Bitcoin Forum
September 06, 2026, 05:13:53 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Reverse Engineering a Ledger Nano X Hardware Implant  (Read 156 times)
Pmalek (OP)
Legendary
*
Offline

Activity: 3612
Merit: 9513



View Profile
September 02, 2026, 07:01:04 AM
Merited by vapourminer (4), ABCbits (2), Lucius (1), dkbit98 (1), m2017 (1), Charles-Tim (1), Z-tight (1), tenant48 (1)
 #1

I originally posted about this in My Interview with Famous Hardware Hacker Joe Grand aka Kingpin.
Yesterday, m2017 wrote that the Hardware Wallet board should probably have been the section to share this post. So I am just going to quote my post from earlier because it makes sense to mention it here as well.

It's a very interesting video. When you have 45 mins or so, I recommend that you take a look.

Reverse Engineering a Ledger Nano X Hardware Implant

A crypto user from Thailand had a Ledger Nano X hardware wallet, but the internal battery wasn't working properly. He decided to buy another Nano X, the cheapest one he could find, in order to take its battery and replace the one in his device. He bought one from Lazada. Lazada is an official Ledger reseller for Thailand, but it turns out that the service had (maybe it still has) fake listings as well.

When he got his device, he opened it, noticed that the battery was smaller, and that the circuitry and wires looked different from his device. He posted about it on Reddit and went to the police in Thailand, but nothing was done about it. So, he found Joe and sent him the newly bought wallet for inspection.

Here is an image of what the user found after opening the bought and modified Nano X:


Jos also purchased multiple modified Ledger wallets from Lazada to inspect them.

Here is a close-up of one such device:


And a comparison between a legit Nano X at the top and a modified one at the bottom:


This is the back side of the implant:


Joe started taking them apart to figure out how they were working. He noticed there was an antenna, which signals potential wireless capabilities. He found out that the implant sends something over a cellular network. Joe accessed and dumped the flash memory of the microchip on the implant.

He also discovered that the implant had an eSIM on it. Joe extracted the data from the eSIM, hoping to find information about the person/group who created the implant.  He learned that it was a data-only eSIM that was originally registered in the Netherlands through Vodafone.

Here is another picture of the entire implant with information about the individual components:


Through reverse engineering, Joe found out that the implant has a storage area where it stores recovery phrases. The implant monitors the Nano X’s screen. When the user starts configuring their wallet and generates the seed, the implant logs the data, moves it to flash, and sends it over a cellular network to the hacker.

Joe contacted Ledger and informed them about his findings. They exchanged some information and told him they have had a similar experience with such implants in Ledger devices as well. They also told him that their future devices will have better mitigations against such attacks.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
m2017
Legendary
*
Offline

Activity: 2604
Merit: 1718


keep walking, Johnnie


View Profile
September 02, 2026, 01:09:01 PM
Merited by vapourminer (1)
 #2

There is a much better chance here (in this section) that more people (specifically those interested in hardware wallets) will see this important information.

The hardware wallet market has taken hit after hit (Coldcard, the implants found in Ledger Nano X), and these devices, instead of remaining reliable, secure "vaults" for cryptocurrency, have become a vulnerability. The crypto community has realized that we can no longer blindly trust hardware wallets; we must stay vigilant and carefully verify the security of our storage solutions. The Ledger incident serves as a timely reminder to exercise caution and diligence when purchasing hardware wallets.

Perhaps it is time for HW manufacturers to make hardware wallets easy to disassemble (using screws to join the casing halves instead of snap-fit ​​plastic, which I’ve never liked) so that users can open the wallet and verify that the circuit board hasn't been tampered with. Tamper-evident seals aren't the answer; they are easily faked. I wouldn't trust a seal, I’d rather see this device's internals with my own eyes to put any doubts to rest.

I’m also curious about the scale of production for these counterfeits. Consider this: they use a genuine Ledger Nano X (which is costly), and the implantation process requires technical skill and time, making the production cost of these fake hardware wallets quite high. I understand that a single successful hack could recoup all the attackers' costs, but I wonder: just how widespread are these counterfeits on the market? Tens? Hundreds? Thousands? It’s a question of gauging the scale of the threat (the actual probability of buying a modified wallet).

Lucius
Legendary
*
Offline

Activity: 4088
Merit: 7764


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
September 02, 2026, 03:07:34 PM
 #3

This is really well thought out and maybe explains all those mysterious hacking cases where users claim they didn't do anything wrong but were hacked anyway. However, I think that it is not only Ledger that is exposed to this, it is probably not a problem to install such implants in other hardware wallets as well.

