Saudi Press

Saudi Arabia and the world
Tuesday, Jan 13, 2026

Ledger Hack Victims Are Receiving fake Crypto Hardware Wallets

Ledger Hack Victims Are Receiving fake Crypto Hardware Wallets

A new hack is claiming victims following the the Ledger data breach of July 2020. The new scam involves sending convincing but fake hardware wallets to victims.

Bitcoin Magazine’s pseudonymous author ‘Namcios’ covered the recent scam, detailing how it was done step by step and the victims lured in. Here’s the story:

Victims of a hack of customer data held by bitcoin hardware wallet provider Ledger, which happened almost a year ago, are still apparently being targeted by scammers. Over 1 million victims of the hack had their details exposed, including their names, phone numbers and email addresses. And more than 200,000 people also had their home addresses breached.

Now, some of the victims appear to be receiving counterfeit hardware wallets through the mail. And a recent Reddit post indicates that the new scam attempt is quite sophisticated.

Reddit user u/jjrand, who self-identified as one of the victims of last year’s Ledger data breach, shared that they received a package that appeared to be from Ledger in the mail, even though they hadn’t ordered one. Although the device was wrapped in seemingly authentic packaging, the user could spot some telltale signs that hinted that it was a fake. The package also included a letter, supposedly from Ledger CEO Pascal Gauthier, though it was poorly written and filled with grammatical and spelling errors.

“As you know, Ledger was targeted by a cyberattack that led to a data breach in July 2020,” read the fake letter. “For this reason for security purposes, we have sent you a new device you must switch to a new device to stay safe. There is a manual inside your new box you can read that to learn how to set up your new device. For this reason, we have changed our device structure. We now guarantee that this kinda breach will never happen again.”

Also in the package was a Ledger Nano X box that seemingly contained a legitimate device. However, the Reddit user became suspicious and opened it, sharing pictures demonstrating that the machine was likely tampered with.

Security researcher Mike Grover analyzed the photos and explained to BleepingComputer how the attackers probably carried out their actions.

“This seems to be a simple flash drive strapped on to the Ledger with the purpose to be for some sort of malware delivery,” Grover told BleepingComputer in a chat about the photos. “All of the components are on the other side, so I can’t confirm if it is JUST a storage device, but…. judging by the very novice soldering work, it’s probably just an off-the-shelf mini flash drive removed from its casing.”

Grove also explained that “those four wires piggyback the same connections for the USB port of the Ledger.”

Previously, the attackers had sent out phishing emails to victims, prompting them to type in their recovery seeds — the 12 or 24 words used to derive one’s private keys, giving anyone who possesses it complete control of the victim’s funds. By tampering with the device, the attackers likely hoped to get their target to type their recovery words into the fake application, which would allow the bad actors to take control of the victim’s funds.

Therefore, this attack is severe since it could cause a victim to lose all of their funds. Ledger is already aware of this scam and warned users in a post in May.

“The fake user guide in the Nano’s box asks the user to connect the device to a computer,” the post stated. “To initialize the device, the user is then asked to enter his 24 words in a fake Ledger Live application. This is a scam. Do not connect the device to your computer and never share your 24 words. Ledger will never ask you to share your 24-word recovery phrase.”

It is unclear if Ledger has done any active work to educate its customers who saw their data exposed last year with dedicated emails or warnings, apart from the passive blog posts.

Needless to say, under no circumstance should you type your bitcoin wallet seed phrase on any keyboard, take photos of it or have any internet-connected device know about it. The only safe place to store, write and recover a seed phrase is the hardware wallet itself.

MORE ON BITCOIN SEED PHRASES AND PRIVATE KEYS

A seed phrase is a collection of 12 or 24 human-readable words used to generate bitcoin private keys for a wallet. The seed phrase, also known as the recovery phrase or backup phrase, contains all of the information needed to access, spend and recover bitcoin funds. For this reason, the seed phrase has to be kept safe; otherwise, anyone who discovers it can steal the bitcoin.

The private key, which is generated by the seed phrase, is not human readable. It is a secret 256-bit number, usually in hexadecimal format — 64 characters or 32 bytes in the range of zero to nine or A to F.

Modern wallets leverage both seed phrases and private keys to employ Hierarchical Deterministic (HD) Wallets, using BIP32 seeds. HD Wallets allow the wallet to use a single seed phrase to generate a whole sequence of keys, allowing the entire wallet to be restored from that seed.

