https://www.samanthapayne.ky/situs-judi-slot-jackpot-terbesar/

https://www.mnrconstructions.com.au/slot-gacor/

https://www.beselectrical.com.au/situs-judi-slot-online-jackpot-terbesar/

https://bagliography.com/slot-gacor/

https://www.ppqro.com/slot-gacor/

https://foropokemongo.net/slot-online/

https://dozaleather.vn/link-slot-gacor/

https://www.dealbasic.ca/situs-slot-gacor-hari-ini/

https://tagorecoaching.com/situs-judi-slot-terbaik-dan-terpercaya-no-1/

https://www.divinejoyyoga.com/slot-gacor/

https://www.alandesignstudio.com/situs-judi-slot-terbaik-dan-terpercaya/

https://tagorecoaching.com/slot-gampang-menang/

https://www.elmuseodelrecambio.es/wp-content/slot-gacor/

https://www.readygunner.com/wp-content/uploads/slot-gacor/

https://mysticsoapandcandles.com/slot-gacor/

https://www.carmenrussocosmetici.it/wp-includes/slot-gacor/

https://millersoils.nl/wp-content/uploads/slot-gacor/

https://sportventuregroup.com/wp-content/uploads/slot-gacor/

https://mirmidones.gr/slot-gacor-hari-ini/

https://nexarkagroup.com/wp-includes/slot-gacor-maxwin/

https://viasolimoveis.com.br/wp-includes/slot-gacor/

https://milliesdoggystore.com/wp-includes/slot-gacor/

https://www.silentmarriage.com/judi-slot-online-jackpot-terbesar/

Alert: Modified hardware wallets spotted in the wild – Fyifli
Sunday, May 29, 2022
  • Home
  • Cryptocurrency
  • Entrepreneurship
  • Finance
  • Financial Literacy
  • Investing
No Result
View All Result
No Result
View All Result
Home Cryptocurrency

Alert: Modified hardware wallets spotted in the wild

admin by admin
June 24, 2021
in Cryptocurrency
0
Alert: Modified hardware wallets spotted in the wild
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

Last week someone on the Ledger subreddit reported receiving an unsolicited package with a Ledger Nano X along with a  letter from “the CEO” of Ledger. The scam tries to trick people into migrating their crypto holdings onto the new, modified device. Kraken Security Labs decided to explore this supposed phishing scam.

In the video above, our security team demonstrates how this scam was supposed to play out and, as with previous Ledger phishing attacks, will explain how best to avoid these attacks from happening to you. 

As an important note, there are no flaws with the Ledger wallet or its firmware. The purpose of the video and blog is to simply increase awareness about this phishing attack, as this is often the single-best way to prevent crypto holders falling victim to these attempts. 

The Letter and Device

The package was delivered in what appeared to be official Ledger shrink wrapping. But after opening the package, the recipient spotted an immediate red flag. The letter, which was purportedly from Ledger CEO Pascal Gauthier, was in poorly-written English and had errors throughout; hardly consistent with the communication clients usually receive from companies. 

Having already heard about Ledger falling victim to a data breach in the past, the recipient felt increasingly suspicious. They decided to take the Ledger apart and posted pictures of the insides on Reddit. The community quickly discovered that a tiny USB stick had been secretly implanted into the device. Once plugged into a computer, the device would appear as a USB stick, containing a malicious application attempting to phish the user’s seed

You can also check out Bleepingcomputer’s full writeup of the attack here.

Rebuilding The Attack   

Kraken Security Labs has rebuilt the attack to demonstrate how this highly sophisticated, real-world phishing attack works, so clients are prepared in case anyone should ever attempt this on them.

The implant: A simple USB stick

Kraken Security Labs ordered a Ledger Nano X wallet online. Once received, we used a simple tiny USB-stick as an implant, extracted from a promotional gift. After removing some padding, the USB stick fitted perfectly underneath the display of the wallet.

The USB stick attached to the USB lines of the Ledger Nano X.

Next, just like the original attacker, we used magnet wire to connect the contacts of the USB-stick to the USB data-lines on the original wallet’s Printed Circuit Board (PCB), which connects all the device’s electrical components together.

To prevent conflicts between the USB-stick and the Ledger CPU we had to make additional modifications. Hardware security expert Mike Grover highlighted that the attackers had removed an oscillator – a component which basically allows the device to keep time – to prevent the CPU from interfering with the USB-stick. Our testing found that removing that component would disable the device, making the attack more conspicuous. Kraken Security Labs performed a slightly different modification so the wallet would work normally and would therefore raise less suspicion. This included allowing regular connections to the wallet via bluetooth.  Additionally we found that the attackers performed further hardware modifications to make the USB connection work.

From the outside, it’s virtually impossible to distinguish a genuine Ledger wallet from a backdoored one. The USB-stick is hidden below the display, and the tiny wires connect it to the Ledger PCB. When plugged in, the wallet will boot, charge its battery, and appear like a completely unmodified Ledger.

When the device is plugged into a computer, it will appear as a USB stick, containing only a phony “Ledger Live” application that will try to trick the victim into entering their seed phrase, which will enable the attackers to drain funds from their wallet.

Can you tell which Ledger is modified?

Reminder

When utilizing a hardware wallet, always make sure you order directly from the vendor and check that the packaging, including the cellophane wrapping, has not been tampered with. 

If you are ever in doubt, contact the wallet vendor directly or speak to someone through the official support portal.

Stay up-to-date with the latest security alerts and best practices with Kraken Security Labs.

Like this:

Like Loading…

Previous Post

100+ Words of Encouragement for a Better Mental Health

Next Post

Federal Student Loans For Expats

admin

admin

Next Post
Federal Student Loans For Expats

Federal Student Loans For Expats

Discussion about this post

No Result
View All Result

Recent Posts

  • Expressing something | Seth’s Blog
  • Ben Shapiro and Candace Owens are good at blasting and revisiting lies the radical left fed Americans.
  • Japan crypto exchange bitbank signs MOU to form institutional blockchain investment company » CryptoNinjas
  • Ethereum Slips, What Are The Next Vital Trading Levels For The Coin?
  • 4 Growth Industries In The Post-Pandemic World

Recent Comments

    Archives

    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • May 2012
    • April 2010

    Categories

    • Cryptocurrency
    • Entrepreneurship
    • Finance
    • Financial Literacy
    • Investing
    • Uncategorized

    Meta

    • Register
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    Categories

    • Cryptocurrency
    • Entrepreneurship
    • Finance
    • Financial Literacy
    • Investing
    • Uncategorized

    Tags

    Slot Bonus New Member 100 di awal
    • Contact Us
    • Privacy Policy

    Copyright © 2021 - Fyifli.com

    No Result
    View All Result
    • Home
    • Cryptocurrency
    • Entrepreneurship
    • Finance
    • Financial Literacy
    • Investing

    Copyright © 2021 - Fyifli.com

    Slot Terbaru

    https://concealedrights.com/

    https://alayziahwarttreatment.com/

    Link Slot

    https://redlighttherapy.co.za/

    https://www.republicanmatters.com/

    https://zdoc.us/

    Slot Anti Boncos