Users of Ledger cryptocurrency wallets have reported unauthorized draining of their accounts, prompting the company to suspect a coordinated tampering scheme involving reseller CryptoBillis and malicious hardware components. In response, Ledger has instructed CryptoBillis to immediately pause all sales while an investigation is underway.
Evidence shared on social media platforms X and Threads includes images and video footage revealing small circuit boards hidden beneath the screens of affected devices. The implant is designed to intercept information displayed on the screen, specifically targeting the seed passphrase generated during the initial setup process.
According to reports, the device utilizes an embedded SIM card to transmit the stolen data back to the attacker, who can subsequently siphon funds from the user’s account.
My seed phrase was logged by this implant before I even noticed my wallet was empty. Never again direct-to-consumer hardware.
Suspend sales is the right call, but I doubt that stops determined attackers from modifying devices themselves.
An eSIM for data exfiltration? That’s almost clever in a purely evil way. Tech criminals are getting too smart.
I bought mine from a different reseller. Should I be worried, or was this strictly a CryptoBillis issue?
This is absolutely terrifying. How do we even verify if a device is safe anymore?