Ledger Nano X: physical cellular implant
Physical implants in Nano X devices are the focus of an ongoing investigation. Ledger confirmed an implant in one affected customer’s device on October 10.
Read disclosure ↗28 sourced records across 11 manufacturers. Explore the affected models, attack requirements and published fixes.
This archive includes individual findings, related research chains and grouped audits. Record counts are not a security ranking.
No matching disclosures. Try another manufacturer or search term.
Physical implants in Nano X devices are the focus of an ongoing investigation. Ledger confirmed an implant in one affected customer’s device on October 10.
Read disclosure ↗Research demonstrated mnemonic extraction through a USB vulnerability chain.
Read disclosure ↗Displayed transaction and signed transaction could differ.
Read disclosure ↗Review could show fewer operations than the signed transaction contains.
Read disclosure ↗A token approval could satisfy a swap payment check.
Read disclosure ↗Older bootloader: malicious firmware. Uninitialized Multi: memory corruption. Silent Payments: funds lock.
Read disclosure ↗One valid proof could satisfy checks intended for different chips.
Read disclosure ↗Coinkite’s incident status describes weakened seed generation and thefts. Corrected firmware changes future generation; it does not strengthen an existing affected seed.
Read disclosure ↗Ledger Donjon reports an unauthorized password reset using invasive laser fault injection. Tangem acknowledges the scenario but challenges its practical significance.
Read disclosure ↗Pairing could complete without knowing the displayed code.
Read disclosure ↗View and spend keys could be exposed without a new confirmation.
Read disclosure ↗Chip firmware verification could be bypassed.
Read disclosure ↗Crash; potential secret-key extraction on exploitable versions.
Read disclosure ↗Researcher reported private-key recovery from the Delta PIN signing behavior.
Read disclosure ↗Donjon reports faster access-code guesses through a tearing attack.
Read disclosure ↗A counterfeit card could pass the authenticity workflow.
Read disclosure ↗Some anti-tampering countermeasures could be bypassed.
Read disclosure ↗Tangem acknowledged a private-key logging issue associated with seed-based wallet activation and subsequent in-app support contact. Seedless activation was outside this issue.
Read disclosure ↗A complete seed was recovered from a challenge wallet.
Read disclosure ↗Audit found boot/update validation and external-storage weaknesses.
Read disclosure ↗Tamper defenses could be bypassed and firmware downgraded.
Read disclosure ↗Failure to verify the device’s own xpub could substitute attacker-controlled keys.
Read disclosure ↗PIN-protection material could be recovered.
Read disclosure ↗Kraken reported extraction of PIN-encrypted seed material through a microcontroller fault on Trezor One and Model T. Physical access is a prerequisite.
Read disclosure ↗Insufficient multisig script validation could allow tampered PSBT files to redirect transaction change. Coinkite credited researcher Dmitry Petukhov.
Read disclosure ↗PIN-encrypted seed extraction enabled offline PIN attacks.
Read disclosure ↗Faults in USB handling could expose device memory.
Read disclosure ↗Ledger Donjon documented physical-interface and firmware weaknesses in the original ELLIPAL EC01. ELLIPAL later disputed that a seed had actually been extracted.
Read disclosure ↗