Bitcoin Forum
October 11, 2026, 10:13:04 PM *
News: Serious possible issue involving Ledger hardware wallets and CryptoBilis
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 [4] 5 6 7 »  All
  Print  
Author Topic: Reports about wallet-draining by Ledger users. Total losses $86M+  (Read 1805 times)
Livingleged
Full Member
***
Offline

Activity: 336
Merit: 212



View Profile
October 10, 2026, 05:02:46 AM
 #61

Former Mt. Gox CEO Mark Karpelès believes the cause may be a malicious implant. A physical cause.

Quote
This looks like this could be exactly what I'm investigating. Anyone affected, please contact me or open your ledger and send me pictures so we can confirm if there's a bug in there (pictures: ledger board on top, spy implant below).


This really got me thinking if it’s even possible to identify a bug on a hardware device just by looking at a picture. Is this a joke or something?

However, I’m kind of curious with the rate at which series of attacks on bitcoin wallets recently, its making me to to doubt if bitcoin is really going to get that adoption and acceptance like we are thinking in the nearest future, if all this attack continues like this, then we probably might never get there.

joker_josue
Legendary
*
Online Online

Activity: 2534
Merit: 7586


**In BTC since 2013**


View Profile WWW
October 10, 2026, 07:51:54 AM
 #62

It is a kind of implant that is implanted deliberately, like a Skimming tool to find out the ATM password. On the Ledger, the skimming device only reads the text on the screen.
A scammer's clever way of utilizing Resellers to trap all users.
Nothing is safe at the moment, too much hacking and manipulation.

But was the screen's circuit board replaced with another one that performed skimming? Or was it an extra chip inserted inside the device that intercepted the signal?

Another interesting question is: how was the information sent to the thieves?

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
█████████░█████░█████████
████████▀▀░▄▄▄░▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄░▀▀▀░▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
 
  Open − code isolated Crypto Wallet     Sign Up    
NotATether
Legendary
*
Offline

Activity: 2478
Merit: 10390


┻┻ ︵㇏(°□°㇏)


View Profile WWW
October 10, 2026, 07:58:16 AM
Merited by vapourminer (1)
 #63

This fucking crap again!

I thought we were done with this after Coldcard.

If someone can make such a really advanced stealth reader and implant it into resold devices, then serious questions need to start being asked.

- How do we defend from this? Since even your own entropy does not protect from it.
- How do we identify merges & takeovers and other sorts of warning signs?

1. Operational Handover & Conclusion of Role:
Earlier this year, CryptoBilis was acquired by new ownership. As part of this transition, Vimal and I officially stepped down and completed a full handover of all operational, managerial, and administrative responsibilities in March 2026.

Meanwhile their last post on X is basically a photoshoot of Lambos and women.

Very despicable retailer.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
ABCbits
Legendary
*
Offline

Activity: 3752
Merit: 10428



View Profile
October 10, 2026, 08:00:51 AM
 #64

Another interesting question is: how was the information sent to the thieves?

My speculation is internet with SIM card or eSIM connection. But from shared image, i didn't notice anything like that.

- How do we defend from this? Since even your own entropy does not protect from it.

If you're advance user and the company is transparent, you could compare the PCB on hardware wallet you buy with PCB image/schema shared by the company.

- How do we identify merges & takeovers and other sorts of warning signs?

Probably impossible for private company.

NotATether
Legendary
*
Offline

Activity: 2478
Merit: 10390


┻┻ ︵㇏(°□°㇏)


View Profile WWW
October 10, 2026, 08:05:52 AM
Merited by vapourminer (1), LuckyCrypto777 (1)
 #65

My speculation is internet with SIM card or eSIM connection. But from shared image, i didn't notice anything like that.

The main question I have is - did this work worldwide, or only within a certain country?

