Ledger did not get hacked. Let me say that again, because the headlines will get it wrong: Ledger did not get hacked. What broke was something much older and much simpler. People bought a security device from a stranger. Thread. 1/5
Why no check caught it: the Secure Element can only vouch for itself. Chip, firmware, signature. It cannot see what is soldered to it from the outside. No checksum will ever cover a case that was opened. The security layer here was never the chip. It was the purchase channel. 5/5
During setup the 24 words show on the screen. The implant reads them off the display line and sends them out over the mobile network with its own SIM. One packet, then silence. Then the attackers waited. Weeks. Until the wallets were worth draining. About $93M across 311 wallets. 4/5
What happened: a reseller in Southeast Asia (CryptoBilis) sold real Nano X devices. Real chip, real firmware, Genuine Check green. Someone opened the cases, wired a tiny cellular module to the display line, shrank the battery, resealed the wrap. The box looked perfect. 3/5
I know what some of you are feeling right now. You did the "right thing". You bought a hardware wallet. You wrote the words down. You did not screenshot them. And someone still took everything. That is not stupidity. That is a supply chain failing people who trusted it. 2/5
@mohd_almarzooqi Car insurance in the UAE needs to be checked by authorities. I had the same renewed my insurance for another year and needed to pay more than the year before, on the other side where the car got older and more km (less value…)? Makes no sense to me!