Inside a Fake Ledger: How a 4G Modem is Secretly Embedded in a Hardware Wallet

cryptonews.ru2026-08-09 tarihinde yayınlandı2026-08-09 tarihinde güncellendi

Özet

In a presentation at Hardwear.io 2026, hardware security expert Joe Grand detailed a sophisticated spy chip discovered inside counterfeit Ledger Nano X hardware wallets. Initially reported in 2021, these tampered devices reached victims through data leaked from Ledger in 2020 and subsequent phishing campaigns. The implanted board connects to the internal SPI bus, passively intercepting data between the Secure Element and the OLED display. Using pattern recognition, it "reads" the seed phrase words displayed during wallet setup or recovery, stores them in its flash memory, and then exfiltrates the data via a built-in 4G modem and eSIM, independent of the victim's computer. To fit the extra hardware, the attackers reduced the battery size and replaced a thermal sensor with a fixed resistor to fake a 100% charge reading. Grand noted this is not an isolated incident, with similar supply-chain attacks previously targeting Trezor devices where compromised firmware generated predictable seed phrases. The researcher plans to intercept and decrypt the chip's cellular traffic to learn more about the attackers. Ledger advises users to purchase devices directly from the manufacturer or authorized resellers, not third-party marketplaces, and to compare devices against official photos. The company is also considering enhanced physical security for future products. The article questions whether Ledger Live's Secure Element authentication would detect such a passive hardware implant and h...

Hardware security specialist Joe Grand, known by the alias Kingpin, presented a full breakdown of a spy chip found inside a counterfeit Ledger Nano X at the Hardwear.io 2026 conference in Santa Clara. The device originally surfaced in 2021 — Reddit users complained of receiving wallets with foreign electronics inside, and the devices themselves reached victims through the Ledger 2020 data breach and subsequent phishing campaigns.

How the Implant Reads the Seed Phrase

According to Grand, the implanted board connects to the internal SPI bus, which the Nano X's Secure Element uses to transmit data to the device's OLED screen. The implant intercepts this traffic and, using a built-in pattern recognition mechanism, matches the transmitted data with letter images — thus "reading" the words the owner sees on the screen during wallet generation or recovery. The extracted seed phrase is saved in the chip's flash memory and then transmitted to the outside world — not via Wi-Fi or Bluetooth, but over a fourth-generation cellular network, for which the implant contains its own modem and eSIM.

To fit the additional electronics inside the case, the attackers reduced the battery size and replaced the standard thermistor with a fixed resistor — this allows the charge indicator to always show 100%, masking the tampering with the design.

Not the First Case with Hardware Wallets

Grand reminded that such supply chain attacks have affected not only Ledger. Previously, a similar scheme was identified with Trezor One and Trezor Model T — in these devices, the original locked microcontroller was replaced with an unlocked version containing malicious firmware that generated not random, but pre-determined seed phrases known to the attackers. Counterfeit devices were sold through Russian marketplaces.

  • Compromise occurs at the sales stage — the buyer receives a physically altered device instead of the genuine one

  • Externally, such wallets are almost indistinguishable from real ones — only minor assembly details reveal the counterfeit

  • Data is stolen not via the USB interface or application, but through a hidden communication channel independent of the victim's computer

The researcher noted that new modifications of the implant have already been detected — meaning the attackers continue to refine the scheme. As a next step, Grand plans to intercept and decrypt the cellular traffic exchanged by the chip to learn more about who is behind the attack and how successful it has been.

What Ledger Recommends

The company recommends that owners compare the device's appearance with reference photos and buy wallets only directly from the manufacturer or authorized resellers, not through marketplaces and intermediaries. Ledger also stated they are considering additional physical protection measures for future products.

The question remains open as to whether the infected device passed the standard Secure Element authenticity check when connected to the Ledger Live application — this point is not covered in Grand's presentation. Judging by the described attack mechanics, the implant passively intercepts data on the SPI bus between the secure element and the screen, without interfering with the chip itself, so the verification could have proceeded independently of the spy module's operation.

The story of the implant in the Nano X shows that the risk affects not the software part of the wallet, but the physical supply chain itself — from the factory to the buyer's mailbox. Even a correctly working application and a genuine screen do not guarantee the absence of foreign electronics inside the case.

Ledger hardware wallets are freely sold on Russian marketplaces.

AI Opinion

From the perspective of machine data analysis, the story of the implant in the Ledger Nano X is just one facet of the broader issue of trust in hardware wallets. The vulnerability here affected the physical channel for transmitting the seed phrase via the SPI bus, but a similar effect in terms of consequences is also caused by a firmware-level defect: in the Coldcard wallet, a five-year-old bug in the random number generator led to predictable keys and losses amounting to hundreds of millions of dollars. The situation demonstrates that the protection of the seed phrase relies not on a single link — the chip manufacturer, supply channel, or firmware code — but on the entire chain simultaneously.