Roaming fees would make a worldwide op practically unfeasible. Whereas local could have like an automatic top up thing to the sim's phone number going on.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
taufik123
Legendary
*
artcontest
Offline

Activity: 3402
Merit: 2633


Duelbits.com


View Profile
October 10, 2026, 09:46:15 AM
Merited by LoyceV (12), pooya87 (7), ABCbits (5), joker_josue (5), vapourminer (4), Foxpup (3), Pmalek (3)
 #66

Another interesting question is: how was the information sent to the thieves?
My speculation is internet with SIM card or eSIM connection. But from shared image, i didn't notice anything like that.
According to a report written by Tibane Labs, 3 Generation Implants were found with 2 different device distribution lines.

1st generation: As you say, it uses an LTE Modem, an eSIM MFF2 with Vodafone NL Profile which is data-only and a manually generated antenna.

Aug 2025 → May 2026 - Grand Idea Studio takes the first one apart

2nd generation: Implant found on a Ledger Nano X device purchased through Yahoo! Auction Japan.

September 2026 - Nano X units

3rd Generation: Implants found on devices sold through Amazon Japan from sellers based in China and shipped from Malaysia.

September 2026 - Nano X units

The findings on the 1st Generation device with Vodafone eSIM NL profile are proof that this Ledger device gets an internet connection and sends the results of the keylogger.
But there is no technical evidence yet about how the LTE modem, eSIM and microcontroller can connect to each other and how the keylogger data is sent with certainty, still in the investigation stage.



The main question I have is - did this work worldwide, or only within a certain country?

Roaming fees would make a worldwide op practically unfeasible. Whereas local could have like an automatic top up thing to the sim's phone number going on.
Your question about the use of this SIM and eSIM is it successful for worldwide coverage based on Roaming Charges, Since the roaming charges alone are not enough to conclude that the global operation is not feasible.
Implants embedded with LTE Modems and eSIM profiles that support roaming will only transmit small amounts of data in the form of text.
As for the connectivity range, it will depend on the available network support.

Taken apart: the scraped eSIM and MCU and the nRF9151, next to their footprints on the implant board.

https://x.com/MagicalTux/status/2108583893809201216

While the use of local SIM with automatic recharge is still only a hypothesis, the Tibane Labs report does not prove that such a mechanism is used.

As far as the evidence is concerned, for the distribution channels that have been identified are in Asia, but the actual scope of distribution is still unknown

Full Source: https://www.tibane.net/research/ledger-nano-x-implant

Rymaster
Member
**
Offline

Activity: 510
Merit: 51

-Squidster-


View Profile
October 10, 2026, 09:57:22 AM
Merited by Pmalek (3)
 #67

How can the average user ever trust a hardware wallet at this point and where does it stop? We’re talking about a step that should create extra protection but instead has been compromising it. Heck, how can you even trust wallet apps aren’t skimming your seed phrases too?? Are we forced to go back to generating our own air gapped device paper wallets and forever letting our funds sit there without any interaction?

Join us over in the Reddit group!  www.reddit.com/r/CryptoCollectibles
Dave1
Hero Member
*****
Offline

Activity: 2184
Merit: 652



View Profile
October 10, 2026, 10:17:33 AM
 #68

If the attack remains within South East Asia and from the reseller CryptoBills, then it narrow everything down to them and this may be a case of their staff tampering with the wallet. These attacks scare me to death because those maybe be the entire saving of some people being drained. Last time it was open source wallet,  today it is a closed source wallet, what then is the way forward?

There has been a report already that someone purchase it recently and then moved all his Bitcoin to the compromise wallet and all is gone now.

Also news surfacing that there is a new CEO of CryptoBilis or at least a new management has takes over. And after that, this whole fiasco started to surface. So there is a big possibility that the new management might have something to do wit this attacks.


