Foresight News reports: 23pds, Chief Information Security Officer at SlowMist, tweeted that if, as former Mt. Gox CEO Mark Karpelès said, the modification to the Ledger was made on the PCB, it would be a sophisticated technique. 23pds speculated that the process was as follows: the seed is generated inside the secure element, and the recovery phrase is displayed on the screen. A malicious module taps into the screen’s data lines (such as SPI) and records the displayed words. Once it has collected them all, it sends them via LTE or eSIM. The attacker can then use the recovery phrase to transfer the assets.
Previously, former Mt. Gox CEO Mark Karpelès tweeted that a Ledger hardware wallet he received appeared to have been implanted with a spy module. The device came from Malaysia, and its outer shrink wrap was intact. The anomaly was also difficult to spot immediately after opening it, as the implant was concealed where the screen’s cushioning pad should have been. The module contained an LTE communications component, an antenna, an eSIM, and a microcontroller connected to Ledger’s SPI bus. It could analyze the characters displayed to the user and send the relevant data after the recovery phrase was set up. The attacker could monitor the victim’s wallet address and transfer the assets at a chosen time.