A technical aspect that remains outside the article's field of view is the independent verification of the Secure Element's integrity when connecting to the Ledger Live application. How reliable is such a mechanism against a passive interceptor that does not interfere with the chip's own operation?

end-content

Trend Kriptolar

İlgili Sorular

QWhat was the key finding presented by Joe Grand regarding a counterfeit Ledger Nano X?

AJoe Grand presented a detailed breakdown of a spy chip found inside a counterfeit Ledger Nano X. The implanted device connects to the internal SPI bus to intercept the seed phrase as it is displayed on the OLED screen, stores it, and then transmits it via a built-in 4G modem and eSIM.

QHow does the implanted spy chip in the fake Ledger Nano X extract the seed phrase?

AThe chip connects to the SPI bus between the Secure Element and the OLED screen. It intercepts this data traffic and uses a built-in pattern recognition mechanism to match the transmitted data with character images, effectively 'reading' the words shown on the screen during wallet generation or recovery.

QWhat modifications did the attackers make to the hardware to fit the implant?

ATo fit the additional electronics, the attackers reduced the size of the battery and replaced the standard thermistor with a fixed resistor. This causes the battery charge indicator to always show 100%, masking the physical tampering.

QWhat is the primary recommended way to avoid receiving a compromised hardware wallet according to Ledger?

ALedger recommends purchasing wallets only directly from the manufacturer or authorized resellers, not through marketplaces or intermediaries. Users should also check the device's physical appearance against reference photos.

QAccording to the article's 'AI Opinion,' what broader issue does the Ledger implant case highlight?

AThe case highlights the broader problem of trust in hardware wallets, where security depends on the entire chain—the chip manufacturer, the supply channel, and the firmware code—simultaneously, not just on one single link like software or a specific component.

İlgili Okumalar

Google and Meta Called Out for Benchmark Gaming

Recently, analysis firm SemiAnalysis accused tech giants Google and Meta of "benchmark gaming" with their AI models Gemini 3.8 Flash and Muse Spark 1.3. The accusation stems from a dramatic performance drop between two versions of the Terminal-Bench evaluation for AI agents. On the older, public Terminal-Bench 2.1, Gemini 3.8 Flash scored 89.4, ranking second and beating GPT-6 Astra, while Muse Spark 1.3 scored 88.8. However, on the newly released, more secure Terminal-Bench 4.0, their scores plummeted to 19.1 and approximately 33.3 respectively, far behind competitors. SemiAnalysis argues this indicates "benchmark contamination," where companies train models not on the public test questions themselves, but on expensive, privately purchased training data specifically designed to mimic the benchmark's style. This has evolved into a lucrative industry, with specialized firms selling tailored training tasks for thousands to hundreds of thousands of dollars. The article specifically points to Datacurve, a company that both sells expert coding data and runs its own benchmark (DeepSWE), where the accused models also performed well. Meta's Chief AI Officer, Alexandr Wang, dismissed the claims as a "silly argument," pointing out similar performance drops for other models like GPT-5.6 Sol. He stated Meta never claimed Muse Spark 1.3 was as powerful as top-tier models, only that it offered better value. The report concludes that this is the inevitable fate of all high-quality public benchmarks—they become "gamed" over time. The proposed solution of private, high-quality benchmarks comes with a significant downside: it would erode public transparency, turning open rankings into marketing tools and leaving developers without a common, fair measure to compare AI models.

marsbit2 saat önce

Google and Meta Called Out for Benchmark Gaming

marsbit2 saat önce

Crypto's Nouveau Riche Strikes Gold in the Real World: Coinbase Co-founder's Venezuelan Oil Field Adventure

Coinbase co-founder Fred Ehrsam is venturing into the oil fields of Venezuela, a surprising shift for a prominent figure in the digital asset space. Through his company Primavera Infinita, he recently secured a production contract for the Budare-Elotes block with Venezuela's state oil firm PDVSA. This move into a politically volatile, sanction-scarred country highlights a bet on high returns from its reopening under new leadership and shifting U.S. foreign policy. Ehrsam’s investment reflects a venture capital-style appetite for risk, targeting assets deeply discounted by political uncertainty. He is not alone; smaller, politically connected U.S. firms like Aspect Holdings and Hunt Oil are also entering, while established giants like ExxonMobil remain cautious due to past expropriations. To manage the complex, capital-intensive nature of oil, Ehrsam is assembling a professional team. This trend extends beyond Ehrsam. Other crypto wealth, like BitMEX's Arthur Hayes and Tether, is diversifying into traditional hard assets—energy, metals, and agriculture—seeking physical scarcity as a long-term anchor. Tether, for instance, took a controlling stake in agricultural giant Adecoagro. These moves signify crypto capital's evolving interest: not just tokenizing real-world assets (RWA), but directly acquiring and operating them. Ultimately, Ehrsam's gamble is less on oil geology and more on the duration of Venezuela's current political window. It underscores a broader narrative where digital-era wealth seeks stability and scale in the physical world's most traditional, immovable resources.

marsbit2 saat önce

Crypto's Nouveau Riche Strikes Gold in the Real World: Coinbase Co-founder's Venezuelan Oil Field Adventure

marsbit2 saat önce

Refuting the Ethereum 'Abandoning' ETH Narrative: What Does It Really Mean to Pay Gas Without ETH?

