The cold wallet screen became a data-leak point

SlowMist says the modified device copied the seed phrase via the screen’s SPI bus, then sent it back over LTE/eSIM. The device Karpelès received came from Malaysia. Its shrink-wrap was intact, and the module was hidden where the screen’s cushioning pad sits.

A secure element can’t stop screen content from being copied. Buyers bear all the risks of modifications made through unofficial channels, so it’s time to reassess the trust we place in hardware wallets.

Still have a secondhand or reseller-sourced Ledger? Would you dare to keep a large amount on it?

$BTC $ETH $SOL #Ledger #WalletSecurity