Scammers mail out fake hardware wallets to victims of Ledger data breach

Scammers mail out fake hardware wallets to victims of Ledger data breach

The consequences of Ledger’s major data breach continue to be felt almost a year later. One contributor to the r/Ledgerwallet forum on Reddit, writing under the tag u/jjrand and self-identified as one of those affected by the breach, has posted images of what appears to be a fake Ledger Nano X wallet received in the mail.

Wrapped in seemingly authentic packaging, the device nonetheless included several tell-tale signs that sparked the contributor’s suspicion. Most jarringly, the package came together with a poorly written letter claiming to be signed by Ledger CEO Pascal Gauthier, telling its recipient:

Our top trading bots

“For security purposes we have sent you a new device you must switch to a new device to stay safe. There is a manual inside your new box you can read that to learn how to set up your new device. For this reason, we have changed our device structure. We now guarantee that this kinda breach will never happen again.”
Scammers mail out fake hardware wallets to victims of Ledger data breach
Box containing allegedly fraudulent Ledger device, received by reddit user u/jjrand. Source: Reddit
Scammers mail out fake hardware wallets to victims of Ledger data breach
Scam letter purportedly written and signed by Ledger CEO Pascal Gauthier. Source: Reddit

Aside from the letter, u/jjrand also received a fake manual, enclosing instructions regarding how to use the device and, crucially, asking that the user enter their private Ledger recovery phrase to connect their cryptocurrency wallet to the new hardware. On the basis of further images showing the device’s circuit board uploaded to Reddit, security researcher Mike Grover told BleepingComputer that the fake device was tampered with:

“This seems to be a simply flash drive strapped on to the Ledger with the purpose to be for some sort of malware delivery. All of the components are on the other side, so I can’t confirm if it is JUST a storage device, but [...] judging by the very novice soldering work, it’s probably just an off the shelf mini flash drive removed from its casing.”

Grover highlighted a section of the back of the device, showing the flash drive implant and noting that “those 4 wires piggyback the same connections for the USB port of the Ledger.” 

Scammers mail out fake hardware wallets to victims of Ledger data breach
Back of fake Ledger device. Source: Reddit, with highlight added by Mike Grover 
Scammers mail out fake hardware wallets to victims of Ledger data breach
Back of authentic Ledger device. Source: BleepingComputer

On the basis of Grover and BleepingComputer's analysis, it appears that the heist is designed to intercept the user’s entered recovery phrase in order to reroute the details to a device controlled by the scammers, which they can then use to steal the associated cryptocurrency holdings.

Related: Ledger data leak: A ‘simple mistake’ exposed 270K crypto wallet buyers

In an online post dated May 10 but not cited by u/jjrand, Ledger had already warned customers against the fake letter and device, stating that:

“The fake user guide in the Nano’s box asks the user to connect the device to a computer. To initialize the device, the user is then asked to enter his 24 words in a fake Ledger Live application. This is a scam. Do not connect the device to your computer and never share your 24 words. Ledger will never ask you to share your 24-word recovery phrase.”

While the warning is included as part of Ledger’s online list of phishing campaigns of which the company is aware, it is unclear whether the company has reached out to users directly, especially those whose leaked details may leave them more susceptible to falling for the ruse.

Cointelegraph has reached out to Ledger for comment and will update this article with further information regarding this issue.

As previously reported, other consequences of the data leak have included Ledger users receiving emails from extortionists threatening physical violence or other criminal attacks. The original data breach had occurred in June and July 2020 and included 1,075,382 email addresses from users subscribed to the Ledger newsletter. It notably also involved the leak of personal information (including home addresses) associated with 272,853 hardware wallet orders. 

Continue reading at Cointelegraph
Terra price gains 75% in February as $2.57B in LUNA tokens removed from supply
Terra (LUNA) emerged as one of the best performing financial assets in February, a month mired by geopolitical conflicts and their negative impacts on the...
Former Cisco employee launches DAO to buy Denver Broncos
A new decentralized autonomous organization (DAO) has been formed to raise money in an effort to purchase the Denver Broncos U.S. National Football League...
Binance.US is under investigation from SEC over trading affiliates: Report
The U.S. Securities and Exchange Commission (SEC) has reportedly launched a probe into major crypto exchange Binance's U.S. arm regarding trading firms...
Bitcoin price down 20% so far in 2022 after worst January since 2018
Bitcoin (BTC) is heading for its worst January performance in four years — could all not be what it seems?Data from on-chain analytics resource Coinglass shows January...
Does a Fed digital dollar leave any room for crypto stablecoins?
During Jerome Powell’s Jan. 11 United States Senate confirmation hearings, Sen. Patrick Toomey posed a question to the incumbent-and-future Federal Reserve...
Second largest US mortgage lender UWM dumps Bitcoin payment plans
United Wholesale Mortgage (UWM), one of the largest wholesale and purchase lenders in the United States, is ditching Bitcoin (BTC) payment plans after running...
New research claims 21 accounts pumped the $4.4B EOS ICO with wash trades
New research has shed more light on the crypto industry’s largest-ever token sale, alleging that foul play may have been afoot during EOS’s initial coin...
Cause and effect: Will the Bitcoin price drop if the stock market crashes?
The year 2009 was marked by both the genesis of Bitcoin and the United States stock market starting an unprecedented bull market — one that’s continued...
Berkshire Hathaway invests $500M in Brazilian digital bank
Brazilian digital bank Nubank has raised $500 million from Berkshire Hathaway, a multinational holding company run by billionaire Warren Buffett.In an announcement...
Bitcoin tackles $40,000 as Biden unveils new $6 trillion federal spending budget
Bitcoin (BTC) may get a boost to finally clear $40,000 at the expense of the U.S. dollar as United States President Joe Biden's new $6 trillion federal...
Tether mints more coins to break $60 billion market cap
Tether (USDT), the world’s largest stablecoin by market capitalization, continues to grow despite record-breaking cryptocurrency outflows triggered by Elon...
Art reimagined: NFTs are changing the collectibles market
Art has been serving as the ultimate source of inspiration to many people throughout all of history. In the era of cryptocurrencies and the digitized world,...
Akon to Launch AKoin and Establish a Crypto-City in Senegal
The world of showbiz is persistently trying to invade the world of cryptocurrencies. Celebrities keep prying into the industry, e.g., rapper Snoop Dogg...
Facebook, Instagram Ban Ads on Bitcoin and ICOs As ‘Deceptive Practices’
Around a month ago Facebook CEO and co-founder Mark Zuckerberg promised to look into crypto technologies, as well as to work on the errors that the company...
ICO Benebit Team Disappeared With $2.7 million
The organizers of the ICO project Benebit disappeared with at least $2.7 million of investors' funds. According to other sources, the amount of money raised...