Security researchers discover counterfeit Ledger hardware wallets sold on Chinese e-commerce platforms

robot
Abstract generation in progress
ME News: On April 17 (UTC+8), a Brazilian security researcher warned that the Ledger Nano S Plus device purchased on a Chinese e-commerce platform is a carefully crafted counterfeit intended to steal users’ crypto assets. The device is priced the same as in the official store; its packaging and product page appear legitimate, but after connecting to the official Ledger Live app it fails to pass the “authenticity verification.” Disassembly found that the device’s hardware and firmware have been tampered with; WiFi and Bluetooth antennas are embedded inside, and the chip markings have been scraped off. After analyzing the firmware, the researcher found that when the device starts up, it displays the manufacturer as the Shanghai-listed company Espressif Technology. The researcher advises users to download Ledger Live only from ledger.com and to purchase hardware only from ledger.com. If the device does not pass authenticity verification, it should be stopped immediately. Earlier this month, more than 50 victims lost a total of $9.5 million after fake Ledger Live apps listed on the Apple App Store leaked seed phrases. (Source: PANews)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 11
  • 8
  • Share
Comment
Add a comment
Add a comment
WalletEarlyAccessAlarm
· 9h ago
Buying a hardware wallet from domestic e-commerce sites, my heart is truly big.
View OriginalReply0
CancelingOrdersIsLikeBreathing
· 11h ago
Can this fake firmware fool Live's verification? It's terrifying to think about.
View OriginalReply0
GateUser-4590f4c6
· 14h ago
Only when taking it apart do you realize that ordinary people simply can't tell.
View OriginalReply0
GateUser-0fdb3438
· 14h ago
Fake Live streams on the App Store can all be listed; what is Apple review doing?
View OriginalReply0
StainedGlassSolarArray
· 14h ago
Third-party sellers on e-commerce platforms really can't be trusted
View OriginalReply0
MoonlightDisconnectSwitch
· 14h ago
Researcher, this breakdown is really helpful; otherwise, more people would get caught.
View OriginalReply0
StrollingOnTheEdgeOfTheDao
· 14h ago
Enter the mnemonic phrase, and the wallet resets to zero, a classic script.
View OriginalReply0
GovernanceGremlin
· 14h ago
From now on, buying a Ledger requires weighing it first; counterfeit products might have a few extra grams of antenna.
View OriginalReply0
PuppyLooksAtTvl
· 14h ago
9.5 million dollars to learn a lesson, hardware wallets must be bought from the official website
View OriginalReply0
GateUser-78b4adc8
· 14h ago
Lexin Technology gets dragged into the mess; they shouldn't be blamed for this.
View OriginalReply0
View More
  • Pinned