Ledger Discovers Suspected Tampered Hardware in Crypto Theft Investigation

icon币界网
Share
AI summary iconSummary
Ledger, a leading crypto hardware wallet company, has discovered a tampered foreign component in one of its devices linked to thefts. The suspect hardware was traced to CryptoBilis, an authorized distributor in Southeast Asia. Ledger has suspended sales through this distributor and is cooperating with authorities. The incident could hinder CFT efforts, as compromised devices may be used to facilitate illicit fund transfers. MiCA regulations may also necessitate stricter oversight of hardware supply chains. Former Mt. Gox CEO Mark Karpelès confirmed the tampering after analyzing the suspect component.
CoinDesk reports:

The hardware wallet company Ledger discovered a disturbing detail during its investigation into a suspected cryptocurrency theft: at least one hardware device had been inserted with a suspicious external hardware component.

Ledger's latest update, released on October 10, stated that it discovered this suspicious hardware on a device belonging to an affected user. The device originated from the recent CryptoBilis security incident. CryptoBilis is an authorized distributor in Southeast Asia.

This is the first concrete evidence discovered during the investigation indicating that hardware has been tampered with, suggesting that some Ledger wallets may have been secretly altered before reaching users.

It is currently unclear whether this implant is related to the alleged thefts or how many devices may have been affected.

In addition, Ledger stated that, as a precautionary measure, CryptoBilis has suspended the sale of all hardware wallets until the investigation is complete.

Ledger also stated that the company is maintaining contact with affected users and cooperating with law enforcement to track down those involved.

This suspected attack is particularly concerning because the attackers may not even need to compromise the secure element—the chip inside Ledger devices used to generate and protect private keys. The alleged malicious hardware is said to be designed to intercept communication lines between different components and the screen within the wallet.

Former Mt. Gox CEO investigates mysterious spy implant

While Ledger investigates the allegedly mysterious hardware, Mark Karpelès, former CEO of the now-defunct cryptocurrency exchange Mt. Gox, is also examining these suspicious devices found in Ledger wallets.

On October 10, Karpelès posted that he had independently identified these hardware modifications, as he was reviewing images sent to him by affected users.

“I also confirmed this from the images sent to me by affected users,” Karpelès said on X.

He encouraged those who own these devices and are willing to donate them for analysis to contact him directly.

In a subsequent update, Karpelès stated that he had actually disassembled a suspicious hardware component found in a hardware wallet for analysis.

“Dissecting a spy implant inside a crypto wallet was probably the most cyberpunk thing I’ve done this year,” he joked.

Previously, Karpelès reported that a Ledger Nano X device he inspected, which originated from Malaysia, contained a hidden electronic component, despite still appearing to be in its original shrink-wrapped packaging.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.