律动BlockBeats
律动BlockBeats|10月 10, 2026 01:11
[SlowMist Analysis of Suspected Hardware Implant Attack on Ledger: Malicious Module May Steal Mnemonic via Screen Data Line] BlockBeats News, October 10, SlowMist Security Chief Information Security Officer 23pds published an article stating that if the modification of the Ledger device PCB is indeed as described by former Mt. Gox CEO Mark Karpelès, then the attackers possess a very high level of technical expertise. The attack process might be as follows: the wallet generates the mnemonic within the Secure Element (SE) and then displays the mnemonic on the screen for the user to write down; the malicious module intercepts the displayed content via screen data lines such as SPI, records the complete mnemonic, and then transmits the data to the attacker via LTE/eSIM, ultimately leading to the theft of user assets. The Secure Element is designed to prevent private keys from being directly read or exported, but it cannot stop external modules from capturing information displayed on the screen. However, the above analysis is based on the premise that the PCB has indeed been modified as described, and the related attack path and hardware implant situation still require independent verification. BlockBeats previously reported that former Mt. Gox CEO Mark Karpelès disclosed that a Ledger hardware wallet he received appeared to have a spy module implanted. The device originated from Malaysia, with its outer packaging shrink wrap intact, and abnormalities were not immediately apparent upon opening. The implant was hidden in the position where the screen's original buffer pad should have been. Karpelès further explained that the module contained LTE communication components, an antenna, an eSIM, and a microcontroller connected to the Ledger SPI bus, capable of analyzing characters displayed to the user by the device and sending the relevant data after the mnemonic setup is completed. [Original Link]
Share To

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads