Ledger Nano S RamboRiki Hack
Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' and 'General Prevention' sections to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
Reddit user RamboRiki had $25k worth of cryptocurrency stolen from their Ledger hardware wallet. They swear that their seed phrase was uniquely generated and remained stored securely in a safe at their home. They had mentioned a plan to reach out to Coinfirm for assistance in recovery, however no further updates are available on this case.
This is a global/international case not involving a specific country.[1][2][3][4][5][6][7][8][9]
About Ledger
"Based in France, Ledger is the largest cryptocurrency hardware wallet company." "Ledger is a hardware cryptocurrency wallet that is used to store, manage, and sell cryptocurrency. The funds held in these wallets are secured using a 24-word recovery phrase and an optional secret passphrase that only the owner knows."
"Ledger offers two products, the Nano S and Nano X, that can store the digital keys used to secure crypto wallets. The devices can be used with a variety of cryptocurrencies, are compatible with numerous apps, and are supposed to offer a safe way to manage crypto without compromising too much on convenience. Ledger says on its website that it has sold 1.5 million products to customers in 165 countries to date."
"I purchased L[e]dger Nano S from Registered vendor here in South Africa nearly 3 years ago. The company is called BITMART and the first and original Bitcoin hardware reseller in South Africa."
"Kept [the seed phrase] in [a] safe. No one could have taken it or used it, it is still there and I am only one with safe access."
"Clicked on link directly on my ledger live which I have used for nearly 3 years. No Playstore."
"I presume seed means the 20 phrases that I had to write down from the ledgers small screan, when I first started the Ledger Nano S nearly 3 years ago. If that is what you mean...then NO definitely not a photo!" "I did not type in 24 word phrase on pc or anywhere else for that matter. I update ledger live from the ledger live which I have had now for more than 2 years."
"I wanted to check the amount of UTRUST coins in my wallet as I saw the price went up considerably. I purchased them during ICO. On 16 August 2020, I could not enter myetherwallet as this annoying "Windows Security scan" popup kept on blocking my ledger. I read FAQ on ledger support which suggested I update Ledger live on PC. I clicked on blue button directly in ledger live to update it and followed the prompts. I still could not enter ledger wallet on Myetherwallet and Ledger support suggested I update the Ledger Nano S' firmware from Ledger Live as well. I did that and to my amazement all my "STARRED ACCOUNTS" on my ledger live profile was hacked 30min later. The other ERC20 coins still there tho, but worth about $500."
"[The blockchain] shows the transactions (their dates and times) when the coins just magically were sent by someone other than me."
"I honestly don't know what you mean with key security practice (English not my first language), but this is what I did regarding security: I kept ledger with original key written down on paper that came with box of ledger and stored it in my safe. That is literally it. Enough said. No one knows the ledger pin, not even my wife."
"With this COVID-19 thing, my wife lost her Salon, her income as well as all our savings in the bank, so YES...LITERALLY OUR FINAL LIFE SAVINGS GONE! The plan was to sell some of the crypto at the end of September to pay a few bills and keep the 1 business we have left afloat. Transparency enough?"
"I bought the NANO S 3 years ago and had quite a lot of crypto on it. It was stored safely in my SAFE with the original 24 word written down safely as well."
"I logged in 30min ago and to the shock of my life...ALL MY CRYPTO IS GONE!!! Someone took everything on 17 August 2020."
"How is this even possible? What to do? Please help, all my life savings gone just like that..."
"How do actually contact Ledger support via telephone or email? What can I do in this situation?"
"Please help, this is my first post on Reddit ever as I am clueless on what to do..."
"In ledger live you have your asset allocation on your profile which still show a few coins with their unchanged amounts."
"I added BTC, ETH and UTK at accounts for transfers and it then falls under starred accounts on your home page on ledger live as quick links and valuation for those starred accounts."
"The transaction dates and times are clearly shown. I posted the links at the start of the thread."
"[T]he only possible explanation is that the mnemonic was compromised somehow."
"I came across "COINFIRM" who partnered with coinbase after their 2019 hack, to try and recover my stolen crypto. They apparently do this kind of thing and even crypto sent to the wrong address. The fee is a portion of the recovered funds. This Crypto hack was worth +- $25000. I live in South Africa, and with the exchange rate is a crap load of money. Nearly half a million, so I have enothing else to lose but to try. These days all established exchanges have to do KYC process if I am not mistaken, so I pray that hopefully I can get everything back!"
This is a global/international case not involving a specific country.
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.
Include:
- Known history of when and how the service was started.
- What problems does the company or service claim to solve?
- What marketing materials were used by the firm or business?
- Audits performed, and excerpts that may have been included.
- Business registration documents shown (fake or legitimate).
- How were people recruited to participate?
- Public warnings and announcements prior to the event.
Don't Include:
- Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
- Anything that wasn't reasonably knowable at the time of the event.
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.
The Reality
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
Date | Event | Description |
---|---|---|
August 16th, 2020 10:31:58 AM MDT | Main Event | Expand this into a brief description of what happened and the impact. If multiple lines are necessary, add them here. |
Technical Details
This section includes specific detailed technical analysis of any security breaches which happened. What specific software vulnerabilities contributed to the problem and how were they exploited?
Total Amount Lost
The total amount lost has been estimated at $25,000 USD.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Immediate Reactions
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
General Prevention Policies
This is almost certainly an issue with a compromised seed phrase, while the exact mechanism is unclear. Seed phrases should never be entered anywhere except the physical Ledger device.
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ My Ledger Nano S has been HACKED!!! Please help!!! : ledgerwallet (Mar 19, 2022)
- ↑ Ledger Live : Most trusted & secure crypto wallet | Ledger (Feb 13, 2022)
- ↑ Ledger Refuses Refunds, Tells Clients “Bank Vault Is More Secure” | Financegates (Mar 19, 2022)
- ↑ Physical Addresses of 270K Ledger Owners Leaked On Hacker Forum - Slashdot (Mar 19, 2022)
- ↑ Scammers Are Using Fake Devices to Steal Cryptocurrency Wallets | PCMag (Mar 6, 2022)
- ↑ https://etherscan.io/tx/0x269697c6360ce27e38654f13de3aca0378c442c71c0ae628597fe9099d8eda3c (Mar 30, 2022)
- ↑ https://etherscan.io/tx/0x8a77b115a9cfe1677afd54eef7fda69899beeda44c6382a015e7d4d6089ba870 (Mar 30, 2022)
- ↑ Bitcoin Explorer - Blockstream.info (Mar 30, 2022)
- ↑ Fix for Windows 10 security popup – Ledger Support (Mar 30, 2022)