Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Counterfeit Ledger Wallet Scam Targeting First-Time Users Traced to Chinese Marketplace

A Brazilian cybersecurity researcher found that inside the fake Ledger wallet, it was a fully trojanized phishing operation capable of draining wallets across 20 blockchains.

Written By Dhara Chavda
Published April 17, 2026 1:00 PM·Updated 4 months ago
Make The Crypto Times preferred on GoogleGoogle
Counterfeit Ledger Wallet Scam Targeting First-Time Users Traced to Chinese Marketplace
Show AI Summary
A Brazilian researcher unknowingly bought a counterfeit Ledger Nano S+ wallet, exposing a phishing operation targeting first-time crypto users.
The fake device stored sensitive information like PINs and seed phrases in plaintext, putting users’ crypto assets at risk of theft.
The scam’s impact may be widespread, as the counterfeit wallet was purchased at a legitimate price from a major Chinese marketplace, appearing almost indistinguishable from an authentic one.

A cybersecurity researcher from Brazil has uncovered a large-scale phishing operation after purchasing what he believed to be a legitimate Ledger Nano S+ hardware wallet from a major Chinese marketplace. The findings, shared on Reddit by user u/Past_Computer2901, reveal a sophisticated supply-chain attack that targets first-time crypto users with counterfeit hardware and trojanized companion software.

Contrary to initial assumptions, the researcher did not purchase the device as a research project. It was bought for actual use, at a price matching the official Ledger store. The listing appeared legitimate, and the packaging looked authentic from the outside. It was only after Ledger’s built-in Genuine Check flagged the device as fake that the researcher decided to crack it open.

Inside the Counterfeit Device

According to a Reddit post, once opened, the device revealed clear signs of tampering. The chip markings had been physically scraped off to prevent identification. More tellingly, the device contained a WiFi/Bluetooth antenna—a component entirely absent from a genuine Ledger Nano S+. By measuring the chip’s package size and pin layout, the researcher identified it as an ESP32-S3 with internal flash, a generic IoT microcontroller manufactured by Espressif Systems.

When put into boot mode, the chip initially identified itself as “Nano S+ 7704” with a spoofed serial number and Ledger’s factory name. However, once the boot sequence completed, the mask dropped and revealed its true manufacturer: Espressif Systems. A full firmware dump confirmed the worst — the PIN the researcher had created and the seed phrases from two test wallets were all stored in plaintext, alongside multiple hardcoded references to external command-and-control (C2) servers.

How the Scam Actually Works

Despite the WiFi/Bluetooth antenna being present in the hardware, the researcher found no firmware functions related to wireless data exfiltration. The antenna exists but is unused. Similarly, there were no bad USB attack scripts that would inject keystrokes when the device is plugged in.

Instead, the attack relies on social engineering. Inside the packaging, a “Start Here” card with a QR code redirects users to a cloned website that mimics ledger.com. From there, the victim downloads a fake “Ledger Live” application available for Android, iOS, Windows, and macOS. The fake app shows a hardcoded “Genuine Check” screen that always passes, giving the user a false sense of security. Every seed phrase and PIN entered through the fake app is quietly exfiltrated to the attacker’s infrastructure.

The Fake Ledger Live App: More Than Just Seed Theft

The researcher decompiled the fake Ledger Live APK for Android and found capabilities that go well beyond stealing seed phrases. The app was built with React Native and the Hermes engine (v96) and signed with an Android debug certificate—an indication the attackers did not invest in proper code signing.

Key capabilities identified in the fake APK include:

  • Intercepting APDU commands (the communication protocol between app and device) using XState state machine hooks
  • Making stealth XHR requests to exfiltrate data to C2 servers
  • Requesting location permissions and continuing to run in the background for approximately 10 minutes after the app is closed
  • Monitoring wallet balances via public keys, allowing the attacker to know exactly when a victim deposits funds and how much

The researcher also confirmed that trojanized versions of the app exist for Windows (.EXE), macOS (.DMG), and iOS (distributed via Apple’s TestFlight, bypassing App Store review entirely).

C2 Infrastructure and Distribution Network

Three command-and-control domains were identified: kkkhhhnnn[.]com (extracted from firmware), s6s7smdxyzbsd7d7nsrx[.]icu and ysknfr[.]cn (extracted from the APK). All three were registered through the same registrar with matching nameserver infrastructure, linking them to a single operation.

The distribution was traced back to a shell company registered specifically to sell through the marketplace. The operation combines counterfeit hardware, trojanized multi-platform software, a cloned website, and a QR code redirect chain into a unified phishing pipeline.

Ledger’s Genuine Check Works — But That’s Not the Point

In an important correction to his initial post, the researcher clarified that Ledger’s official Genuine Check — the cryptographic attestation built into the real Ledger Live app — does successfully flag this counterfeit device. This is not a zero-day vulnerability or a flaw in Ledger’s security architecture.

The critical danger lies in the fact that the scam is designed so the victim never interacts with the real Ledger Live at all. A first-time crypto user unboxing this device is guided by the included QR code to a fake website, where they download the fake app. They never visit ledger.com, never run the real Genuine Check, and therefore never receive the warning.

Ongoing Investigation and Next Steps

The researcher has submitted a full report to Ledger’s security team. A deeper technical breakdown is expected once their analysis is complete. The Windows and macOS payloads still require full reversing, the iOS TestFlight app needs examination, and the C2 infrastructure requires deeper mapping.

Also Read: Russian Crypto Exchange Grinex Halts Operations After $13M Hack

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:BrazilCrypto Scam
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Crypto Market Live: LAB Token Collapses 85% to $2

Prediction Market Fight May Reach Supreme Court CFTC Chair Selig

Prediction Market Fight May Reach Supreme Court: CFTC Chair Selig

Anchorage Bets Big on AI Economy With New Banking Model

Anchorage Bets Big on AI Economy With New Banking Model

Tapnob Rolls Out Crypto-to-Naira Payment Platform in Nigeria

Tapnob Rolls Out Crypto-to-Naira Payment Platform in Nigeria

Clarity Act on Fast Track Senator Moreno Sets July 4 Deadline

Clarity Act on Fast Track? Senator Moreno Sets July 4 Deadline

Find Us on Socials

You may also like

Crypto Market Today Utya, Dogs, LAB Top Gainers as Bitcoin Reclaims $81K

Crypto Market Today: Utya, Dogs, LAB Top Gainers as Bitcoin Reclaims $81K

Rep. Horsford Says Crypto Tax Bill Is Foundation as CLARITY Stalls

Rep. Horsford Says Crypto Tax Bill Is Foundation as CLARITY Stalls

Tether Freezes $38M USDT After $150M DSJ Ponzi Collapse ZachXBT

Tether Freezes $38M USDT After $150M DSJ Ponzi Collapse: ZachXBT

Just 0.1% of Polymarket accounts captured 67% of all profits WSJ

Just 0.1% of Polymarket accounts captured 67% of all profits: WSJ

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information