LEDGER has disclosed a severe security breach affecting Ledger hardware wallets, described as a targeted tampering operation that involved hiding clandestine hardware within devices. The attackers allegedly installed an extra circuit board with a microcontroller, LTE module, antenna and an eSIM, integrated into the SPI link to the display.
The published teardown image and accompanying analysis claim the modification enables the interception of on-screen data as users initialise their wallets, potentially allowing an attacker to reconstruct the 24-word recovery phrase by analysing the typographic rendering shown on the device screen. If the recovery phrase is captured during initialisation, it could be used in a software wallet to restore control of the associated funds without any physical access to the original Ledger unit.
The investigation highlights a second element of the breach: the unauthorised acquisition of an authorised Ledger distributor, CryptoBilis, operating in South-East Asia. Ledger says CryptoBilis was secretly acquired earlier this year under conditions including a confidentiality period, suggesting a long‑running, premeditated operation. While some speculation points to North Korean actors, the article notes that Ledger and the cybersecurity community have yet to confirm the attackers’ identities.
Reported impact estimates in the piece place losses at more than USD 80 million, with a growing risk to additional wallets as investigations continue. The piece emphasises that compromised seeds could be restored using compatible wallets, underscoring a need for ongoing, verifiable disclosures from Ledger as findings evolve.