• About
  • Contact
  • Privacy Policy
  • bitcoinBitcoin$104,667.00-0.45%
  • ethereumEthereum$2,509.69-0.31%
  • xrpXRP$2.150.58%
  • bitcoin cashBitcoin Cash$459.898.02%
Cryptovibes.com - Daily Cryptocurrency and FX News
  • Home
  • News
    • PR
  • Analysis
  • Crypto
    • Crypto Presales
    • Bitcoin Minetrix Price Prediction
    • Bitcoin Casinos
  • Broker Reviews
    • Herdos Review
    • FXTB Review
    • Altindex
    • Bitcoin Trading
      • Immediate Evex
      • Immediate Connect
      • Quantum Flash
      • Bitsoft360
      • Bitcoin360 AI
      • Immediate Edge
      • Bitcoin Code
      • BitAlpha AI
      • Bitcoineer
      • Immediate Experience
      • Quantum AI
      • Bit GPT AI
      • Immediate Bitcoin
      • Vena System
      • Immediate Profit
      • Immediate GP
      • Bitcoin Fast Profit
      • Ethereum Code
      • Immediate Granimator
      • Quantum Prime Profit
      • BitVestment
      • BitIQ
      • BitProfit
      • Bitcoin Edge
      • Bit Index AI
      • Immediate Iplex
      • Yuan Pay Group
      • Metaverse Profit
      • Today Profit
      • Bitcoin Buyer
      • AI Trading Bots
      • Quantum Code
      • Bitcoin Billionaire
      • Bitcoin Circuit
      • Bitcode Prime
      • Bitprime Gold
      • Bitcoin Motion
      • BitAI Method
      • Bitcoin Bank Breaker
      • Bitcoin Smarter
      • Bitcoin Robot Guide
      • Bitcoin Oracle AI
      • Bitcoin Future
      • Bitcoin Millionaire Pro
      • BitiCodes
      • Crypto Bank
      • Bitcoin Loophole
      • Bitcoin Storm
      • Bitcoin SuperSplit
      • Bitcoin Supreme
      • TeslaCoin
      • Bitcoin System
      • Bitcoin Fortress
      • Bitcoin Profit
      • BitQH
      • Quantumator
      • Bitcoin Trader
      • Immediate Alpha
      • xBitcoin Club
      • Bitcoin Bank
      • Quantum Hancock
      • Chain Reaction
      • Bitcoin Union
      • Crypto Capital
      • CoinTrade1000
      • BitQT
      • Quantum System
      • Immediate Momentum
      • Libra Profit System
      • Bitcoin Sprint
      • Bitcoin KPEX AI
      • Quantum Trade Wave
      • Bitcoin Bonanza
      • Bitcode Method
      • Bitcoin Millionaire
      • Immediate Fortune
      • Bit Iplex Codes
      • Bitcoin Revolution
      • Bitcoin Method
      • Profit Compass
      • Bitcoin Champion
      • Bitcoin Optimizer
      • Bitcoin Rush
      • NFT Profit
      • Bitcoin Decoder
      • Immediate Future
      • Immediate Revolution 360
      • Altrix Edge
      • Trader AI
      • Immediate Eurax ai
      • Immediate Enigma
      • Immediate Definity AI
      • Immediate Peak
      • Immediate Coraldex
      • Immediate Bitwave
      • Immediate Lidex Ai
      • Voltix Momentum
      • Immediate matrix
      • TradeGPT 360
      • Immediate Vortex
      • Bitcoin Avage
      • Bitcoin Urex GPT
      • Profit Builder
      • Immediate GPT
      • Immediate Wealth
      • ChainWizard AI
      • BitApp 24
      • BGX AI
      • Immediate Code AI
      • Immediate Growth
      • Gewinn Code System
      • Quantum FBC
      • Immediate Flik
      • Quantum Genius GPT
      • Immediate Motion
      • Immediate 3.0 ReoPro
      • Immediate iPro AI
      • Immediate Multiplex
      • Immediate Cipro AI
      • Immediate Bitnex
      • Immediate Avage
      • Immediate ePrex
      • Immediate Serax
      • Yuan International
      • Immediate Innovault
      • Quantum Espace
      • Immediate Turbo
      • Immediate Maximum
      • Immediate Neupro AI
      • Immediate Core
      • Immediate Savage 360
      • Immediate EWave
      • Quantum G Force
      • Everix Peak
      • Immediate Evista
      • Profit Rex
  • Disclaimer
  • Cryptovibes
    • Croatian
    • Czech
    • Danish
    • Dutch
    • Finnish
    • German
    • Hungarian
    • Japanese
    • Korean
    • Norwegian
    • Polish
    • Portuguese
    • Romanian
    • Slovak
    • Spanish
    • Swedish
    • Turkish
No Result
View All Result
Cryptovibes.com - Daily Cryptocurrency and FX News
No Result
View All Result

Scammers Sent Fake Hardware Wallets To Ledger Data Breach Victims

John Wanguba by John Wanguba
June 17, 2021
in Crypto news
Reading Time: 5min read
Scammers Sent Fake Hardware Wallets To Ledger Data Breach Victims
Rate this post

Several Ledger users have reported receiving fake replacement devices in the mail. The new devices are designed to phish private security information. Consequences of Ledger’s major data breach are continuously being felt nearly one year later.