Unfortunately, the only way to make sure something like this isn't installed in the device would be to open it up and inspect the components - but there are two problems with that - first, you lose your warranty, and second, most people aren't qualified to assess whether something has been added or not.

It seems that we will all have to become engineers to protect ourselves from these attacks, or we will have to forget about hardware wallets as something that we have long considered the safest way to store private keys.

Pmalek (OP)
Legendary
*
Offline

Activity: 3612
Merit: 9513



View Profile
September 02, 2026, 03:46:23 PM
Merited by vapourminer (1)
 #4

Perhaps it is time for HW manufacturers to make hardware wallets easy to disassemble (using screws to join the casing halves instead of snap-fit ​​plastic, which I’ve never liked) so that users can open the wallet and verify that the circuit board hasn't been tampered with.
Hardware wallet manufacturers don't want you to disassemble the devices. If you do that, you will lose the warranty. A physical inspection of the hardware components does make sense, though. People will have to weigh up the pros versus the cons and decide what's better for them personally. You either don't open the device and use it as it is. In that case the wallet is under warranty for a year or however long the warranty lasts. The other option is to take it apart to look inside and perhaps risk breaking something and you also lose your warranty by doing that.

I know that Ledger shows on its website picture of how the inside boards and circuitry are supposed to look like in many of their models and generations. I don't know which other brands do that but it's definitely something they should do.

Also, the longer the supply chain, the greater the risk that someone may have manipulated a hardware wallet. If you buy it from the company directly, you are facing the lowest risk of physical manipulation. At the same time, your personal data is sitting in a centralized database that hackers and thieves will want to get their hands on. The alternative is to buy it from a reseller at a physical store to be safe from data leaks. However, you are then getting a product that has exchanged many more hands than if purchased directly from the manufacturer.

This is really well thought out and maybe explains all those mysterious hacking cases where users claim they didn't do anything wrong but were hacked anyway. However, I think that it is not only Ledger that is exposed to this, it is probably not a problem to install such implants in other hardware wallets as well.
Ledger is probably the main target because they are the most known and biggest manufacturer of hardware wallets. It's unlikely that hackers would be interested in targeting a small company that sells much smaller quantities of their products. I guess Trezor is their second most popular target.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
m2017
Legendary
*
Offline

Activity: 2604
Merit: 1718


keep walking, Johnnie


View Profile
September 03, 2026, 06:11:07 AM
Merited by vapourminer (4)
 #5

Hardware wallet manufacturers don't want you to disassemble the devices. If you do that, you will lose the warranty. A physical inspection of the hardware components does make sense, though. People will have to weigh up the pros versus the cons and decide what's better for them personally. You either don't open the device and use it as it is. In that case the wallet is under warranty for a year or however long the warranty lasts. The other option is to take it apart to look inside and perhaps risk breaking something and you also lose your warranty by doing that.
There is one way to find out whether physical modifications have been made to the device.

Make the hardware wallet casing out of transparent plastic. Ledger offers several transparent casing options, but I don't think the plastic is clear enough to allow for a good view of the internal components.

HW manufacturers should further develop this transparent casing concept. It would help minimize the risks associated with modified devices without requiring any intrusion into the internal mechanism.

I know that Ledger shows on its website picture of how the inside boards and circuitry are supposed to look like in many of their models and generations. I don't know which other brands do that but it's definitely something they should do.
While I fully agree with this, malicious actors will also gain access to this information, which will allow them to better disguise their forgeries.

Also, the longer the supply chain, the greater the risk that someone may have manipulated a hardware wallet. If you buy it from the company directly, you are facing the lowest risk of physical manipulation. At the same time, your personal data is sitting in a centralized database that hackers and thieves will want to get their hands on. The alternative is to buy it from a reseller at a physical store to be safe from data leaks. However, you are then getting a product that has exchanged many more hands than if purchased directly from the manufacturer.
Every buyer will face this dilemma: either risk their personal data (exposing themselves to a threat) or risk the contents of their wallet (running the risk of buying a counterfeit).

