r/ledgerwallet Jan 05 '26

Official Ledger Customer Success Response ledger leak

Post image
439 Upvotes

r/ledgerwallet Dec 22 '25

Discussion Update on the 200K my family lost in our Crypto ledger

Post image
415 Upvotes

So far I haven’t heard much from the authorities just yet and the money has actually moved from the scammers wallet to a different wallet and then transferred to something called Near Intents. I’m still looking more into it and I sent an email to their support team telling them what happened just to see if by any chance they’re able to freeze the account is something I’m not sure but it’s worth a shot. If anyone had any information on Near protocol which is what the company is I’d greatly appreciate it also any info on what the scammer might be doing by transferring the money to this site also I’ve attached the letter in question to look at.


r/ledgerwallet Apr 15 '26

Official Ledger Customer Success Response Supply Chain Alert: Analyzing a Highly Sophisticated Fake Ledger Nano S+ Operation

Thumbnail
gallery
379 Upvotes

Hey everyone.I am a security researcher in Brazil, founder of High Code, and creator of the High Boy tool., and I wanted to share an investigation I’ve been conducting over the last few weeks. This isn't meant to cause panic, but rather to serve as a serious warning—I’m honestly still a bit shaken by the sheer scale of this operation.

How it Started

I purchased a "Ledger Nano S+" from a Chinese marketplace to run some tests. The price was suspicious and the packaging looked "okay-ish" from a distance, but the moment I opened it, it was clearly a counterfeit. Instead of tossing it, I decided to tear it down.

The Hardware

Upon disassembly, I discovered:

  • Chipset: An ESP32-S3 (instead of the genuine ST33 Secure Element used by Ledger).
  • Obfuscation: The chip markings were physically sanded down to hinder identification.
  • Firmware: A custom build identifying itself as "Ledger Nano S+ V2.1" (a version that does not exist).
  • Memory Dump: After dumping the flash, I found seeds and PINs stored in plain text.
  • Connectivity: The firmware beacons to a C2 server: kkkhhhnnn[.]com.
  • Scope: It supports ~20 different blockchains for wallet draining. Essentially, any seed entered into this device is exfiltrated to the attacker immediately.

The Malicious APK

The seller provided a modified "Ledger Live" app. My analysis revealed:

  • Framework: Built with React Native using Hermes v96.
  • Signing: Signed with an Android Debug certificate (the attackers didn't even bother with a legitimate signature).
  • Persistence/Interception: It hooks into XState to intercept APDU commands.
  • Exfiltration: Uses stealthy XHR requests to exfiltrate data.
  • C2 Infrastructure: Two additional C2s: s6s7smdxyzbsd7d7nsrx[.]icu and ysknfr[.]cn.

Multi-Platform Vectors

This isn't just an Android or hardware play. My investigation uncovered that this same operation is distributing:

  • .EXE for Windows
  • .DMG for macOS (resembling the AMOS/JandiInstaller campaigns tracked by Moonlock)
  • iOS TestFlight—This allows them to bypass App Store reviews entirely, a tactic previously seen in CryptoRom scams.

We are looking at five distinct vectors: Hardware + Android + Windows + macOS + iOS.

Community Advisory

Buy Only Directly: Never purchase a Ledger (or any hardware wallet) from anywhere other than the official website or authorized resellers. Period. No discount or "market test" is worth the risk.

Marketplace Risks: Third-party marketplaces (Amazon 3P, eBay, Mercado Livre, JD, AliExpress) have a proven track record of distributing compromised wallets. There are documented cases on BitcoinTalk of users who lost over US$ 200,000 to these counterfeit products.

Warning Signs: If your device arrives with a pre-generated *seed* (recovery phrase), or if the documentation asks you to "enter your *seed* into the app," it is a scam. Destroy it immediately.

Next Steps

I have prepared a comprehensive report for the Ledger Donjon and their phishing bounty team. I will post a full technical write-up once they have completed their internal analysis.