Source: Ledger Hack Victims Are Receiving fake Hardware Wallets – Fintechs.fi

Newsletter

Related Articles

Saudi Press
0:00
0:00
Close
Trump Designates Saudi Arabia a Major Non-NATO Ally, Elevating US–Riyadh Defense Partnership
Trump Organization Deepens Saudi Property Focus with $10 Billion Luxury Developments
There is no sovereign immunity for poisoning millions with drugs.
Mohammed bin Salman’s Global Standing: Strategic Partner in Transition Amid Debate Over His Role
Saudi Arabia Opens Property Market to Foreign Buyers in Landmark Reform
The U.S. State Department’s account in Persian: “President Trump is a man of action. If you didn’t know it until now, now you do—do not play games with President Trump.”
CNN’s Ranking of Israel’s Women’s Rights Sparks Debate After Misleading Global Index Comparison
Saudi Arabia’s Shifting Regional Alignment Raises Strategic Concerns in Jerusalem
OPEC+ Holds Oil Output Steady Amid Member Tensions and Market Oversupply
Iranian Protests Intensify as Another Revolutionary Guard Member Is Killed and Khamenei Blames the West
President Trump Says United States Will Administer Venezuela Until a Secure Leadership Transition
Delta Force Identified as Unit Behind U.S. Operation That Captured Venezuela’s President
Trump Announces U.S. Large-Scale Strike on Venezuela, Declares President Maduro and Wife Captured
Saudi-UAE Rift Adds Complexity to Middle East Diplomacy as Trump Signals Firm Leadership
OPEC+ to Keep Oil Output Policy Unchanged Despite Saudi-UAE Tensions Over Yemen
Saudi Arabia and UAE at Odds in Yemen Conflict as Southern Offensive Deepens Gulf Rift
Abu Dhabi ‘Capital of Capital’: How Abu Dhabi Rose as a Sovereign Wealth Power
Diamonds Are Powering a New Quantum Revolution
Trump Threatens Strikes Against Iran if Nuclear Programme Is Restarted
Why Saudi Arabia May Recalibrate Its US Spending Commitments Amid Rising China–America Rivalry
Riyadh Air’s First Boeing 787-9 Dreamliner Completes Initial Test Flight, Advancing Saudi Carrier’s Launch
Saudi Arabia’s 2025: A Pivotal Year of Global Engagement and Domestic Transformation
Saudi Arabia to Introduce Sugar-Content Based Tax on Sweetened Drinks from January 2026
Saudi Hotels Prepare for New Hospitality Roles as Alcohol Curbs Ease
Global Airports Forum Highlights Saudi Arabia’s Emergence as a Leading Aviation Powerhouse
Saudi Arabia Weighs Strategic Choice on Iran Amid Regional Turbulence
Not Only F-35s: Saudi Arabia to Gain Access to the World’s Most Sensitive Technology
Saudi Arabia Condemns Sydney Bondi Beach Shooting and Expresses Solidarity with Australia
Washington Watches Beijing–Riyadh Rapprochement as Strategic Balance Shifts
Saudi Arabia Urges Stronger Partnerships and Efficient Aid Delivery at OCHA Donor Support Meeting in Geneva
Saudi Arabia’s Vision 2030 Drives Measurable Lift in Global Reputation and Influence
Alcohol Policies Vary Widely Across Muslim-Majority Countries, With Many Permitting Consumption Under Specific Rules
Saudi Arabia Clarifies No Formal Ban on Photography at Holy Mosques for Hajj 2026
Libya and Saudi Arabia Sign Strategic MoU to Boost Telecommunications Cooperation
Elon Musk’s xAI Announces Landmark 500-Megawatt AI Data Center in Saudi Arabia
Israel Moves to Safeguard Regional Stability as F-35 Sales Debate Intensifies
Cardi B to Make Historic Saudi Arabia Debut at Soundstorm 2025 Festival
U.S. Democratic Lawmakers Raise National Security and Influence Concerns Over Paramount’s Hostile Bid for Warner Bros. Discovery
Hackers Are Hiding Malware in Open-Source Tools and IDE Extensions
Traveling to USA? Homeland Security moving toward requiring foreign travelers to share social media history
Wall Street Analysts Clash With Riyadh Over Saudi Arabia’s Deficit Outlook
Trump and Saudi Crown Prince Cement $1 Trillion-Plus Deals in High-Profile White House Summit
Saudi Arabia Opens Alcohol Sales to Wealthy Non-Muslim Residents Under New Access Rules
U.S.–Saudi Rethink Deepens — Washington Moves Ahead Without Linking Riyadh to Israel Normalisation
Saudi Arabia and Israel Deprioritise Diplomacy: Normalisation No Longer a Middle-East Priority
Saudi Arabia Positions Itself as the Backbone of the Global AI Era
As Trump Deepens Ties with Saudi Arabia, Push for Israel Normalization Takes a Back Seat
Thai Food Village Debuts at Saudi Feast Food Festival 2025 Under Thai Commerce Minister Suphajee’s Lead
Saudi Arabia Sharpens Its Strategic Vision as Economic Transformation Enters New Phase
Saudi Arabia Projects $44 Billion Budget Shortfall in 2026 as Economy Rebalances
×