███████▄▄███▄███▄
███▄▄████████▌████▄
▄██████████████▐███▌
██▄███████████▌████▌
████████▀███████▐▌█
███████████████▌█▌▐
████████▄████████▐▐
██████████████████▌
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

█▄▄▄██████▄▄▄███████▄▄▄
████████████████████████████
████▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
████▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀██████████▌█████████████▄▄████▀
██████████▄█████▀████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀
 
..PLAY NOW..
Comeacross
Full Member
***
Offline

Activity: 308
Merit: 128



View Profile
October 10, 2026, 10:27:23 AM
 #69

It’s still unclear which type of scam was used but Ledger has actually issued an announcement [1] that victims are those who purchased their ledger wallet from a third party reseller named CryptoBills and are warning those who got their wallet from the reseller most importantly those in South East Asia to move their coins to a new device and wallet (seed and phrase)

Also there is report that the exploit was carried out through phishing email with the some reporting that the email looks like the in the image [1].

[1] https://x.com/ledger_support/status/2108551100613714002?s=46&t=QdZ3_ryvESgybupE3D6xaQ

Image [1]

From that announcement, cryptobilis is not just a random third party reseller, he's listed as an official ledger reseller. I don't think he'll risk his business and reputation by attempting to tamper with the device. The device was probably compromised before reaching the reseller either during shipment or likely from the company itself.

Additionally, we shouldn't be surprising if this is related to phishing. Ledger has experienced several data breaches/leaks in the past few months/years that involves customers email and addresses.

LoyceV
Legendary
*
Offline

Activity: 4186
Merit: 22932


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
October 10, 2026, 10:54:23 AM
Merited by Foxpup (3), Pmalek (3), vapourminer (1), ABCbits (1), taufik123 (1), joker_josue (1)
 #70

Simcard 2x2 mm is found inside of Ledger device. This is starting to look like a spy movie.
Ever since I read about the existence of esim, I feared this would happen one day.

I think we all need to rethink our wallet setup for storing our bitcoins.
It looks like I'm not even paranoid enough if I don't account for potential esim data leaks.

~
Dump the slips of paper in a bowl. Shuffle them!!! Pick 23. Write 'em down.
Get a new hardware wallet. Enter those 23 words and let the hardware wallet calculate the 24th word for you (the checksum). Do this and you'll know your seed is safe, because you made it yourself 100% randomly.
That doesn't save you if the hardware wallet contains wireless broadcasting hardware.

There is a very old guide, and now it's time to summon it back here
Check Integrity of Hardware Wallets.
I remember from years ago that Ledger doesn't even tamper proof their packaging. I wouldn't be surprised if the integrity check is unable to detect the added hardware.

Just another reason to justify my long dislike of hardware wallets!
I've never fully trusted them, as it's a "black box" I can never fully verify. But I've used them, and it's much more convenient than manually creating all keys offline.

The main question I have is - did this work worldwide, or only within a certain country?
Roaming fees would make a worldwide op practically unfeasible.
A worldwide esim data connection costs a few (dozen) dollars per month, and seed phrases don't consume a lot of data. Hardware wallets aren't powered on all the time, so I expect many devices to be able to share the same "subscription". If it works this way, it'll cost only cents per device per month.

Are we forced to go back to generating our own air gapped device paper wallets and forever letting our funds sit there without any interaction?
Being air gapped doesn't mean you can't make transactions, it's just more work to do.



Why is anyone still buying Ledger? They've lied in the past, and replaced their crucial "seeds can't leave the device" for "seeds will be uploaded to our servers" years ago. I would have expected them to just leak all seeds at some point, but even if they lied only once, they never deserve to be trusted again! This has been known for years!



How's this scenario:
  • Someone knows you own a hardware wallet (thanks to a data leak).
  • Someone breaks into your house and swaps your hardware wallet for a compromised device with esim broadcasting "feature".
  • You don't notice anything wrong, and use your hardware wallet.
  • The moment you enter your PIN, it's broadcasted to the thief, who has your real hardware wallet and steals your coins.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
[MUSIC] The Ballad of LoyceV
NotATether
Legendary
*
Offline

Activity: 2478
Merit: 10390


┻┻ ︵㇏(°□°㇏)


View Profile WWW
October 10, 2026, 10:55:53 AM
 #71

1st generation: As you say, it uses an LTE Modem, an eSIM MFF2 with Vodafone NL Profile which is data-only and a manually generated antenna.

