presentan las opiniones de los usuarios sobre el precio de JOE (JOE).

活动图片