{"id":44504,"date":"2021-06-17T12:39:50","date_gmt":"2021-06-17T09:39:50","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=44504"},"modified":"2025-08-31T17:14:58","modified_gmt":"2025-08-31T14:14:58","slug":"fraudsters-distribute-hacked-ledger-devices-to-steal-cryptocurrency","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/fraudsters-distribute-hacked-ledger-devices-to-steal-cryptocurrency\/","title":{"rendered":"Fraudsters distribute hacked Ledger devices to steal cryptocurrency"},"content":{"rendered":"<p>Ledger hardware-wallet users received by mail new devices that purportedly would protect them from the consequences of the breach that occurred in the summer of 2020. In reality, the &#8216;wallets&#8217; have been modified by hackers and are designed to steal cryptocurrency. This was <a href=\"https:\/\/www.reddit.com\/r\/ledgerwallet\/comments\/o154gz\/package_from_ledger_is_this_legit\/\" target=\"_blank\" rel=\"noopener\">reported<\/a> by a member of the Ledger community on Reddit under the username jjrand.<\/p>\n<p>The device is packaged in convincingly authentic packaging and outwardly resembles a Ledger Nano X. A letter full of grammatical and spelling errors accompanies the package. In it, unknown individuals on behalf of the company stated that the &#8216;wallet&#8217; has been sent as a replacement for the existing one and is intended to safeguard customers&#8217; security.<\/p>\n<div id=\"attachment_139271\" style=\"width: 1562px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-139271\" class=\"size-full wp-image-139271\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/packaging-letter.jpeg\" width=\"1552\" height=\"992\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/packaging-letter.jpeg 1552w, https:\/\/forklog.com\/wp-content\/uploads\/packaging-letter-300x192.jpeg 300w, https:\/\/forklog.com\/wp-content\/uploads\/packaging-letter-1024x655.jpeg 1024w, https:\/\/forklog.com\/wp-content\/uploads\/packaging-letter-768x491.jpeg 768w, https:\/\/forklog.com\/wp-content\/uploads\/packaging-letter-1536x982.jpeg 1536w\" sizes=\"auto, (max-width: 1552px) 100vw, 1552px\" \/><\/p>\n<p id=\"caption-attachment-139271\" class=\"wp-caption-text\">Source: Reddit.<\/p>\n<\/div>\n<blockquote>\n<p>&#8220;We have redesigned the structure of our device. We now guarantee that such a breach will never happen again. You must switch to the new device,&#8221; the letter states.<\/p>\n<\/blockquote>\n<p>Users compared the printed circuit boards of the original and the device received in the package. In the photos, their differences are visually evident:<\/p>\n<div id=\"attachment_139270\" style=\"width: 897px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-139270\" class=\"size-full wp-image-139270\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/fake-ledger-front-pcb.jpeg\" width=\"887\" height=\"308\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/fake-ledger-front-pcb.jpeg 887w, https:\/\/forklog.com\/wp-content\/uploads\/fake-ledger-front-pcb-300x104.jpeg 300w, https:\/\/forklog.com\/wp-content\/uploads\/fake-ledger-front-pcb-768x267.jpeg 768w\" sizes=\"auto, (max-width: 887px) 100vw, 887px\" \/><\/p>\n<p id=\"caption-attachment-139270\" class=\"wp-caption-text\">Front view of fake Ledger hardware wallet. Source: Reddit.<\/p>\n<\/div>\n<div id=\"attachment_139269\" style=\"width: 1290px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-139269\" class=\"wp-image-139269 size-full\" style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/real-ledger-front-pcb.jpeg\" width=\"1280\" height=\"397\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/real-ledger-front-pcb.jpeg 1280w, https:\/\/forklog.com\/wp-content\/uploads\/real-ledger-front-pcb-300x93.jpeg 300w, https:\/\/forklog.com\/wp-content\/uploads\/real-ledger-front-pcb-1024x318.jpeg 1024w, https:\/\/forklog.com\/wp-content\/uploads\/real-ledger-front-pcb-768x238.jpeg 768w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p id=\"caption-attachment-139269\" class=\"wp-caption-text\">Original Ledger hardware wallet front view. Source: Ledger.<\/p>\n<\/div>\n<p>Security researcher Mike Grover, after reviewing the photos, concluded that the attackers had added USB flash-drive components to the device.<\/p>\n<blockquote>\n<p>&#8220;It looks like it&#8217;s just a flash drive attached to a Ledger, intended to deliver some malware. All components are on the other side, so I can&#8217;t confirm that the device functions only as a memory. But judging by the soldering, it&#8217;s probably just a mini flash drive without a case,&#8221; he said.<\/p>\n<\/blockquote>\n<p>Grover added that the flash-drive implant has four wires connected to the Ledger&#8217;s USB-port-like pads.<\/p>\n<div id=\"attachment_139264\" style=\"width: 880px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-139264\" class=\"size-full wp-image-139264\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/back-pcb.jpeg\" width=\"870\" height=\"310\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/back-pcb.jpeg 870w, https:\/\/forklog.com\/wp-content\/uploads\/back-pcb-300x107.jpeg 300w, https:\/\/forklog.com\/wp-content\/uploads\/back-pcb-768x274.jpeg 768w\" sizes=\"auto, (max-width: 870px) 100vw, 870px\" \/><\/p>\n<p id=\"caption-attachment-139264\" class=\"wp-caption-text\">Back view of fake Ledger hardware wallet. Source: Reddit.