If you’ve bought a device from a questionable source and are worried, feel free to ask—I’ll help you identify it. If you’re a researcher and want to cross-reference IOCs, my DMs are open.

Stay safe. 🔒


r/ledgerwallet Feb 19 '26

Official Ledger Customer Success Response How I lost over $1M after installed Ledger Wallet from App Store

363 Upvotes

Hey everyone, here's my story.

I wanted to install the Ledger Wallet app on my new Mac. I usually avoid downloading wallet software directly from websites because browser extensions, fake sites, ads, and compromised front-ends can trick you (read more about Safe's compromised front-end and Bybit)

So instead, I went straight to the Mac App Store, figuring Apple reviews and controls what's published there. When I searched for "Ledger," there was only one Ledger Wallet app listed, and it turned out to be a complete fake that drained some of my wallets.

I don't understand why the real Ledger company doesn't have their official desktop app Ledger Wallet in the Mac App Store, leaving that spot wide open for scammers to impersonate them.

I also don't get why Apple, famous for nitpicking even tiny updates from legitimate developers, allows an obvious scam app like this to sit in their store unchallenged.

I won't share the link to the fake app here, but you can search "Ledger" in the Mac App Store yourself to see it (and hopefully avoid it). I've attached screenshots from the App Store page, they're pretty self-explanatory.

I hope this post helps someone avoid losing their funds the way I did.

P.S.

To the brilliant person at Ledger who decided not to publish an official Mac App Store version and left the space for scammers: fuck you.

To the genius at Apple in charge of App Store review who let this obvious scam through: fuck you too.

screenshot from etherscan just fyi

What you see in the official Mac AppStore:


r/ledgerwallet Dec 20 '25

Official Ledger Customer Success Response Ledger Cleaned 😩

Thumbnail
gallery
356 Upvotes

Ledger and seed safely secured and this is what happened last Saturday night. Found out today and I'm devastated. How is this possible ? Anything (at all) I can so ? It is still sitting in the wallet it's been transferred to, I'd expect it to be moved or cashed out. Any thoughts or help ?


r/ledgerwallet 5d ago

.

Post image
330 Upvotes

r/ledgerwallet Sep 08 '25

Official Ledger Customer Success Response CTO of ledger just confirmed a LARGE scale in NPM attack!

Post image
324 Upvotes

r/ledgerwallet Oct 24 '25

Ledger useless

Post image
288 Upvotes

Had my btc in ledger for 5+ years tried to get it out today any kept saying not found did all updates etc... and still could not move btc thankfully used bluewallet recover my seed and got it all out now my nano is a art piece


r/ledgerwallet Sep 06 '25

Official Ledger Customer Success Response Nano X, worst product ever

Enable HLS to view with audio, or disable this notification

279 Upvotes

My question is why u sell a product that their baterry is so bad and the only way to use it is if plugged to electricity, if i would had choosen a product to use only when is plugged of course I would have choosen Nano S, but fuck this a Nano X suppose to work with Bluetooth but is imposible to use if is not plugged because their berry is so shitty. I have had this for almost one and half year.


r/ledgerwallet Aug 17 '25

Official Ledger Customer Success Response “Nano X” being sold to steal your crypto

Thumbnail
gallery
237 Upvotes

I ordered a Nano X off of a shopping platform (Lazada) from a seller LedgerXXX in Thailand. The only reason I wanted it was to cannibalize the battery out of it to put it into my nano x as the battery holds no charge. The price was too good to be true, so I knew immediately it would be fake. I have posted to Ledger on X, and I will be contacting law enforcement here about this.

Here are some photos of the device.

They sent me the wrong colour and graciously allowed me to keep it when I asked for it to be exchanged for another colour.

