Abstract:
The French cryptocurrency hardware wallet Ledger recently encountered a serious security incident. Hackers stole the mnemonic phrases set by users by modifying the hardware and installing a stealing device. Currently, the hackers have stolen more than $80 million worth of cryptocurrency. As time goes by, more users' cryptocurrency wallets may be reset by hackers and the assets inside are transferred.

Hacker modified the wallet to install a screen monitoring module:
The hardware disassembly diagram released by Mark Karpelès, the former head of Mt. Gox, was the trigger for this incident. The hacker seemed to have seen the disassembly diagram posted by Mark and concluded that the modification incident would definitely attract attention, so he chose to immediately steal the wallets that had been successfully collected. If Mark hadn't discovered this, it is estimated that hackers would have continued to lurk and collect more wallet data.
Mark inspected a Ledger Nano This circuit board contains components such as a microcontroller, LTE communication module, antenna and eSIM, and is connected via internal wiring to the device display-related SPI communication link.
The possible way it works is to listen to the character data sent by the device to the screen, and then use recognition logic trained for Ledger fonts to reconstruct the screen content. When the Ledger device is initialized for the first time, 24 mnemonic words will be displayed on the screen. Under normal circumstances, the mnemonic words are generated and displayed internally by the device. Ledger's secure element is responsible for saving private keys and performing key operations.
If an attacker can read these words in the screen link bypass and then send them out through the cellular network, it is possible to obtain the complete mnemonic phrase after the user completes the initialization. In the subsequent process, the hacker does not need to access the wallet, and can restore the mnemonic phrase through other compatible wallets and control the assets in the corresponding address.
Authorized reseller CryptoBilis was secretly acquired:
CryptoBilis is Ledger’s authorized distributor in Southeast Asia. Many users do not order equipment from Ledger (because it takes a long time to ship from the French factory via French Post). This dealer had been secretly acquired as early as March, and the acquisition agreement also required that the acquisition be kept secret for at least 6 months. It was obvious that the hackers had been planning for a long time.
Currently it is speculated that the person who acquired CryptoBilis was a North Korean hacker. Those who have the ability to mass-customize and modify microcircuit boards and microcontrollers are naturally not ordinary people. However, the industry is still under investigation and the identity of the hacker cannot be confirmed for the time being.
Comments