Rebuilt from scratch. Scan withyour iPhone to try it on TestFlight
Five stories the community upvoted most, every Sunday. No spam, unsubscribe anytime. What's in it?
This is the spy SIM card, a 2x2mm chip, making it a bit of a pain to tap. More details to come (provider, etc).
they didn’t hack ledger. they didn’t exploit the code. they BOUGHT the company selling you the device. $86 million gone a company called CryptoBilis was an authorized ledger reseller in southeast asia. trusted. legit. sold ledgers for years a random chinese company quietly bought CryptoBilis from its malaysian owner made the original owner sign a confidentiality agreement. he couldn’t tell anyone the company was sold same brand name. same website. same “authorized reseller” badge. but different people behind it now the new owners started opening every ledger device before shipping soldered a tiny spy chip onto the board inside. repackaged it. sealed the box. shipped it the device looked normal. felt normal. worked normal but the spy chip was silently capturing your private keys the moment you set it up your seed phrase was sent to the attacker before you even finished writing it down hundreds of wallets across ethereum tron and bitcoin. all drained the guy who lost $5.3 million said “i did everything right. no leverage. no memecoins. i stored my funds on a hardware wallet like we’re all told to” he was right. he did everything right except his device had a parasite inside it that he couldn’t see ledger has now told CryptoBilis to stop all sales. told recent buyers NOT to set up their devices mark karpelès posted photos of the implant. normal board on top. spy chip below the most dangerous attack in crypto this year wasn’t a line of code it was a business acquisition
here's how hackers steal your crypto from tampered Ledgers. they attach a small hardware implant to the wires connecting Ledger's secure chip to the OLED display. basically, anything displayed on the screen can also be read by the hidden chip. so when your 24-word seed phrase appears during setup, the implant captures it and stores it. then a built-in 4G modem and eSIM transmit that phrase to the attacker, completely independently of your computer. the craziest part is that the device can still pass Ledger's authenticity check because the original secure chip is genuine. and fun fact: some people even buy these fake Ledgers just to extract the eSIM and use it for free mobile data lmao
Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices. W…
Just realized why the Ledger Nano X implants using nRF91 (LTE-M / NB-IoT) are quietly brilliant: A 24-word seed is around 250 bytes. That’s not a data constraint for these radios instead it’s their sweet spot. NB-IoT/LTE-M were built for tiny, infrequent messages. One short transmission, low power, blends into normal IoT traffic. No high-bandwidth connection needed. The same limitation that makes them useless for bulk data makes them perfect for quietly walking off with a seed. The interesting part isn’t that someone added cellular. It’s that they picked a radio whose design goals align almost perfectly with the attack and nobody is speaking about the type of the modem.
“Buy crypto“ has begun trending worldwide on @Google Bull market has begun.
I hate this so much. The top Google result (an ad) leads to a well-made scam version of @safe. Given how often legitimate crypto projects get suspended from ad programs, fkn @Google still happily sells its top spot to scammers after all these years.