Image: Mark Karpelès
The prominent French cryptocurrency hardware wallet manufacturer Ledger recently suffered a severe security breach. In this breach, malicious actors meticulously modified hardware by installing clandestine espionage modules to steal user-configured seed phrases. Currently, the digital assets pillaged by these hackers exceed a staggering 80 million dollars in value. As time progresses, a growing number of user wallets face the imminent threat of being compromised and subsequently drained of their funds.
Hardware Modifications and Screen Monitoring Modules
An incredibly revealing hardware teardown image, published by the former Mt. Gox CEO Mark Karpeles, served as the catalyst for exposing this incident. Upon witnessing Karpeles’ publication, the hackers seemingly concluded that their sophisticated modifications would inevitably attract intense scrutiny. Consequently, they chose to immediately plunder the wallets they had already successfully compromised. Otherwise, had Karpeles not discovered this alarming anomaly, the perpetrators would likely have remained concealed in the shadows. They would have continuously harvested even more sensitive wallet data.
Karpeles meticulously examined a Ledger Nano X unit originating from Malaysia. While the exterior shrink-wrap packaging appeared entirely pristine and untouched, opening the device revealed an extraordinary anomaly. There was an unauthorized, auxiliary circuit board concealed precisely where the screen buffer should reside. In detail, this rogue circuit board featured a microcontroller, an LTE communication module, a miniature antenna, and an eSIM. These components were intricately wired into the Serial Peripheral Interface (SPI) communication link directly associated with the device’s display panel.
Intercepting the Recovery Phrase
The presumed operational mechanism involves covertly eavesdropping on the character data transmitted from the device to the screen. It subsequently utilizes sophisticated recognition logic trained specifically on Ledger’s typography to meticulously reconstruct the on-screen content. When a Ledger device is initialized for the first time, it displays a crucial 24-word recovery phrase on its screen. Under normal circumstances, this phrase is securely generated and displayed entirely internally. In addition, Ledger’s secure element dutifully guards the private keys and executes critical operations.
If attackers can successfully intercept these vital words by bypassing the screen’s communication link and subsequently transmit them via a cellular network, they can effortlessly acquire the complete recovery phrase the moment a user finishes initialization. In the ensuing stages, the hackers require absolutely no physical contact with the original hardware wallet. They can seamlessly utilize any compatible software wallet to restore the purloined seed phrase and seize absolute control over the digital assets residing at the corresponding addresses.
The Clandestine Acquisition of Authorized Reseller CryptoBilis
CryptoBilis functioned as a highly trusted, authorized Ledger distributor operating within the Southeast Asian region. Numerous users preferred purchasing from this vendor rather than ordering directly from Ledger. This was primarily to circumvent the notoriously lengthy shipping delays associated with dispatching products from the French manufacturing facility via standard French postal services. Astonishingly, this particular distributor was secretly acquired as early as March. Furthermore, the acquisition agreement explicitly mandated a strict confidentiality period of at least six months regarding the transaction. This undeniably proves that this was a deeply premeditated, long-term malicious operation.
Current speculation suggests that North Korean cyber operatives orchestrated the covert acquisition of CryptoBilis. The formidable capability to custom-manufacture miniature circuit boards and microcontrollers on a massive scale, followed by their meticulous physical integration into sealed consumer electronics, clearly demonstrates that these are no ordinary criminals. However, a definitive confirmation of the hackers’ true identities remains pending, as Ledger official support and the cybersecurity industry continue exhaustive investigations.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!