A Brazilian security researcher has uncovered a counterfeit Ledger Nano S Plus operation built to steal crypto assets by capturing wallet recovery phrases. The issue went far beyond fake packaging. After opening the device, the researcher found hardware changes that should not exist in a legitimate Ledger wallet, including added wireless components and a concealed secondary chip.
The researcher, known on Reddit as “Past_Computer2901,” said the device was purchased from a Chinese marketplace and appeared convincing at first glance. Its packaging and pricing matched normal retail expectations. The warning sign came after the wallet was connected to the official Ledger Live desktop app, where it failed the platform’s Genuine Check.
Physical teardown exposed hidden components
That failed verification prompted a teardown. Inside, the researcher found WiFi and Bluetooth antennas added to the device, even though the genuine Nano S Plus does not include those features. The inspection also revealed another manufacturer’s chip hidden beneath scraped markings, a sign that the scammers took deliberate steps to disguise the modification.
During boot, the device initially identified itself as Nano S Plus 7704. Later in the startup sequence, the listed manufacturer appeared as Espressif Systems, a semiconductor company based in Shanghai. For a Ledger wallet, that kind of alteration cuts against the core security model, since private keys are supposed to remain in a strictly offline environment.
QR code in the box directed users to a fake app
The attack did not rely on hardware alone. According to the researcher, a QR code placed inside the packaging sent users to a fraudulent version of Ledger Live. That malicious app was designed to suppress or bypass normal security warnings, then present a false confirmation that the hardware was authentic.
Once users followed the setup prompts and generated or entered a seed phrase, the modified firmware captured the information. With the recovery phrase in hand, attackers could drain the wallet whenever they chose. The researcher said the goal of publishing the findings was not to cause panic, but to warn users after seeing what appeared to be a large-scale operation.
Ledger warns users never to share their 24 words
A Ledger spokesperson told crypto.news that users buying through online marketplaces should verify the seller’s identity and download Ledger wallet software only from official desktop and mobile channels. The company described the case as counterfeit hardware paired with a fake companion app flow that imitated the normal onboarding process through unofficial distribution channels.
Ledger also repeated a clear rule: Ledger will never ask users for their 24 words. If any person claiming to represent Ledger, or any app claiming to be a Ledger app, asks for those words, users should treat it as a scam immediately. The researcher added a similar warning, urging people to download Ledger Live only from ledger.com, buy hardware only from ledger.com, and stop using any device that fails the Genuine Check.
Fake app case earlier this month led to $9.5 million in theft
The discovery came after another incident earlier this month involving a fraudulent app that slipped past Apple App Store review using a bait-and-switch tactic. That app convinced more than 50 people to reveal their recovery phrases and led to $9.5 million in theft before it was removed. Apple said the listing was taken down for malicious bait-and-switch functionality.
The methods differ, but the objective is the same: get users to hand over their recovery phrase by making a fake process look official. In this case, the counterfeit hardware, the fake verification flow, and the malicious app were all part of the same trap.