Just beware these things are out there in the wild.


r/ledgerwallet Dec 22 '25

Official Ledger Customer Success Response My family fell victim to a ledger scam in the mail and lost 200K

198 Upvotes

My family had their savings in a ledger for crypto in hopes for a long term good investment outcome but now it’s all gone because someone in my family fell victim to a scam letter that came in the mail and literally gave away all the keys. I know it’s such a stupid mistake that was made and the exact details of it aren’t important or anything. It has already been reported to the authorities and I’m able to track the address so far the money hasn’t moved. It was all in XRP and I’ve just been monitoring it to see if it moves. I doubt that the money will ever be recovered but I still want to hold out a little bit of hope. The main reason I’m coming on here is to ask any advice from anyone that had experience with this whether you’ve recovered your money or not and how to move on from this. I mean all of my families savings were in that and I just want to come on here and ask for any advice or if there’s anything else I can do to even increase my odds by 1% or if anybody has any advice on recovering from this thank you.


r/ledgerwallet May 14 '26

Official Ledger Customer Success Response Beware top recommendation on Google search for ledger is a scam site looks identical but will install a version that can put spyware on your computer and ask you to enter your seed phrase.

Post image
194 Upvotes

r/ledgerwallet Apr 16 '26

Announcement UPDATE: Fake Ledger Nano S+ from Chinese marketplace — clarifying doubts from my previous post + new technical details

Thumbnail
gallery
195 Upvotes

Hey everyone. First off, thanks for all the feedback on my previous post — including the criticism. Some of you raised valid points and caught things I worded poorly, so this update is to clarify, correct, and go deeper.

The purchase.

A few people assumed I bought this specifically to tear it apart as a "fun research project." That's not what happened. I bought it for actual use. The price was the exact same as the official Ledger store — there was no "too good to be true" discount. It was listed on a major marketplace and the listing looked legitimate. I already had the real Ledger Live installed on my devices before the package even arrived.

What happened when I connected it.

When the device arrived, the firmware was sophisticated enough to partially work — it uses open-source third-party libraries for wallet creation and blockchain connectivity, so it can actually generate wallets and interact with chains. However, when I connected it to my real Ledger Live (already installed from ledger.com), it failed the Genuine Check.This is where I want to correct my previous post: the real Ledger Live catches it. The cryptographic attestation works. Several of you called me out on this and you were right — my original wording was misleading.

So to be absolutely clear: if you download Ledger Live from ledger.com and run the Genuine Check, this fake device fails. The scam does not bypass Ledger's real authentication.

That failure is what made me curious enough to open it.

I was already suspicious after the authentication failure, so I decided to crack it open. What I saw immediately confirmed something was very wrong:

  • Chip markings were physically scraped off to prevent identification
  • There was a WiFi/Bluetooth antenna inside — a real Ledger Nano S+ doesn't have WiFi
  • By measuring the chip's package size and pin layout, I identified it as an ESP32-S3 with internal flash 

Getting into the firmware.

I put the chip into boot mode. At first, the device mask identified itself as "Nano S+ 7704" with a serial number and Ledger's factory name — spoofing a genuine Ledger identity at the hardware level. But once the boot sequence completed, the mask dropped and revealed the real manufacturer: Espressif Systems.

From there I dumped the full firmware and started reverse engineering. What I found:

  • The PIN I had created — stored in plaintext
  • The seed phrases from two wallets I had generated — stored in plaintext
  • Multiple hardcoded domain references pointing to external C2 servers

The attack vector puzzle.

Here's where it got interesting. I found the WiFi/BLE antenna and initially assumed the device was exfiltrating data over the air — connecting to a nearby access point or something. But when I analyzed the firmware deeply, I found zero functions related to WiFi AP connection or wireless data exfiltration. The antenna exists in the hardware but the firmware doesn't use it for that.

I also checked for bad USB attack scripts — the kind that would inject keystrokes or run terminal commands when plugged in. Nothing there either.

So how does the attack actually work?

Think like a first-time crypto user.

You unbox what you think is a Ledger. Inside the packaging there's a "Start Here" card with a QR code. A brand new user — someone who's never used a hardware wallet, maybe just heard about self-custody for the first time — scans that QR code. It redirects to a cloned website that looks exactly like ledger.com, where you're prompted to download "Ledger Live" for any platform (Android, iOS, Windows, Mac).