Title: Refuting the "Ethereum Abandoning ETH" Argument: What Does Paying Gas Without ETH Really Mean? The debate sparked by Vitalik Buterin's discussion of EIP-8141 (Frame Transactions), which suggests users could pay transaction fees without holding ETH, has led to extreme claims that ETH will lose its value. However, this perspective misunderstands the proposal. Currently, an Ethereum user initiating a transaction must also pay the network's Gas fee in ETH. EIP-8141 aims to decouple these actions. It allows a transaction to be split into separate "frames." A user could sign a transaction to, for example, send USDC, while a separate Paymaster account pays the required ETH Gas fee on their behalf. The user would then settle the cost with the Paymaster using USDC or another token. From the user's perspective, they pay in a stablecoin without interacting with ETH. Crucially, from the Ethereum protocol's perspective, the Gas is still paid in ETH; only the settlement layer between the user and Paymaster changes. This concept isn't entirely new; ERC-4337's Account Abstraction already allows similar Gas sponsorship. EIP-8141 seeks to integrate this capability more natively. The core goal is to drastically improve user experience by abstracting away the complexity of Gas, similar to how one pays with a credit card abroad without handling the local currency. It also enables atomic operations, like bundling token approval with a swap, which would revert together if the swap fails. Regarding ETH's value, the argument that "no ETH is needed" is incorrect. While users may not hold ETH, Paymasters and services must still acquire and spend ETH to pay network fees on the backend. The demand for ETH shifts from being distributed across millions of user wallets to being concentrated in the balances of these service providers. The key variable is whether this improved usability attracts significant new users and increases overall network activity. If it does, total ETH burned in fees could rise substantially. If it doesn't, the change merely reshuffles who holds the ETH needed for Gas. In summary, EIP-8141 aims to lower the entry barrier by hiding Gas complexity, betting that this will drive broader adoption and increase the fundamental utility—and thus demand—for the Ethereum network and ETH itself.

marsbit2 saat önce

Refuting the Ethereum 'Abandoning' ETH Narrative: What Does It Really Mean to Pay Gas Without ETH?

marsbit2 saat önce

İşlemler

Spot

Popüler Makaleler

JOE Nasıl Satın Alınır

HTX.com’a hoş geldiniz! TraderJoe (JOE) satın alma işlemlerini basit ve kullanışlı bir hâle getirdik. Adım adım açıkladığımız rehberimizi takip ederek kripto yolculuğunuza başlayın. 1. Adım: HTX Hesabınızı OluşturunHTX'te ücretsiz bir hesap açmak için e-posta adresinizi veya telefon numaranızı kullanın. Sorunsuzca kaydolun ve tüm özelliklerin kilidini açın. Hesabımı Aç2. Adım: Kripto Satın Al Bölümüne Gidin ve Ödeme Yönteminizi SeçinKredi/Banka Kartı: Visa veya Mastercard'ınızı kullanarak anında TraderJoe (JOE) satın alın.Bakiye: Sorunsuz bir şekilde işlem yapmak için HTX hesap bakiyenizdeki fonları kullanın.Üçüncü Taraflar: Kullanımı kolaylaştırmak için Google Pay ve Apple Pay gibi popüler ödeme yöntemlerini ekledik.P2P: HTX'teki diğer kullanıcılarla doğrudan işlem yapın.Borsa Dışı (OTC): Yatırımcılar için kişiye özel hizmetler ve rekabetçi döviz kurları sunuyoruz.3. Adım: TraderJoe (JOE) Varlıklarınızı SaklayınTraderJoe (JOE) satın aldıktan sonra HTX hesabınızda saklayın. Alternatif olarak, blok zinciri transferi yoluyla başka bir yere gönderebilir veya diğer kripto para birimlerini takas etmek için kullanabilirsiniz.4. Adım: TraderJoe (JOE) Varlıklarınızla İşlem YapınHTX'in spot piyasasında TraderJoe (JOE) ile kolayca işlemler yapın.Hesabınıza erişin, işlem çiftinizi seçin, işlemlerinizi gerçekleştirin ve gerçek zamanlı olarak izleyin. Hem yeni başlayanlar hem de deneyimli yatırımcılar için kullanıcı dostu bir deneyim sunuyoruz.

469 Toplam GörüntülenmeYayınlanma 2024.12.11Güncellenme 2026.06.02

JOE Nasıl Satın Alınır

Tartışmalar

HTX Topluluğuna hoş geldiniz. Burada, en son platform gelişmeleri hakkında bilgi sahibi olabilir ve profesyonel piyasa görüşlerine erişebilirsiniz. Kullanıcıların JOE (JOE) fiyatı hakkındaki görüşleri aşağıda sunulmaktadır.

活动图片