Security researchers discover counterfeit Ledger hardware wallets sold on Chinese e-commerce platforms

ME News Report, April 17 (UTC+8), a Brazilian security researcher warned that the Ledger Nano S Plus device purchased on a Chinese e-commerce platform is a carefully crafted counterfeit designed to steal users' crypto assets. The device is priced the same as in the official store, with packaging and product pages appearing legitimate, but it fails to pass "authenticity verification" when connected to the official Ledger Live app. Disassembly revealed that the hardware and firmware of the device have been tampered with, and it contains WiFi and Bluetooth antennas internally, with chip markings scraped off. After analyzing the firmware, the researcher found that upon startup, the device displays the manufacturer as Lexin Technology, a Shanghai-listed company. The researcher advises users to only download Ledger Live from ledger.com and purchase hardware only from ledger.com. If the device does not pass authenticity verification, it should be stopped immediately. Earlier this month, over 50 victims lost a total of $9.5 million after fake Ledger Live apps were listed on the Apple App Store, which leaked seed phrases. (Source: PANews)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • 12
  • Share
Comment
Add a comment
Add a comment
LighthouseInTheMist
· 21h ago
It's terrifying to think about; if it hadn't been dismantled, how many people could this thing have fooled?
View OriginalReply0
PopFruitCollage
· 21h ago
Ledger's official verification process saved a life, but many people probably won't bother to verify it at all.
View OriginalReply0
GateUser-423f10e3
· 21h ago
Opening the chip label and scraping it off—this move is way too skillful, the supply chain is terrifyingly mature.
View OriginalReply0
Mirror-FinishTeacupWith
· 21h ago
Counterfeiting the same style and price is possible; ordinary users simply can't defend against it.
View OriginalReply0
ReviewMonsterDoesn'tSleep
· 21h ago
From now on, only buy hardware wallets from the official website; even if third-party platforms are cheaper, I won't dare to touch them.
View OriginalReply0
TheSkyInsideTheMirroredSphere
· 21h ago
Lexin Technology got caught in the crossfire; even after the chip was scraped, it can still be recognized. The researchers are indeed professional.
View OriginalReply0
GateUser-3f3455c7
· 21h ago
This is just too outrageous; WiFi and Bluetooth are both included, turning the hardware wallet into a hardware backdoor.
View OriginalReply0
  • Pinned