The shrink wrap is intact, but the recovery phrase is still exposed.

The former CEO of Mt. Gox took apart a Ledger shipped from Malaysia. Hidden where the screen’s cushioning pad should be were an LTE module, an antenna, and an eSIM. The microcontroller was connected directly to the SPI bus, so once the recovery phrase was generated, it was sent out over the mobile network.

Once attackers have their eye on an address, they can lie low for a long time and strike when the holdings grow. The hardware wallet’s offline-signing defenses were bypassed with a physical implant. Every link at the end of the supply chain deserves scrutiny.

If you own a Ledger, have you checked under the cushioning pad? Do you still dare to use it?

$BTC $ETH #Ledger #Web3