Security researchers discover counterfeit Ledger hardware wallets sold on Chinese e-commerce platforms

robot
Abstract generation in progress
ME News Report, April 17 (UTC+8), a Brazilian security researcher warned that the Ledger Nano S Plus device purchased on a Chinese e-commerce platform is a carefully crafted counterfeit designed to steal users' crypto assets. The device is priced the same as in the official store, with packaging and product pages appearing legitimate, but it fails to pass "authenticity verification" when connected to the official Ledger Live app. Disassembly revealed that the hardware and firmware of the device have been tampered with, and it contains WiFi and Bluetooth antennas internally, with chip markings scraped off. After analyzing the firmware, the researcher found that upon startup, the device displays the manufacturer as Lexin Technology, a Shanghai-listed company. The researcher advises users to only download Ledger Live from ledger.com and purchase hardware only from ledger.com. If the device does not pass authenticity verification, it should be discontinued immediately. Earlier this month, over 50 victims lost a total of $9.5 million after fake Ledger Live apps were listed on the Apple App Store, which leaked seed phrases. (Source: PANews)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 11
  • 6
  • Share
Comment
Add a comment
Add a comment
BorrowedHalo
· 10h ago
Fake firmware + fake app combo, unstoppable defenses
View OriginalReply0
GasFeeAnxiety
· 12h ago
Brazilian researcher bought it on Chinese e-commerce, cross-border rights protection has become more difficult
View OriginalReply0
GateUser-f4fbd803
· 12h ago
Authentic product verification must be done; don't find it troublesome.
View OriginalReply0
HexiHoodie
· 12h ago
Is Espressif Systems getting caught in the crossfire? Or is there an insider?
View OriginalReply0
InstantNoodle-LevelResearcher
· 12h ago
The chip markings have all been scraped off. Probably a professional counterfeiting team.
View OriginalReply0
ProofOfCoffee
· 12h ago
From now on, purchasing a hardware wallet requires full video recording of the unboxing and verification.
View OriginalReply0
LonelyStoneUnderTheAurora
· 12h ago
Disassembled the device and found the WiFi antenna—are they trying to remotely steal private keys?
View OriginalReply0
SlowerThanBlock
· 12h ago
Fake Ledger Live apps on the App Store surprisingly managed to get listed, what is Apple review doing?
View OriginalReply0
RetroRadio
· 12h ago
9.5 million USD, I feel for those guys.
View OriginalReply0
MintCondition
· 12h ago
Buy from official channels! Don't be greedy for cheap prices.
View OriginalReply0
View More
  • Pinned