SlowMist Analyzes Ledger Hardware Implant Attack: Malicious Module May Steal Mnemonics via Screen Data Cable

iconKuCoinFlash
Share
AI summary iconSummary
This week’s inflation data has reignited pressure on crypto markets, with on-chain metrics showing increased withdrawals from exchanges. As reported by Blockbeats, on October 10, SlowMist Security’s CISO, 23pds, explained that if Ledger devices’ PCBs were tampered with, as claimed by former Mt. Gox CEO Mark Karpelès, attackers would require advanced technical expertise. The method could involve a malicious module capturing display data through the screen’s data line—such as SPI—to steal full mnemonics. The stolen data could then be transmitted to hackers via LTE/eSIM, posing a risk of asset loss. While secure elements prevent direct access to private keys, they cannot prevent screen data from being intercepted. This analysis assumes the PCB modifications occurred as described; however, the attack vector and hardware tampering remain unverified by third parties.

BlockBeats news, on October 10, SlowMist Chief Information Security Officer 23pds posted that if the modification of the Ledger device's PCB is indeed as described by former Mt. Gox CEO Mark Karpelès, then the attacker would possess a very high level of technical expertise.


The attack process may be as follows: the wallet generates the mnemonic phrase within the secure element (SE), then displays it on the screen for the user to manually record; a malicious module intercepts the displayed content via SPI or other screen data lines, captures the complete mnemonic phrase, and transmits the data to the attacker via LTE/eSIM, ultimately resulting in the theft of the user’s assets.


The secure element prevents private keys from being directly read or exported, but it cannot prevent external modules from capturing information displayed on the screen. However, the above analysis assumes that the PCB has indeed been modified as described; the related attack vectors and hardware tampering require independent verification.


BlockBeats reported yesterday that Mark Karpelès, former CEO of Mt. Gox, disclosed in a post that a Ledger hardware wallet he received appears to have been implanted with a spy module. The device originated from Malaysia; the outer shrink-wrap packaging was intact, and the tampering was difficult to detect upon opening, as the implant was concealed in the location where the screen’s original cushioning should have been.


Karpelès further explained that the module includes an LTE communication component, an antenna, an eSIM, and a microcontroller connected to the Ledger SPI bus, which analyzes the characters displayed on the device and transmits relevant data after the mnemonic phrase has been set up.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.