A contributor to the Reddit r/ledgerwallet forum, posting under the tag “u/jjrand” and self-identified as being among the victims of last year’s breach, has published images of what seems to be a fake Ledger Nano X wallet received in their postal mail.

Wrapped in somewhat authentic packaging, the device nevertheless featured multiple red flag signs that sparked his suspicion. Most strangely, the new device came with a poorly written letter alleging to be signed by Ledger CEO Pascal Gauthier, informing its recipient:

“For security purposes, we have sent you a new device you must switch to a new device to stay safe. There is a manual inside your new box you can read that to learn how to set up your new device. For this reason, we have changed our device structure. We now guarantee that this kinda breach will never happen again.”

Box containing allegedly fraudulent Ledger device, received by reddit user yu/jjrand. Source: Reddit
Box containing allegedly fraudulent Ledger device, received by reddit user yu/jjrand. Source: Reddit
Scam letter purportedly written and signed by Ledger CEO Pascal Gauthier. Source: Reddit
Scam letter purportedly written and signed by Ledger CEO Pascal Gauthier. Source: Reddit

Apart from that letter, u/jirand also got a fake manual that enclosed instructions about how to use the new device and, critically, asking the recipient to enter their private Ledger recovery phrase to enable them to connect their crypto wallet to the new hardware.

Based on additional images displaying the device’s circuit board uploaded on Reddit, security researcher Mike Grover told BleepingComputer said that this fake device was already tampered with:

“This seems to be a simple flash drive strapped on to the Ledger with the purpose to be for some sort of malware delivery. All of the components are on the other side, so I can’t confirm if it is JUST a storage device, but […] judging by the very novice soldering work, it’s probably just an off-the-shelf mini flash drive removed from its casing.”

Grover focused on a section of the back of the device that showed the flash drive implant, noting that:

“those 4 wires piggyback the same connections for the USB port of the Ledger.”

Back of fake Ledger device. Source: Reddit, with highlight added by Mike Gover
Back of fake Ledger device. Source: Reddit, with highlight added by Mike Gover
Back of authentic Ledger device. Source: BleepingComputer
Back of authentic Ledger device. Source: BleepingComputer

Based on Gover and BleepingComputer’s analysis, it seems like the heist is perfectly designed to intercept the user’s entered recovery secret phrase to reroute the details to a gadget or device entirely controlled by the scammers. The criminals then use the entered phrase to steal the associated crypto holdings.

In a May 10 online post that was not cited by u/jirand, Ledger had warned its users against the fake letter and device, saying:

“The fake user guide in the Nano’s box asks the user to connect the device to a computer. To initialize the device, the user is then asked to enter his 24 words in a fake Ledger Live application. This is a scam. Do not connect the device to your computer and never share your 24 words. Ledger will never ask you to share your 24-word recovery phrase.”

While that warning comes as part of Ledger’s online list of phishing activities of which the firm is already aware, it is not yet determined whether the firm has reached out to its users directly, mostly those whose leaked details might leave them more susceptible to falling for this syndicate.

Ledger is yet to respond to this matter. But according to previous reports, other consequences of the data leak included Ledger getting emails from extortionists who threatened with physical violence and other criminal attacks.

The initial data breach had happened in June and July of 2020 and featured 1,075,382 email addresses from users who had subscribed to the Ledger newsletter. Notably, it involved the leak of personal information like home addresses that are associated with 272,853 hardware wallet orders.

Like what you're reading? Subscribe to our top stories
Tags: Businesscryptocrypto scamcryptocurrencyhardware walletLedgerPhishingScamswallet

Related Posts

How Gold And The Dollar Could Help Validate A Bitcoin Bull Run
Analysis

How Gold And The Dollar Could Help Validate A Bitcoin Bull Run

June 24, 2023
Can Memecoins Make You Rich?
Analysis

Can Memecoins Make You Rich?

May 20, 2023
FightOut: The Move-to-Earn Crypto Project Expected To Blast Off In 2023
Crypto news

FightOut: The Move-to-Earn Crypto Project Expected To Blast Off In 2023

December 17, 2022
Facebook Twitter Instagram Telegram RSS Youtube

Copyright © 2017-2019 Cryptovibes.com. Price data provided by our official partner CoinGecko.