This is really well thought out and maybe explains all those mysterious hacking cases where users claim they didn't do anything wrong but were hacked anyway. However, I think that it is not only Ledger that is exposed to this, it is probably not a problem to install such implants in other hardware wallets as well.
Ledger is probably the main target because they are the most known and biggest manufacturer of hardware wallets. It's unlikely that hackers would be interested in targeting a small company that sells much smaller quantities of their products. I guess Trezor is their second most popular target.
Shall we look forward to a "surprise" involving this brand? Smiley


Unfortunately, the only way to make sure something like this isn't installed in the device would be to open it up and inspect the components - but there are two problems with that - first, you lose your warranty, and second, most people aren't qualified to assess whether something has been added or not.
On the contrary, there is another (old) method. Can transfer a small amount of money to the "potentially counterfeit device" and watch to see if those funds move "on their own". This method is not 100% foolproof, however, as malicious actors might leave small amounts untouched (perhaps due to a minimum transaction threshold) and wait for a more substantial sum to appear.

It seems that we will all have to become engineers to protect ourselves from these attacks, or we will have to forget about hardware wallets as something that we have long considered the safest way to store private keys.
Securely managing cryptocurrencies requires a wide range of skills, including engineers ones.

One should not forget hardware wallets; however, it is essential to recognize that they don't offer a 100% guarantee of secure storage and to factor this into one's overall security strategy.

Pmalek (OP)
Legendary
*
Offline

Activity: 3612
Merit: 9513



View Profile
September 03, 2026, 06:50:11 AM
 #6

There is one way to find out whether physical modifications have been made to the device.
Make the hardware wallet casing out of transparent plastic. Ledger offers several transparent casing options, but I don't think the plastic is clear enough to allow for a good view of the internal components.

HW manufacturers should further develop this transparent casing concept. It would help minimize the risks associated with modified devices without requiring any intrusion into the internal mechanism.
Everything evolves and gets better with time. You can expect the same thing with these hardware wallet implants. If you look at the pictures in OP, you will notice that it looks quite primitive in design. You have wires sticking out and going in all directions. Let's call that model1, the earliest generation of hardware implants. When they get more experience, the hackers will develop better looking implants and at one point in the future they might become much smaller and barely noticeable to a commoner.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
tenant48
Full Member
***
Offline

Activity: 380
Merit: 221


View Profile
September 03, 2026, 07:28:36 AM
Merited by vapourminer (4), Pmalek (3), Polkat (2), m2017 (1)
 #7

Everything evolves and gets better with time. You can expect the same thing with these hardware wallet implants. If you look at the pictures in OP, you will notice that it looks quite primitive in design. You have wires sticking out and going in all directions. Let's call that model1, the earliest generation of hardware implants. When they get more experience, the hackers will develop better looking implants and at one point in the future they might become much smaller and barely noticeable to a commoner.
The current implants with messy wires and shaved-down batteries are just crude 'Gen 1' proof-of-concepts. Attackers with a real budget will inevitably pivot to a full PCB Swap with exact topology cloning.The original chips, including the Secure Element, are simply hot-aired off and transplanted onto a custom multilayer board. On this new board, hackers can perfectly replicate Ledger's original routing, solder mask color, and silkscreen to match the official teardown photos, while hiding the spy components in the inner layers or blind spots.And the hardware is already commercially available to anyone. For instance, the TI MSPM0C1104 microcontroller is just 1.38 mm² (literally the size of a pepper corn), and a WLCSP-packaged eSIM (like the Infineon OPTIGA Connect) is roughly 1.8 x 1.6 mm and paper-thin. You just upload the gerber files to a service like JLCPCB, and Chinese pick-and-place robots assemble the boards. To the factory, it looks like a standard production run for a smartwatch.

