SlowMist CISO speculates on the attack path for compromised Ledger devices: covert screen recording of mnemonic phrases followed by exfiltration.
According to disclosures by SlowMist Security Team CISO 23pds (@im23pds), researchers have indicated that Ledger hardware wallets may be susceptible to a PCB-level supply chain attack. The attack works by implanting a malicious module on the device’s screen data cable (such as the SPI bus) to passively monitor and record the mnemonic display process. The mnemonics are then forwarded to attackers via LTE/eSIM, allowing them to drain user assets. Since this spy module only performs passive read-only operations and does not interact with the firmware or Secure Element (SE), the device’s power-on self-test cannot detect any anomalies. The actual compromised security boundary is the plaintext bus between the MCU and the screen. To date, Ledger has officially launched an investigation into user fund loss incidents in Southeast Asia. The affected devices are suspected to be connected to Malaysian distributor CryptoBilis; Ledger has ordered it to halt all sales and shipments and has advised users to await official updates on the investigation.