Slow Fog Analysis suggests hardware implantation to steal mnemonic phrases from Ledger
The Chief Information Security Officer of Slow Mist Security, 23pds, stated that if the modification of the Ledger device's PCB is indeed as described by former Mt. Gox CEO Mark Karpelès, the attacker would possess a considerable level of technical skill.
23pds mentioned that the possible attack process involves the wallet generating a mnemonic phrase within a secure element and displaying it on the screen for the user to write down. A malicious module could obtain the displayed content through screen data lines such as SPI, record the complete mnemonic phrase, and then send the data to the attacker via LTE/eSIM. The secure element can prevent the private key from being directly read or exported, but it cannot stop external modules from accessing the information currently displayed on the screen. He noted that the above analysis is based on the premise that the PCB has indeed been modified in the described manner, and the relevant attack paths and hardware implantation still require independent verification.
Mark Karpelès previously stated that a Ledger hardware wallet he received was suspected of being implanted with a spy module. The device came from Malaysia, the outer packaging was intact with shrink wrap, and the implant was hidden in the position where the screen originally had a cushion, containing LTE communication components, an antenna, eSIM, and a microcontroller connected to the Ledger SPI bus, capable of analyzing the characters displayed to the user and sending relevant data after the mnemonic phrase setup is completed.