Alright, that's what it is? Then manufacturers should be able to add a coated later of thick aluminium inside the shell, to prevent cellular signals from exiting in the first place. This would kill the remotely exploitable part.

And please nobody suggest to put all of your money in an iPhone. You can't airgap a phone.

@LoyceV: hopefully thick aluminium layers can solve this, right?

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
LoyceV
Legendary
*
Offline

Activity: 4186
Merit: 22932


Thick-Skinned Gang Leader and Golden Feather 2021


View Profile WWW
October 10, 2026, 11:02:31 AM
 #72

@LoyceV: hopefully thick aluminium layers can solve this, right?
I'm not sure. They'll probably find a way to make the cable act as an antenna.

¡uʍop ǝpᴉsdn pɐǝɥ ɹnoʎ ɥʇᴉʍ ʎuunɟ ʞool no⅄
[MUSIC] The Ballad of LoyceV
blockman
Hero Member
*****
Offline

Activity: 3794
Merit: 685


AntiSwap.io - NO AML/KYC EXCHANGER MONITORING


View Profile
October 10, 2026, 11:05:59 AM
Last edit: October 10, 2026, 11:36:06 AM by blockman
 #73

CryptoBilis Philippines posted on their facebook page about official notice of the management and instructions of contacting them for those affected users who have lost their funds. With all of those requirements about the packaging and stuff, I hope that all of the victims have kept all of it. And as long as the details provided by the victims are genuine even they lack the others, CryptoBilis must help all of them who reaches them out.


retreat
Hero Member
*****
Offline

Activity: 1890
Merit: 550


Rollbit.com | Crypto's Most Rewarding Casino


View Profile WWW
October 10, 2026, 11:20:31 AM
 #74

The fact that they took the name CryptoBilis kind of tickled me a bit, because 'bilis' means anchovies. In my area, 'bilis' has a bit of a negative connotation, it's something considered low and not serious. They really live up to their name. If I didn't know that they were authorized resellers from Ledger, I might have thought they were just some random guy selling Ledger.

But, moving on from that, I just went to their site and noticed that it turns out they not only offer Ledger, but they also provide other hardware wallets. Don’t know if at this point it’s really wise to trust the hardware wallets they provide because this situation is so f**ked up..



R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT|
4,000+ GAMES
███████████████████
██████████▀▄▀▀▀████
████████▀▄▀██░░░███
██████▀▄███▄▀█▄▄▄██
███▀▀▀▀▀▀█▀▀▀▀▀▀███
██░░░░░░░░█░░░░░░██
██▄░░░░░░░█░░░░░▄██
███▄░░░░▄█▄▄▄▄▄████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
█████████
▀████████
░░▀██████
░░░░▀████
░░░░░░███
▄░░░░░███
▀█▄▄▄████
░░▀▀█████
▀▀▀▀▀▀▀▀▀
█████████
░░░▀▀████
██▄▄▀░███
█░░█▄░░██
░████▀▀██
█░░█▀░░██
██▀▀▄░███
░░░▄▄████
▀▀▀▀▀▀▀▀▀
||.
|
▄▄████▄▄
▀█▀
▄▀▀▄▀█▀
▄▄░░▄█░██░█▄░░▄▄
▄▄█░▄▀█░▀█▄▄█▀░█▀▄░█▄▄
▀▄█░███▄█▄▄█▄███░█▄▀
▀▀█░░░▄▄▄▄░░░█▀▀
█░░██████░░█
█░░░░▀▀░░░░█
█▀▄▀▄▀▄▀▄▀▄█
▄░█████▀▀█████░▄
▄███████░██░███████▄
▀▀██████▄▄██████▀▀
▀▀████████▀▀
.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
░▀▄░▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄░▄▀
███▀▄▀█████████████████▀▄▀
█████▀▄░▄▄▄▄▄███░▄▄▄▄▄▄▀
███████▀▄▀██████░█▄▄▄▄▄▄▄▄
█████████▀▄▄░███▄▄▄▄▄▄░▄▀
████████████░███████▀▄▀
████████████░██▀▄▄▄▄▀
████████████░▀▄▀
████████████▄▀
███████████▀
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▀▄███░░░▀████░███▄▀██▄
███░████░░░░░▀██░████░███
███░████░█▄░░░░▀░████░███
███░████░███▄░░░░████░███
▀██▄▀███░█████▄░░███▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
OFFICIAL PARTNERSHIP
SOUTHAMPTON FC
FAZE CLAN
SSC NAPOLI
Porfirii
Legendary
*
Offline

Activity: 2660
Merit: 4020


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
October 10, 2026, 11:47:13 AM
 #75

-snip-

But, moving on from that, I just went to their site and noticed that it turns out they not only offer Ledger, but they also provide other hardware wallets. Don’t know if at this point it’s really wise to trust the hardware wallets they provide because this situation is so f**ked up..




That's worrying, and while there is no evidence yet that the rest of the devices on the list have been compromised, I think the most prudent option would be to quarantine all HWs sold by this vendor.

The warning is not new, it has always been said that we should not trust intermediaries when buying hw because of the possibility of tampering, and it is confirmed once again that this warning should not be taken lightly.

Zaguru12
Legendary
*
Offline

Activity: 1568
Merit: 1323



View Profile WWW
October 10, 2026, 11:57:37 AM
 #76


From that announcement, cryptobilis is not just a random third party reseller, he's listed as an official ledger reseller. I don't think he'll risk his business and reputation by attempting to tamper with the device. The device was probably compromised before reaching the reseller either during shipment or likely from the company itself.

Additionally, we shouldn't be surprising if this is related to phishing. Ledger has experienced several data breaches/leaks in the past few months/years that involves customers email and addresses.

Me and you cannot simply say until he is investigated and seriously everything points directly to him and this is not just a phishing attack according to one MagicalTux on X who open the ledger he reported bought from same region (Malaysia) showed that there was a little board under the screen and this has the capacity to watch the display of the data and then sends the information over a mobile data since the extra board has both modem and eSIM. By this we can clearly say that victims seed phrases might have been,

We can’t single out cryptobillis but every victim is pointing out to buying from him, who would be your suspect then?


But, moving on from that, I just went to their site and noticed that it turns out they not only offer Ledger, but they also provide other hardware wallets. Don’t know if at this point it’s really wise to trust the hardware wallets they provide because this situation is so f**ked up..




Seriously if I was one of those with this wallets and I have bought mine from the south east Asia in the last three months? I do think I will be worried by now.

.◼.◼.Vega.bet.◼.◼.██
██
██
██
██
██
██
██
██
██
██
██
██

...100 FS + 750% BONUS..MAX.WIN.$5,000...

███...FAST PAYOUTS  |  NO KYC  |  10% LOSSBACK...███
██
██
██
██
██
██
██
██
██
██
██
██
██

...Play Now...
icopress
Ken Masters
Legendary
*
Offline

Activity: 2492
Merit: 13613



View Profile
October 10, 2026, 12:14:41 PM
Merited by NeuroticFish (5), pooya87 (5), Pmalek (3), joker_josue (2), NotATether (2), vapourminer (1), ABCbits (1), taufik123 (1), Crypto Library (1)
 #77

Guys, there’s a lot of noise online right now, so I’m sharing a post here from 2023—written by someone you know.

Even though it was a custom Ledger, it serves as a clear example of what the device and the verification stages should look like.


In theory, on their website the required steps look simple, yet the practice is the one which always kills us. All I found there was this:

Quote
Secure Element attestation

The Secure Element itself is personalized at factory with an attestation proving that it has been manufactured by Ledger. You can verify it by running

pip install --no-cache-dir ledgerblue

python -m ledgerblue.checkGenuineRemote --targetId 0x33000004

Obviously, those were not commands which could be simply typed in a Command Prompt window. So after some digging I understood that I have first to install Python. You can get Python from here: https://www.python.org/downloads. Alternatively, you can also download it from Microsoft store. I downloaded Python 3.11.4.

