Ledger Nano X Implants Target Recovery Words, Researchers Say
Tibane Labs’ specimen B exposes a concealed implant and custom antenna inside a modified Ledger Nano X; no connection to CryptoBilis has been established. Photo: Tibane Labs
Technology & Security

Ledger Nano X Implants Target Recovery Words, Researchers Say

Tibane Labs details hidden implants in Ledger Nano X wallets that capture recovery words, while a link to the CryptoBilis investigation remains unproven.

Make us preferred on Google

Key Notes

  • Tibane Labs describes hidden Ledger Nano X implants that read recovery words from display data and transmit them through a cellular modem.
  • Modified wallets can retain a genuine secure element, while newer implants conceal their electronics beneath the OLED screen.
  • Neither examined specimen was bought from CryptoBilis, and the report does not establish a link to the reseller’s ongoing loss investigation.

Tibane Labs has published an examination of tampered Ledger Nano X wallets containing hidden hardware designed to capture recovery words from the device’s screen and send them over a cellular connection. The report describes a physical attack around the wallet’s secure chip, rather than a demonstrated break of that chip’s cryptography.

The researchers say they obtained two implanted devices through Japanese marketplaces in September and compared them with an earlier specimen analyzed by hardware researcher Joe Grand. Their field report traces three generations of increasingly concealed modifications, including a black-coated circuit hidden beneath the OLED display.

The findings arrive during Ledger’s investigation into missing funds reported by CryptoBilis customers. Tibane explicitly says neither of its specimens was purchased from that reseller and that it has no evidence linking the devices to the investigation. The shared Malaysian shipping connection does not establish a common source or attacker.

The Implant Watches the Screen, Not the Secure Chip

A hardware wallet’s recovery phrase can restore access to its accounts on another compatible device. Capturing those words can therefore defeat the owner’s control without extracting private keys directly from the original secure element.

The described implant taps the SPI connection carrying display data between the Nano X’s secure element and its OLED screen. It reconstructs letters from the pixels used to show recovery words, stores the phrase and uses a separate cellular modem, SIM and antenna to transmit it. The attack does not require the owner’s computer to provide an internet connection.

Grand’s original teardown, presented at hardwear.io USA 2026, documents a real-world implant inside a Nano X. His published research includes presentation slides and extracted firmware, providing an earlier technical reference for the attack method described in Tibane’s new report.

The distinction matters for authenticity checks. Tibane says the modified wallets can pass Ledger’s Genuine Check because the original secure element is still genuine. Authenticating that chip does not, by itself, demonstrate that nobody has attached additional hardware to the surrounding circuit.

Three Generations Become Harder to Spot

The first known version used visible wires and a smaller battery to make room for its electronics. Tibane’s two newer specimens use flexible circuits; the most concealed example retains the original battery, replaces padding beneath the display and uses a black coating to blend into the board.

That progression makes a simple visual check less reassuring. An intact exterior cannot reveal what is under the display, and opening the casing alone may not expose a carefully concealed addition. Tibane interprets the later design as suited to repeatable installation, but has not established how many such devices exist.

The lab also labels its work an ongoing investigation and says it is sourcing hardware for more extensive analysis. Its photographed specimens document physical modifications; they do not provide a complete census of affected wallets or independently establish the cause of every reported theft.

The CryptoBilis Link Remains Unproven

Ledger’s October 9 customer warning concerns people in Southeast Asia who bought devices through CryptoBilis. The company asked the reseller to pause sales and shipments while the investigation proceeds.

For customers who purchased from CryptoBilis within the previous 90 days, Ledger advised against initializing devices that had not yet been set up. Those who had already completed setup were told to consider moving assets to a new Ledger signer with a new seed.

CoinScreamer’s earlier coverage explains that reseller-specific warning and analyst Darkfost’s concern that losses may extend beyond initial estimates. Investigator Specter’s preliminary assessment exceeded $86 million, but a final verified total and the mechanism behind the reported losses remain unresolved.

The implant report supplies a concrete example of how tampered hardware can expose recovery words. It does not establish that this mechanism caused the entire loss cluster, that every CryptoBilis device was modified or that all Nano X owners are affected.

A New Device Must Also Mean a New Recovery Phrase

Tibane’s central precaution is to treat a recovery phrase displayed on an implanted device as exposed. For a Nano X of uncertain origin, the researchers recommend generating a new phrase on trusted hardware and moving the assets to accounts controlled by it.

Ledger’s existing security guidance explains why replacing hardware alone is insufficient: importing the same recovery phrase restores the same wallet. If another person has that phrase, their access is not removed by purchasing a replacement device.

A new phrase generated on trusted hardware creates a different wallet. That distinction is essential when following Ledger’s advice to affected recent CryptoBilis buyers: the recommendation specifies both a new signer and a new seed, rather than restoring a potentially exposed backup.

The company’s phishing warnings also say its staff will never ask customers for their recovery words. Those words should not be entered into a website or sent to someone offering to inspect a wallet. The unresolved questions remain the distribution of implanted units, their connection to reported thefts and the full extent of affected purchases.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

News, Technology & Security