A Brazil-based security researcher exposes a counterfeit Ledger Nano S+ operation using malicious firmware and fake apps to drain wallets across 20 blockchains.A Brazil-based security researcher exposes a counterfeit Ledger Nano S+ operation using malicious firmware and fake apps to drain wallets across 20 blockchains.

Counterfeit Ledger Nano S+ Drains Wallets Across 20 Chains

2026/04/18 07:59
4 min read
For feedback or concerns regarding this content, please contact us at [email protected]

A Brazil-based security researcher exposes a counterfeit Ledger Nano S+ operation using malicious firmware and fake apps to drain wallets across 20 blockchains.

A Brazil-based security researcher has exposed one of the most sophisticated counterfeit Ledger Nano S+ operations ever documented. The fake device, sourced from a Chinese marketplace, carried custom malicious firmware and a cloned app. The attacker immediately stole every seed phrase that users entered.

Counterfeit Ledger Nano S+ Drains Wallets Across 20 Chains

The researcher bought the device on suspicion of price irregularities. Upon opening it, the counterfeit nature was obvious. Instead of discarding it, a full teardown followed.

What Was Hidden Inside the Chip

The genuine Ledger Nano S+ uses an ST33 Secure Element chip. This device had an ESP32-S3 instead. The chip markings were physically sanded down to block identification. The firmware identified itself as “Ledger Nano S+ V2.1” — a version that does not exist.

Investigators found seeds and PINs stored in plain text after conducting a memory dump. The firmware beaconed to a command-and-control server at kkkhhhnnn[.]com. Any seed phrase entered into this hardware was exfiltrated instantly.

The device supports roughly 20 blockchains for wallet draining. That is not a minor operation.

Five Attack Vectors, Not One

The seller bundled a modified “Ledger Live” app with the device. The developers built the app with React Native using Hermes v96 and signed it with an Android Debug certificate. The attackers did not bother obtaining a legitimate signature.

The app hooks into XState to intercept APDU commands. It uses stealthy XHR requests to pull data out silently. Investigators identified two additional command-and-control servers: s6s7smdxyzbsd7d7nsrx[.]icu and ysknfr[.]cn.

This is not limited to Android. The same operation distributes a .EXE for Windows and a .DMG for macOS, resembling campaigns tracked by Moonlock under AMOS/JandiInstaller. An iOS TestFlight version also circulates, bypassing App Store review entirely — a tactic tied previously to CryptoRom scams. Five vectors total: hardware, Android, Windows, macOS, iOS.

The Genuine Check Cannot Save You Here

Ledger’s official guidance confirms that genuine devices carry a secret cryptographic key set during manufacturing. The Ledger Genuine Check in Ledger Wallet verifies this key each time a device connects. According to Ledger’s support documentation, only a genuine device can pass that check.

The problem is straightforward. A compromise during manufacturing renders any software check useless. The malicious firmware mimics enough of the expected behavior to proceed past basic checks. The researcher confirmed this directly in the teardown.

Past supply chain attacks targeting Ledger users have repeatedly shown that packaging-level verification alone is insufficient. Documented cases on BitcoinTalk record individual users losing over $200,000 to fake hardware wallets from third-party marketplaces.

Where These Devices Are Being Sold

Third-party marketplaces are the primary distribution channel. Amazon third-party sellers, eBay, Mercado Livre, JD, and AliExpress all have documented histories of listing compromised hardware wallets, the researcher noted in the Reddit post on r/ledgerwallet.

The price point is deliberately suspicious. That is the lure. A non-official source doesn’t offer a discounted Ledger as a deal—it sells a compromised product to benefit the attacker.

Ledger’s official channels are its own e-commerce site at Ledger.com and verified Amazon stores across 18 countries. Nowhere else carries any guarantee of authenticity.

What the Researcher Is Doing Next

The team prepared a comprehensive technical report for Ledger’s Donjon team and its phishing bounty program, and it will release the full write-up after Ledger completes its internal analysis.

The researcher has made IOCs available to other security professionals through direct messages. Anyone who purchased a device from a questionable source can reach out for identification assistance.

The key red flags remain simple. A pre-generated seed phrase included with the device is a scam. Documentation asking users to type a seed phrase into an app is a scam. Destroy the device immediately in either case.

The post Counterfeit Ledger Nano S+ Drains Wallets Across 20 Chains appeared first on Live Bitcoin News.

Market Opportunity
Based Logo
Based Price(BASED)
$0.115
$0.115$0.115
-9.56%
USD
Based (BASED) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

CME Group to launch Solana and XRP futures options in October

CME Group to launch Solana and XRP futures options in October

The post CME Group to launch Solana and XRP futures options in October appeared on BitcoinEthereumNews.com. CME Group is preparing to launch options on SOL and XRP futures next month, giving traders new ways to manage exposure to the two assets.  The contracts are set to go live on October 13, pending regulatory approval, and will come in both standard and micro sizes with expiries offered daily, monthly and quarterly. The new listings mark a major step for CME, which first brought bitcoin futures to market in 2017 and added ether contracts in 2021. Solana and XRP futures have quickly gained traction since their debut earlier this year. CME says more than 540,000 Solana contracts (worth about $22.3 billion), and 370,000 XRP contracts (worth $16.2 billion), have already been traded. Both products hit record trading activity and open interest in August. Market makers including Cumberland and FalconX plan to support the new contracts, arguing that institutional investors want hedging tools beyond bitcoin and ether. CME’s move also highlights the growing demand for regulated ways to access a broader set of digital assets. The launch, which still needs the green light from regulators, follows the end of XRP’s years-long legal fight with the US Securities and Exchange Commission. A federal court ruling in 2023 found that institutional sales of XRP violated securities laws, but programmatic exchange sales did not. The case officially closed in August 2025 after Ripple agreed to pay a $125 million fine, removing one of the biggest uncertainties hanging over the token. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/cme-group-solana-xrp-futures
Share
BitcoinEthereumNews2025/09/17 23:55
Zelenskyy warns Russia aims to involve Belarus in Ukraine conflict

Zelenskyy warns Russia aims to involve Belarus in Ukraine conflict

The post Zelenskyy warns Russia aims to involve Belarus in Ukraine conflict appeared on BitcoinEthereumNews.com. Zelenskyy said Russia is trying to draw Belarus
Share
BitcoinEthereumNews2026/04/18 11:12
Bitcoin, Gold, and U.S. Stocks Dive as Trump Pledges to Hit Iran ‘Extremely Hard’

Bitcoin, Gold, and U.S. Stocks Dive as Trump Pledges to Hit Iran ‘Extremely Hard’

The post Bitcoin, Gold, and U.S. Stocks Dive as Trump Pledges to Hit Iran ‘Extremely Hard’ appeared on BitcoinEthereumNews.com. In brief Bitcoin dropped Thursday
Share
BitcoinEthereumNews2026/04/02 17:57

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!