<\/p>\n<\/div>\n<div id=\"attachment_139268\" style=\"width: 1290px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-139268\" class=\"size-full wp-image-139268\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/real-ledge-back-pcb-1.jpeg\" width=\"1280\" height=\"465\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/real-ledge-back-pcb-1.jpeg 1280w, https:\/\/forklog.com\/wp-content\/uploads\/real-ledge-back-pcb-1-300x109.jpeg 300w, https:\/\/forklog.com\/wp-content\/uploads\/real-ledge-back-pcb-1-1024x372.jpeg 1024w, https:\/\/forklog.com\/wp-content\/uploads\/real-ledge-back-pcb-1-768x279.jpeg 768w\" sizes=\"auto, (max-width: 1280px) 100vw, 1280px\" \/><\/p>\n<p id=\"caption-attachment-139268\" class=\"wp-caption-text\">Original Ledger hardware wallet back view. Source: Ledger.<\/p>\n<\/div>\n<p>The device comes with a setup guide. The user is asked to connect the \u201cLedger\u201d to their computer and run the accompanying app. After that, the program prompts for a recovery phrase to supposedly import the wallet onto the new device.<\/p>\n<p>If the user enters this information, the attackers will be able to access their wallet and steal the cryptocurrency stored on it.<\/p>\n<p>Representatives from Ledger said they were aware of this scam and in May <a href=\"https:\/\/www.ledger.com\/phishing-campaigns-status#phishing-campaigns\" target=\"_blank\" rel=\"noopener\">they had already warned users about it<\/a>.<\/p>\n<p>The company once again urged customers to use software only from the official Ledger.com site and not to share the recovery phrase with anyone.<\/p>\n<p>As reported, <a href=\"https:\/\/forklog.com\/en\/news\/ledger-reports-data-breach-affecting-around-one-million-users\">the data leak of one million Ledger users<\/a> occurred on June 25, 2020. An unknown party gained access to users&#8217; email addresses, names, and phone numbers.<\/p>\n<p>At the end of October, a user under the nickname Polaris posted the database on the hacker forum exploit.in. A user named hyperdrill bought it for 5 BTC.<\/p>\n<p>On December 21, these <a href=\"https:\/\/forklog.com\/en\/news\/ledger-data-leak-exposes-details-of-a-million-hardware-wallet-users\">data were publicly available<\/a> via the RaidForums forum, where anyone could download them.<\/p>\n<p>In early 2021, Ledger Nano wallet owners began receiving <a href=\"https:\/\/forklog.com\/en\/news\/hackers-launch-mass-phishing-campaign-impersonating-exodus-echoing-ledger\">threats from unknown individuals demanding a ransom of 0.3 BTC or 10 ETH<\/a>. The letters contained the victim&#8217;s full name and home address, as well as threats of physical harm if the terms were not met within 24 hours.<\/p>\n<p>The Ledger developers <a href=\"https:\/\/forklog.com\/en\/news\/ledger-to-pay-10-btc-for-information-leading-to-arrests-of-cybercriminals-behind-a-string-of-attacks-and-data-breaches\">announced a reward of 10 BTC<\/a> for help in locating cybercriminals.<\/p>\n<p>In April, the Roche Freedman law firm filed a class-action lawsuit in a San Francisco court against Ledger and Shopify. <a href=\"https:\/\/forklog.com\/en\/news\/ledger-and-shopify-hit-by-class-action-over-data-breach\">They valued the losses from the leak at over $5 million<\/a>.<\/p>\n<p>Subscribe to ForkLog news on Telegram: <a href=\"https:\/\/t.me\/forklogfeed\" target=\"_blank\" rel=\"nofollow noopener\">ForkLog Feed<\/a> \u2014 the full news stream, <a href=\"https:\/\/telegram.me\/forklog\" target=\"_blank\" rel=\"nofollow noopener\">ForkLog<\/a> \u2014 the most important news, infographics and opinions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ledger hardware-wallet users received by mail new devices that purportedly would protect them from the consequences of the breach that occurred in the summer of 2020. In reality, the &#8216;wallets&#8217; have been modified by hackers and are designed to steal cryptocurrency.<\/p>\n","protected":false},"author":1,"featured_media":44505,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,961,1640],"class_list":["post-44504","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-hardware-wallets","tag-ledger"],"aioseo_notices":[],"amp_enabled":true,"views":"57","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/44504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=44504"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/44504\/revisions"}],"predecessor-version":[{"id":44506,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/44504\/revisions\/44506"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/44505"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=44504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=44504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=44504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}