Some news on this old subject:
https://sites.google.com/view/loupiote2-crypto-recovery/home/ledger-hw-1-with-lost-security-card-and-lost-seed-successful-btc-recovery- Short version / TL;DR:
Client has BTC secured by an old Ledger HW.1 hardware wallet, but lost their Security Card and their seed phrase. They still have their unlocking PIN.
The Ledger HW.1 hardware wallet, released in 2014 in the early days of the Ledger Company, is a screenless USB dongle supporting only BTC. Its Security Card feature provides an additional challenge-response layer of protection, preventing unauthorized transactions when the dongle is connected and unlocked.
Without the Security Card or recovery seed phrase, BTC secured by the HW.1 was considered irrecoverable.
However, in 2022, Ledger revealed a firmware vulnerability allowing reassignment of a new Security Card through brute-forcing responses to challenges:
https://donjon.ledger.com/lsb/017/Note: This vulnerability applies only to older screenless Ledger devices (HW.1, Nano). Modern devices (Nano S, X, S+ etc.) are unaffected.
Using this vulnerability, we successfully exploited the HW.1’s firmware to brute-force responses and reassign a new Security Card in our test HW.1 dongle.
This technique will allow recovery of our Client's BTC.