Fake Ledger Hardware Wallets on Chinese Marketplaces Steal Crypto Seeds and PINs
ID: 2be4c05c-d619-5b6e-bd9a-ccd6405188f0
STIX ID: report--2be4c05c-d619-5b6e-bd9a-ccd6405188f0
Feed Name: cybersecurityNews.com
A researcher exposed a large-scale supply-chain scam involving counterfeit Ledger Nano S Plus devices that replaced the secure element with an ESP32-S3 microcontroller, recorded seed phrases and PINs in plaintext, and transmitted them to attacker-controlled C2 servers (including domain kkkhhhnnn.com). The scheme included a cloned/phishing site and a trojanized Ledger Live app (with a falsified Genuine Check) and deployed cross-platform malware (Android, Windows, macOS, and iOS via TestFlight) to simultaneously drain wallets across ~20 blockchains, with confirmed financial losses exceeding $9.5M; users are advised to purchase only from ledger.com or authorized resellers, download Ledger Live exclusively from ledger.com, run the Genuine Check on first use, and report suspicious devices to Ledger security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