m2017
Legendary
*
Offline

Activity: 2604
Merit: 1718


keep walking, Johnnie


View Profile
September 05, 2026, 08:37:55 AM
 #8

Everything evolves and gets better with time. You can expect the same thing with these hardware wallet implants. If you look at the pictures in OP, you will notice that it looks quite primitive in design. You have wires sticking out and going in all directions. Let's call that model1, the earliest generation of hardware implants. When they get more experience, the hackers will develop better looking implants and at one point in the future they might become much smaller and barely noticeable to a commoner.
The current implants with messy wires and shaved-down batteries are just crude 'Gen 1' proof-of-concepts. Attackers with a real budget will inevitably pivot to a full PCB Swap with exact topology cloning.The original chips, including the Secure Element, are simply hot-aired off and transplanted onto a custom multilayer board. On this new board, hackers can perfectly replicate Ledger's original routing, solder mask color, and silkscreen to match the official teardown photos, while hiding the spy components in the inner layers or blind spots.And the hardware is already commercially available to anyone. For instance, the TI MSPM0C1104 microcontroller is just 1.38 mm² (literally the size of a pepper corn), and a WLCSP-packaged eSIM (like the Infineon OPTIGA Connect) is roughly 1.8 x 1.6 mm and paper-thin. You just upload the gerber files to a service like JLCPCB, and Chinese pick-and-place robots assemble the boards. To the factory, it looks like a standard production run for a smartwatch.
This evolution of these modified devices seems quite systematic, and is, for that very reason, truly terrifying. No one is safe from such counterfeits; the situation is reminiscent of the threat posed by quantum computers: while it may not be an immediate danger, the advancement of technology (specifically regarding the skills needed to create and disguise these counterfeit HW devices) could well create significant problems for crypto asset owners in the foreseeable future. The situation is further compounded by the rising value of cryptocurrencies, which increases the potential payoff for attackers. Consequently, your prediction could easily come true, perhaps even in the near future.

How can one protect oneself when hardware wallets, even those from official manufacturers, can no longer be trusted? By developing the concept of building these HW devices yourself.

bitbollo
Legendary
*
Offline

Activity: 4102
Merit: 5040


https://bit.ly/bitbollo


View Profile
September 05, 2026, 08:59:08 AM
 #9

thanks for sharing the story.
I have seen in thepast other wallet modified but something related to software. looking inside of the ledger looks really creepy...
 
I am curious to know... if ths was the original reseller or just a secondary /already used device?
This kind of intervention requires a certain degree of knowledge and a specific target... also could be see as investement for buying ledger/antenna and spending time to assembly all.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Pmalek (OP)
Legendary
*
Offline

Activity: 3612
Merit: 9513



View Profile
September 05, 2026, 03:31:52 PM
 #10

How can one protect oneself when hardware wallets, even those from official manufacturers, can no longer be trusted? By developing the concept of building these HW devices yourself.
But even that is not enough and doesn't get rid of all potential problems. For example, bad code that generates seeds with not enough entropy, like we saw with Coldcard, isn't solved by giving users the option of assembling their hardware wallets themselves. The vulnerability would still be present in the codebase whether the signer is one piece or multiple ones.

I am curious to know... if ths was the original reseller or just a secondary /already used device?
Most probably a different shop or individual seller. Lazada is still on Ledger's list of official resellers for certain regions. If they themselves were at fault for distributing these devices, Ledger would have ended their cooperation with them by now. From what I understand, Lazada allows both individuals to sell their products or you can become a corporate seller.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Lucius
Legendary
*
Offline

Activity: 4088
Merit: 7764


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
Today at 01:47:06 PM
 #11

~snip~
From what I understand, Lazada allows both individuals to sell their products or you can become a corporate seller.


It's just creating an additional risk because the customer thinks they're buying from an authorized seller, but it turns out they're buying from someone authorized by the reseller. If Ledger allows such a practice then it should be added to the list of all the incredibly stupid things they have been doing for the past 5-6 years.

I don't know, even if the manufacturers were to remove the authorized resellers, there is still a risk in the delivery chain - pre-modified devices can be inserted into the packages at any time, whether it happens in the sorting center or is done by the delivery person during delivery.

Such packages should be "anonymous" in some way, in the sense that no one can deduce what is inside.

Pmalek (OP)
Legendary
*
Offline

Activity: 3612
Merit: 9513



View Profile
Today at 03:28:29 PM
 #12

It's just creating an additional risk because the customer thinks they're buying from an authorized seller, but it turns out they're buying from someone authorized by the reseller. If Ledger allows such a practice then it should be added to the list of all the incredibly stupid things they have been doing for the past 5-6 years.
Ledger's authorized reseller for Thailand on Lazada is called LazMall. That's the verified shop on Lazada that sells Ledger products. The link on the official reseller's page takes you here. That's where you should go if you are from Thailand and want to purchase a Ledger hardware wallet on Lazada. What you shouldn't do is search for "Ledger" on Lazada's search feature and purchase something random. That shows results from many other shops, not affiliated with Ledger.

I am not sure what you want Ledger or other companies to do about Lazada's operations. The same thing can theoretically happen anywhere. You have Ledger resellers on Amazon and links to the shop on Ledger's website. Those are the links you should click on and buy from those official resellers only. However, if you go to Amazon and perform a search on Ledger, you could perhaps find a manipulated device sold by someone else.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!