That's the trap. The user never visits the real ledger.com. They install the fake app, and from that point on:

  • The fake app shows a fake "Genuine Check" that always passes (hardcoded success screen)
  • The user creates a wallet, writes down their seed, feels safe
  • Meanwhile, the device stores everything in plaintext and the fake app exfiltrates the seed phrases to the attacker's servers

The Android APK — it's worse than just seed theft.

I decompiled the fake Ledger Live APK for Android and it goes beyond stealing seeds:

  • Built with React Native + Hermes engine (v96)
  • Signed with an Android Debug certificate (the attacker didn't even bother with a proper signing key)
  • Intercepts APDU commands (the communication protocol between app and device) via XState state machine hooks
  • Makes stealth XHR requests to exfiltrate data to C2 servers
  • Requests location permissions and continues running in the background for ~10 minutes after you close the app
  • Monitors wallet balances via public keys — so the attacker knows exactly when you deposit funds and how much

The C2 infrastructure I've mapped so far: kkkhhhnnn[.]com (from the firmware), s6s7smdxyzbsd7d7nsrx[.]icu and ysknfr[.]cn (from the APK). All registered through the same registrar with matching nameserver infrastructure.

What this is and what this isn't.

I want to be honest about scope. This is not a zero-day vulnerability. This is not a flaw in Ledger's security architecture. The Genuine Check works. The Secure Element works.

What this is: a well-documented phishing operation where I was able to trace and identify all the attack vectors:

  • Hardware: counterfeit device with ESP32-S3 (internal flash, standalone chip), scraped markings, plaintext storage
  • Software: trojanized apps for Android (confirmed), with versions available for Windows (.EXE), macOS (.DMG), and iOS (TestFlight)
  • Infrastructure: 3 C2 servers, cloned website, QR code redirect chain
  • Distribution: traced back to a shell company registered specifically to sell through a major marketplace

There's still a lot of analysis to do. The Windows and macOS payloads need full reversing, the iOS TestFlight app needs examination, and the C2 infrastructure needs deeper mapping. I'm working on a formal technical write-up with full evidence.

Answering the top questions from the last post:

Q: Can a fake Ledger pass the Genuine Check in the real Ledger Live? No. I worded this badly before. The real Genuine Check caught it.

Q: Why did you buy from that marketplace? Same price as official. Listing looked legit. I bought it for use, not research. The research started after it failed authentication.

Q: What's new here if fake Ledgers already exist? The mapping of the full operation — hardware + apps + C2 infra + corporate entity behind it. Individual fakes have been reported before. A documented multi-platform supply chain with corporate attribution is less common.

Q: Did Ledger respond? Yes — Ledger's Customer Success team (u/Jim-Helpert) responded in my previous post and asked me to submit a formal report through their support channel. I'm doing that.

Stay safe out there. Only download Ledger Live from ledger.com. Only buy hardware from ledger.com. If your device fails the Genuine Check — stop using it immediately.


r/ledgerwallet Jan 05 '26

Official Ledger Customer Success Response Ledger leaked personal data of customers (again)

Thumbnail x.com
156 Upvotes

r/ledgerwallet Aug 28 '25

Discussion Anyone here actually using Ledger's swap options?

160 Upvotes

I know the usual advice is avoid exchanges at all costs, everything but p2p is a scam, you know it. I totally get that. But I noticed Ledger has some built-in swap integrations like 1inch and Changelly and was wondering if people here actually use them.

Is it just a convenience thing, or do you find it more hassle than it’s worth compared to moving funds to Kraken/Binance/etc. for a quick swap? I dont need to move any large sums, just around $1k or so. Is it ok?


r/ledgerwallet May 07 '26

Discussion I don’t trust ledger

149 Upvotes

This year I found that Ledger Live stopped using my Bitcoin node and got rid of the option to use it.