Following some articles I found on the Internet, I understood that Visual Studio 2017 build tools may also be needed on Windows. As I wanted to make sure I have all prerequisites, I also installed this software (so I don't know if everything works without it). Visual Studio 2017 build tools can be downloaded from here: https://www.visualstudio.com/downloads/#build-tools-for-visual-studio-2017.

If you want to make sure you installed Python properly, you can run this command (directly in a Command Prompt window -- so just press Start - Run - cmd or press Windows key + R): python --version. You should see something like this:



Then you'll need to install pip, which is a Python package manager, which may come or not together with your Python build. Following some tutorials about Python, I reached this page and from here you can download pip. You will see in your Download folder a file named get-pip.py.

Afterwards you have to run this command (Command Prompt): python get-pip.py. This will install pip.

Having pip installed, you can ensure about this by typing the following command (in Command Prompt): pip --version.  You should see something like this:



Additionally, you'll need to install a Virtual Environment for Python, in order to be able to run the commands for checking the hardware integrity (I know, it already sounds like a pain in the ass only by reading everything I wrote here but imagine how it feels to actually do all these (!) and find all the information necessary in order to be able to make this check... Smiley). So following the same tutorial page for Python I installed first Pipenv, which allows you to install Python packages, then I installed Virtualenv, which "creates a folder which contains all the necessary executables to use the packages that a Python project would need". In order to install these, you need to run these commands (in Command Prompt): pip install --user pipenv and pip install virtualenv.

Next step is to install Python tools for Ledger Blue, Nano S and Nano X, which can be found here. In order to be able to do this you need to run the following commands (in Command Prompt): python3 -m venv ledger and pip install ledgerblue.

After finishing all these we finally get back to the command shown on Ledger website: python -m ledgerblue.checkGenuineRemote --targetId 0x33000004 -- but we do not run the command yet (keep reading below). The part "0x33000004" is the TargetID, meaning a code of your product. The entire list of TargetIDs is available on the website I mentioned above (obviously, none of these can be found directly on Ledger's website so you need deep Internet search for obtaining all this information):

Quote
Device nameFirmware VersionTargetID
Nano S Plusall0x33100004
Nano X< 2.2.1 (developer units only)0x33000004
Nano X>= 2.2.10x33000004
Nano S<= 1.3.10x31100002
Nano S1.4.x0x31100003
Nano S>= 1.5.x0x31100004
Ledger Blue<= 2.00x31000002
Ledger Blue2.1.x0x31000004
Ledger Blue v22.1.x0x31010004

As I wrote above, the command should not be entered yet. This is because the Ledgers from Betnomi have an old firmware (2.0.1) and the command works with newer firmware versions. So at this point you need to perform a firmware update (if you haven't already), which can be done through the Ledger Live app. For those not aware (there may be still a few of them), Ledger Live app can be downloaded from Ledger website: https://www.ledger.com/ledger-live. After installation is done select the tab My Ledger. There will be two firmware updates available. First one will upgrade the Ledger's firmware from 2.0.1 to 2.2.1. Second upgrade will bring the firmware 2.2.2 to your Ledger. However, the command for checking the hardware integrity can be run after having the firmware 2.2.1. You should see something like this:



Reaching this point, you must have the Ledger connected to your PC / laptop and also make sure it is not in standby. For obvious reasons, the command won't do anything if the wallet is not connected to the PC. And, if it is in standby mode you'll get a long error message, ending with Connection to remote host was lost. However, assuming that the device is connected and it is not in standby mode, run the command python -m ledgerblue.checkGenuineRemote --targetId 0x33000004. You will receive a warning on your Ledger screen, which you need to confirm.

And finaaaaaaaaaaally, after all these, I received this confirmation:



It was a lot of work but, at least, I was assured that the Ledgers from Betnomi are genuine. Or, at least, I was  50% assured. To ensure the remaining 50% I proceeded to open the device, in order to check its PCB.





Warning: performing the steps mentioned below may destroy your device. If you won't destroy it then you'll certainly lose the warranty.