No Result
View All Result
  • Home
  • News
    • PR
  • Analysis
  • Crypto
    • Crypto Presales
    • Bitcoin Minetrix Price Prediction
    • Bitcoin Casinos
  • Broker Reviews
    • Herdos Review
    • FXTB Review
    • Altindex
    • Bitcoin Trading
      • Immediate Evex
      • Immediate Connect
      • Quantum Flash
      • Bitsoft360
      • Bitcoin360 AI
      • Immediate Edge
      • Bitcoin Code
      • BitAlpha AI
      • Bitcoineer
      • Immediate Experience
      • Quantum AI
      • Bit GPT AI
      • Immediate Bitcoin
      • Vena System
      • Immediate Profit
      • Immediate GP
      • Bitcoin Fast Profit
      • Ethereum Code
      • Immediate Granimator
      • Quantum Prime Profit
      • BitVestment
      • BitIQ
      • BitProfit
      • Bitcoin Edge
      • Bit Index AI
      • Immediate Iplex
      • Yuan Pay Group
      • Metaverse Profit
      • Today Profit
      • Bitcoin Buyer
      • AI Trading Bots
      • Quantum Code
      • Bitcoin Billionaire
      • Bitcoin Circuit
      • Bitcode Prime
      • Bitprime Gold
      • Bitcoin Motion
      • BitAI Method
      • Bitcoin Bank Breaker
      • Bitcoin Smarter
      • Bitcoin Robot Guide
      • Bitcoin Oracle AI
      • Bitcoin Future
      • Bitcoin Millionaire Pro
      • BitiCodes
      • Crypto Bank
      • Bitcoin Loophole
      • Bitcoin Storm
      • Bitcoin SuperSplit
      • Bitcoin Supreme
      • TeslaCoin
      • Bitcoin System
      • Bitcoin Fortress
      • Bitcoin Profit
      • BitQH
      • Quantumator
      • Bitcoin Trader
      • Immediate Alpha
      • xBitcoin Club
      • Bitcoin Bank
      • Quantum Hancock
      • Chain Reaction
      • Bitcoin Union
      • Crypto Capital
      • CoinTrade1000
      • BitQT
      • Quantum System
      • Immediate Momentum
      • Libra Profit System
      • Bitcoin Sprint
      • Bitcoin KPEX AI
      • Quantum Trade Wave
      • Bitcoin Bonanza
      • Bitcode Method
      • Bitcoin Millionaire
      • Immediate Fortune
      • Bit Iplex Codes
      • Bitcoin Revolution
      • Bitcoin Method
      • Profit Compass
      • Bitcoin Champion
      • Bitcoin Optimizer
      • Bitcoin Rush
      • NFT Profit
      • Bitcoin Decoder
      • Immediate Future
      • Immediate Revolution 360
      • Altrix Edge
      • Trader AI
      • Immediate Eurax ai
      • Immediate Enigma
      • Immediate Definity AI
      • Immediate Peak
      • Immediate Coraldex
      • Immediate Bitwave
      • Immediate Lidex Ai
      • Voltix Momentum
      • Immediate matrix
      • TradeGPT 360
      • Immediate Vortex
      • Bitcoin Avage
      • Bitcoin Urex GPT
      • Profit Builder
      • Immediate GPT
      • Immediate Wealth
      • ChainWizard AI
      • BitApp 24
      • BGX AI
      • Immediate Code AI
      • Immediate Growth
      • Gewinn Code System
      • Quantum FBC
      • Immediate Flik
      • Quantum Genius GPT
      • Immediate Motion
      • Immediate 3.0 ReoPro
      • Immediate iPro AI
      • Immediate Multiplex
      • Immediate Cipro AI
      • Immediate Bitnex
      • Immediate Avage
      • Immediate ePrex
      • Immediate Serax
      • Yuan International
      • Immediate Innovault
      • Quantum Espace
      • Immediate Turbo
      • Immediate Maximum
      • Immediate Neupro AI
      • Immediate Core
      • Immediate Savage 360
      • Immediate EWave
      • Quantum G Force
      • Everix Peak
      • Immediate Evista
      • Profit Rex
  • Disclaimer
  • Cryptovibes
    • Croatian
    • Czech
    • Danish
    • Dutch
    • Finnish
    • German
    • Hungarian
    • Japanese
    • Korean
    • Norwegian
    • Polish
    • Portuguese
    • Romanian
    • Slovak
    • Spanish
    • Swedish
    • Turkish

Copyright © 2017-2019 Cryptovibes.com. Price data provided by our official partner CoinGecko.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.