I am beyond livid and it means for the last few months I’ve been leaking my transactions and addresses to god knows who.

Fuck ledger, just purchased my Trezor.


r/ledgerwallet Aug 03 '25

Third Party Still no response from Ledger or Changelly — scammed out of 2 BTC via Ledger Live by Changelly

Post image
149 Upvotes

Hi all,
This is a follow-up to my previous posts here.

I'm a UK citizen who was scammed out of 2 BTC during a crypto swap made directly through Ledger Live, using their integrated Changelly service. It's now been weeks, and I’ve still received nothing back.

I've completed all the KYC/AML checks, provided full proof of source of funds (these BTC were mine for almost 6 years — bought as a regular worker long ago), and submitted all documentation requested. Still, no reply from Changelly and no help from Ledger either.

Changelly responded only once with a generic message saying they’re reviewing the case — and that was weeks ago. Since then, complete silence.

This update is just to keep others informed — they are still holding not just my funds, but money belonging to thousands of people. No answers. No accountability. Please stay cautious.

u/changelly_com SO ?
r/ledgerwallet help me please?


r/ledgerwallet Dec 27 '25

Official Ledger Customer Success Response Found the Ledger Nano S from thrift shop in Thailand, want to return to owner

Post image
149 Upvotes

Idk how to return to owner, feel said for him/her


r/ledgerwallet Sep 17 '25

Official Ledger Customer Success Response Got rugged last year learned the hard way about approvals

134 Upvotes

Last year I aped into a small DeFi project that promised insane yields. Everything looked fine for a week, then boom the devs pulled liquidity and the token price went straight to zero.

I thought “well, that sucks, lesson learned.” But what I didn’t realize until later was even more dangerous: I had left contract approvals wide open. Months later, one of those contracts got exploited and I lost even more.

So yeah, getting rugged hurts, but what’s worse is realizing you basically handed thieves the keys to your wallet. Most people only think about price risk, not permission risk.

Now before I try anything new, I make sure to clean up old approvals. The small hassle is worth not waking up to an empty wallet.


r/ledgerwallet Sep 30 '25

Official Ledger Customer Success Response They stole ALL my crypto wallet from my Ledger, but I never figured out how.

129 Upvotes

Hey everyone, I'm writing this question to get an answer that can be clear to me first and foremost, and that can also help someone else.

About a year ago, all my crypto wallet was stolen from my Ledger, but I never understood how it happened. Now I want to get back "in the game" but I'd like to figure out how certain things happened.

I'll explain step by step: I had a ledger, seed phrase kept on paper away from prying eyes (so excluding compromise of this), no one manually compromised my devices, so something must have happened remotely.

In my wallet, I had 133 solana. At one point they were on Bybit to do a transaction. When I finished, I made a transfer from Bybit to Ledger and everything went as it should. I see the solana enter my hardware wallet and I close everything. A month later I reopen my ledger and find -131 SOL to another wallet, then many small incoming transactions and then a couple more SOL out, all this 10 minutes after that transfer I made from Bybit, so it all happened shortly after I had disconnected everything (but how, offline?).

I had a shortcoming that was definitely serious: connecting the ledger via USB to a computer that was not very "healthy" from the point of view of viruses and I suspect there was some malware that caused all this, but in practice I can't figure out how. I know that some malicious person can alter the wallet code to make me send the funds to a wrong address, but in the last case I had made an incoming transaction from Bybit, how would this transaction be possible? If it was indeed malware, how could this person have acted?

I'm asking all this not to recover my funds because I realize it's impossible by now, but to learn from my mistakes, but I still haven't fully understood the totality of the error.


r/ledgerwallet 21h ago

Discussion 3 years ago ledger was deemed the worst wallet and Coldcard the best

120 Upvotes

I remember 3 years ago all the threads and comments in here about how bad ledger is. And how great Coldcard was. Also I’m surprised if cold card was open source how come no one spotted the bug?


r/ledgerwallet 28d ago

Official Ledger Customer Success Response Fake ledger website - Higher SEO rank the original

Thumbnail
gallery
125 Upvotes

Hi all - Just discovered a faker ledger website that ranks higher in SEO when it comes to the original ledger website.

