I originally posted about this in
My Interview with Famous Hardware Hacker Joe Grand aka Kingpin.Yesterday, m2017 wrote that the Hardware Wallet board should probably have been the section to share this post. So I am just going to quote my post from earlier because it makes sense to mention it here as well.
It's a very interesting video. When you have 45 mins or so, I recommend that you take a look.
Reverse Engineering a Ledger Nano X Hardware ImplantA crypto user from Thailand had a Ledger Nano X hardware wallet, but the internal battery wasn't working properly. He decided to buy another Nano X, the cheapest one he could find, in order to take its battery and replace the one in his device. He bought one from Lazada. Lazada is an official Ledger reseller for Thailand, but it turns out that the service had (maybe it still has) fake listings as well.
When he got his device, he opened it, noticed that the battery was smaller, and that the circuitry and wires looked different from his device. He posted about it on Reddit and went to the police in Thailand, but nothing was done about it. So, he found Joe and sent him the newly bought wallet for inspection.
Here is an image of what the user found after opening the bought and modified Nano X:

Jos also purchased multiple modified Ledger wallets from Lazada to inspect them.
Here is a close-up of one such device:

And a comparison between a legit Nano X at the top and a modified one at the bottom:

This is the back side of the implant:

Joe started taking them apart to figure out how they were working. He noticed there was an antenna, which signals potential wireless capabilities. He found out that the implant sends something over a cellular network. Joe accessed and dumped the flash memory of the microchip on the implant.
He also discovered that the implant had an eSIM on it. Joe extracted the data from the eSIM, hoping to find information about the person/group who created the implant. He learned that it was a data-only eSIM that was originally registered in the Netherlands through Vodafone.
Here is another picture of the entire implant with information about the individual components:

Through reverse engineering, Joe found out that the implant has a storage area where it stores recovery phrases. The implant monitors the Nano X’s screen. When the user starts configuring their wallet and generates the seed, the implant logs the data, moves it to flash, and sends it over a cellular network to the hacker.
Joe contacted Ledger and informed them about his findings. They exchanged some information and told him they have had a similar experience with such implants in Ledger devices as well. They also told him that their future devices will have better mitigations against such attacks.