A Brazilian researcher surfaced a counterfeit Ledger Nano S Plus selling at legitimate prices on a Chinese marketplace — the device contains embedded WiFi and Bluetooth antennas (real Ledgers stay fully offline) and firmware listing Shanghai's Espressif Systems as manufacturer. A QR code in the box routes buyers to a malicious Ledger Live clone that passes its own fake Genuine Check, then captures seed phrases for drain-on-demand theft. Earlier this year a fake Ledger Live on Apple's App Store drained $9.5M from 50+ users before removal — same playbook, different vector.

TLDR by @Benthic

More on Ledger

Comments