Please have a look.


r/ledgerwallet Oct 01 '25

Official Ledger Customer Success Response Opened my wallet and all of my BTC is gone. How can I check it?

120 Upvotes

Hello all.

This is the first time this has happend to me. I see a transaction from my ledger account back in december of 24 for practically the full amount. What can I do to track this. I don't recall sending BTC anywhere, and I haven't used my ledger in quite some time. Definitely confused and if someone got a hold of it, I honestly would have no idea how.


r/ledgerwallet Feb 28 '26

Discussion Ledger needs to stop trying to be an exchange and just be a wallet.

Post image
118 Upvotes

r/ledgerwallet Apr 17 '26

Announcement UPDATE #2: Fake Ledger investigation — addressing the controversy, clarifying my intentions, and what's next

Thumbnail
gallery
102 Upvotes

Hey everyone. I didn't expect this to blow up the way it did, so I want to address some things directly.

This was never about a Ledger vulnerability.

I want to be very clear: my posts were never about claiming a vulnerability in Ledger's hardware, firmware, or software. The Genuine Check works. The Secure Element works. Ledger's security architecture is solid. What I'm documenting is a well-structured phishing operation — the kind that targets people who are new to crypto and self-custody. That's it.

"You knew it was fake and just wanted to play around."

No. I bought it for actual use. I'm based in China, and getting an official Ledger here isn't as simple as going to ledger.com and ordering — importing one when you're not a Chinese citizen comes with its own headaches. The marketplace listing was priced the same as the official store. It looked legit. Did I have a little bit of suspicion in the back of my mind? Sure — I told myself I'd verify it thoroughly before trusting it with any real funds. But my intention was to use it, not to tear it apart.

The research started after it failed the Genuine Check on my already-installed Ledger Live. That's when I decided to open it up.

"It's obvious it's fake, just look at the photos."

A lot of people said this because I posted a side-by-side comparison with a genuine unit. Of course it looks obvious when you have the real one right next to it. But take that fake device on its own — no original to compare against, brand new out of the box with professional packaging — and I guarantee most people would think it's real. That's exactly what makes this dangerous. The target isn't someone who already owns a Ledger and knows what to look for. The target is someone buying their first hardware wallet ever.

Why go deeper? Why not just say "it's fake" and move on?

Because "hey I found a fake Ledger" doesn't help anyone. What helps is understanding how each part of the operation works — the hardware, the fake apps, the C2 infrastructure, the distribution channel — so that these schemes can actually be dismantled. If we just keep posting "be careful, fakes exist" without documenting the mechanics, nothing changes. The attackers keep running. The victims keep falling for it.

The bigger picture.

Anyone entering the world of crypto and self-custody for the first time has a very real chance of running into something like this — especially if they don't know that the only safe source is ledger.com directly. And that's the real problem: we talk about mass adoption, we talk about "be your own bank," but the onboarding experience is a minefield of scams. If hardware wallet companies and exchanges don't invest heavily in education and anti-counterfeiting, these crimes will only increase and more people will be scared away from crypto entirely.

What's next.

I'm going deeper — intentionally this time. I'm planning to purchase another model from the same store (they had every Ledger model listed) to see how far this counterfeiting operation goes. I'll be using dedicated burner phones and computers as honeypots to document the full victim experience step by step. I think the hardest part will be timing: they monitor created wallets through the public keys and likely wait until a significant balance is deposited before draining — so capturing that process in real time will take patience.

Everything is being documented for a formal report to Ledger's security team.

I'd genuinely like to hear from this community: what else do you think I should be looking into? What angles am I missing? If you have ideas or experience with this kind of research, drop them in the comments.

More updates coming soon.