Rebuilt from scratch. Scan withyour iPhone to try it on TestFlight
Five stories the community upvoted most, every Sunday. No spam, unsubscribe anytime. What's in it?
PSA the ledger incident isn't limited to Asia This is a device purchased in store from an official reseller in Europe (a legitimate device doesn't have any of these cables as can be seen in picture 2) This even seems to be an old version of the 'spy implant' even though the device was purchased a couple of weeks ago. The newer versions usually hide the implant by the screen so it's easier to miss What's interesting is that this compromised ledger never transfered funds to an exploiter. Either the device didn't work or they were waiting for a more widespread usage of the comprised devices? If you own a ledger that didn't directly come from the ledger online store make sure to not just rely on the software genuinely check by ledger but to actually open up the ledger yourself to make sure its original, again there are reported cases in Asia, south America and now Europe as well. @MagicalTux made some useful videos on how to open the ledger and what to look for.
I hate this so much. The top Google result (an ad) leads to a well-made scam version of @safe. Given how often legitimate crypto projects get suspended from ad programs, fkn @Google still happily sells its top spot to scammers after all these years.
This is the spy SIM card, a 2x2mm chip, making it a bit of a pain to tap. More details to come (provider, etc).
they didn’t hack ledger. they didn’t exploit the code. they BOUGHT the company selling you the device. $86 million gone a company called CryptoBilis was an authorized ledger reseller in southeast asia. trusted. legit. sold ledgers for years a random chinese company quietly bought CryptoBilis from its malaysian owner made the original owner sign a confidentiality agreement. he couldn’t tell anyone the company was sold same brand name. same website. same “authorized reseller” badge. but different people behind it now the new owners started opening every ledger device before shipping soldered a tiny spy chip onto the board inside. repackaged it. sealed the box. shipped it the device looked normal. felt normal. worked normal but the spy chip was silently capturing your private keys the moment you set it up your seed phrase was sent to the attacker before you even finished writing it down hundreds of wallets across ethereum tron and bitcoin. all drained the guy who lost $5.3 million said “i did everything right. no leverage. no memecoins. i stored my funds on a hardware wallet like we’re all told to” he was right. he did everything right except his device had a parasite inside it that he couldn’t see ledger has now told CryptoBilis to stop all sales. told recent buyers NOT to set up their devices mark karpelès posted photos of the implant. normal board on top. spy chip below the most dangerous attack in crypto this year wasn’t a line of code it was a business acquisition
Just realized why the Ledger Nano X implants using nRF91 (LTE-M / NB-IoT) are quietly brilliant: A 24-word seed is around 250 bytes. That’s not a data constraint for these radios instead it’s their sweet spot. NB-IoT/LTE-M were built for tiny, infrequent messages. One short transmission, low power, blends into normal IoT traffic. No high-bandwidth connection needed. The same limitation that makes them useless for bulk data makes them perfect for quietly walking off with a seed. The interesting part isn’t that someone added cellular. It’s that they picked a radio whose design goals align almost perfectly with the attack and nobody is speaking about the type of the modem.
“Buy crypto“ has begun trending worldwide on @Google Bull market has begun.
The nRF9151 in the latest Ledger Nano X implant supports full bidirectional LTE-M/NB-IoT plus a Cortex-M33, 1 MB flash, and SPI. That means it could do more than just upload seeds. Could it receive commands, firmware updates, or selective triggers? And why the second unmarked MCU if the Nordic already has application processing? Firmware analysis is still pending, but one thing is clear: this was engineered for deployment at scale, not as a one-off implant.