This part may also sound simple, but it's not simple at all. You need to pay a lot of attention, as the product looks like a capsule (obviously, it was not meant to be opened) and it has no screw. Trying to break its case open may break it so your device may be totally damaged. However, since I won 3 such Ledgers from Betnomi I afforded the risks.

So first step is to remove the grey part branded with Betnomi from the wallet. The grey part should be lifted (in a delicate manner) from the grey button of the wallet. It can be removed relatively easy.



Now the important part comes. You need a very thin screwdriver or a very thin knife or any other sharp thing which is also very thin. If you look around the display, you'll see a very thin line -- this is the line where the part of the case protecting the display is assembled with the rest of the product. The screw driver should be used for forcing it into this thin line, in order to detach this part of the case from the other part of it. This should be done with a lot of attention, as at this step the device may become broken. In order to avoid this you may try to push the screwdriver between the part with the display and the rest of the wallet case on multiple spots of this thin line, thus getting some more weak spots which, in the end, will make the detaching of the display more easy.

By pure chance, I had a minuscule screwdriver and I used it for the surgery operation:





Then I used the grey part, which I previously removed, and I inserted it in the small opening made by the screwdriver, to keep that part open. Having a part already open, I used the screwdriver to force the opening more:



I proceeded with caution for the rest of the thin line until the case fully opened.

At this point I had to pay a lot of attention, as the navigation buttons are not attached to the PCB, nor to the external side of the case. They are not attached to anything and only the fact that they enter in the holes of the case keeps them at place. So I took them out, hoping to remember the correct place of each one.



The display is on the other side of the PCB (as seen in the image from above) and it is connected to the PCB through a small interface, so you can manipulate it to a side, since it is not attached on the PCB. This is important, because by moving it to a side you can check the entire side of the PCB where it is placed.

In the end, I could take these pictures of both sides of the PCB:



Next step was to compare the PCB details with the images shown on Ledger's website. There are 4 hardware revisions of these Ledgers, having different PCB colors. The PCB of my device is green, which corresponds to Revision 4. And, by analyzing the look of my PCB and the one from Ledger website, it seems the PCBs are identical:



Now I was finally assured that my product respects the hardware integrity!

Since I am a magician when it comes to opening electronic devices piece by piece then placing all the pieces back together By pure chance I also managed to place back everything inside the wallet case then close back the case. Surprisingly, the wallet is still functional! Grin





In the end, for trying to be more catholic than Pope is, I performed also the genuine check offered by Ledger Live app:









The check concluded by saying that the product is genuine. Hooray!





Conclusion

Having these said, I guess that the owners of Betnomi Ledgers can relax now, as their products are not tampered with. Those which want though can perform the above steps for checking their wallets' hardware integrity on their own. However, I don't recommend this, unless you don't care if the device gets fully damaged or unless you are used to opening electronic devices / fix them / etc. Smiley

It is very sad that icopress is having a huge loss because of Betnomi but, at least, they were not that evil to tamper the devices they raffled on the forum.

pooya87
Legendary
*
Offline

Activity: 4242
Merit: 12622



View Profile
October 10, 2026, 12:41:18 PM
 #78

Just another reason to justify my long dislike of hardware wallets!
I've never fully trusted them, as it's a "black box" I can never fully verify. But I've used them, and it's much more convenient than manually creating all keys offline.
No arguments there. I would probably still suggest using hardware wallets to some people but add a warning to my suggestion from now on. And the hurdle is not just about lack of convenience of creating keys offline, but the fact that many users aren't technically skilled to be able to do it correctly.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Pmalek
Legendary
*
Offline

Activity: 3640
Merit: 9690



View Profile
October 10, 2026, 12:44:22 PM
Merited by taufik123 (1)
 #79

This reminds me of a video that Joe Grand, the hardware hacker, released in August 2026 where he worked on reverse engineering an implant from a Nano X device. That particular hardware wallet was purchased in Thailand and Lazada. The interior looks primitive compared to the newer implants. Scammers are learning and adapting.

If you buy a hardware wallet from an online store, you risk that your personal information will get leaked.
The alternative is to buy it in physical shops where the risk of supply chain attacks increases.

It's getting to a point where we should think hard if and how to purchase classic bitcoin hardware wallets.

Quoting my own post for reference:

Reverse Engineering a Ledger Nano X Hardware Implant

A crypto user from Thailand had a Ledger Nano X hardware wallet, but the internal battery wasn't working properly. He decided to buy another Nano X, the cheapest one he could find, in order to take its battery and replace the one in his device. He bought one from Lazada. Lazada is an official Ledger reseller for Thailand, but it turns out that the service had (maybe it still has) fake listings as well.

When he got his device, he opened it, noticed that the battery was smaller, and that the circuitry and wires looked different from his device. He posted about it on Reddit and went to the police in Thailand, but nothing was done about it. So, he found Joe and sent him the newly bought wallet for inspection.

Here is an image of what the user found after opening the bought and modified Nano X:


Jos also purchased multiple modified Ledger wallets from Lazada to inspect them.

Here is a close-up of one such device:


And a comparison between a legit Nano X at the top and a modified one at the bottom:


This is the back side of the implant:


Joe started taking them apart to figure out how they were working. He noticed there was an antenna, which signals potential wireless capabilities. He found out that the implant sends something over a cellular network. Joe accessed and dumped the flash memory of the microchip on the implant.

He also discovered that the implant had an eSIM on it. Joe extracted the data from the eSIM, hoping to find information about the person/group who created the implant.  He learned that it was a data-only eSIM that was originally registered in the Netherlands through Vodafone.

Here is another picture of the entire implant with information about the individual components:


Through reverse engineering, Joe found out that the implant has a storage area where it stores recovery phrases. The implant monitors the Nano X’s screen. When the user starts configuring their wallet and generates the seed, the implant logs the data, moves it to flash, and sends it over a cellular network to the hacker.

Joe contacted Ledger and informed them about his findings. They exchanged some information and told him they have had a similar experience with such implants in Ledger devices as well. They also told him that their future devices will have better mitigations against such attacks.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████▄█████
█████████████████████████
███████████▀█████████████
█████████▀███▀██████▀████
██████████████████▄██████
█████████▄▄█▄▄███████████
██████████▄▄▄████████████
███████████████████▀█████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
|⚽ 🏀
 
🏈 🏓
 
🎯 🥊
 
⚾ 🎾
 
⛳ 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▄▀▀███████████████▀▀███
█▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌████▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
█▀█████████████████████▀██
██▀▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

 ✔ G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
OcTradism
Legendary
*
Offline

Activity: 2618
Merit: 1050



View Profile
October 10, 2026, 01:07:45 PM
 #80

Why is anyone still buying Ledger? They've lied in the past, and replaced their crucial "seeds can't leave the device" for "seeds will be uploaded to our servers" years ago. I would have expected them to just leak all seeds at some point, but even if they lied only once, they never deserve to be trusted again! This has been known for years!
It's another nail on their coffin, not sure the last one as we all have to wait and witness what will happen next with Ledger.

Ledger is so crappy from data breaches, to Ledger Recover (smh with this product), then this Ledger authorized reseller CryptoBilis but maybe more, it's hard to trust Ledger again.

It's close source too.

In my mind, an authorized reseller selling bugged devices is the nail in the coffin for Ledger. I'll be actively recommending against Ledger from now on.

People still use Ledger after they released this product years ago?
Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties entities

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████▄░░████░░▄███
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET.██████.IIIIICRYPTO'S FASTEST GROWING CASINO.██████.
|
▄
█▄█
▀█▀
▄████▄▄█████████▄▄████▄
█▄████▀█░░█████░░█▀████▄█
▀█▄▄░▐███████████▌░▄▄█▀
▐██▄▄█████████▄▄████▌
████████▄▄█████████
█
█
█▀▀████████████████
██████
█████████████
██
█▀▀████████████████
▀
▀▀▀███████████▀▀▀▀
| 
.
    PLAY NOW    
Pages: « 1 2 3 [4] 5 6 7 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!