# malicious approval — X 热门讨论 (2026-10-10 15:39 UTC)
## @0x_Davide (0xDavide) · 10-10 09:34 · ♥29 ↻7 💬5 📱Following yesterday's draining of (compromised) Ledger hardware devices purchased from a reseller, keep in mind these types of scams targeting such devices:
- Pregenerated seed: The device is delivered with a seed that has already been generated.
- Additional components: An apparently authentic device may contain unauthorized components, such as circuit modifications or hidden communication interfaces. Sometimes, OLED screens equipped with LTE modems and eSIMs are used to transmit data.
- Malware infected devices: Scammers sometimes send fake devices, complete with deceptive packaging and letters, containing malware. Victims are persuaded to switch to the "new" device, often citing the need for updates. These devices frequently include a USB drive designed to spread malware.
- Keyloggers and malware: A "keylogger" records keystrokes, an "infostealer" reads clipboard data and malware intercepts data saved by the wallet software. These can steal a recovery phrase entered into the computer.
- Malicious firmware: a compromised supply chain or an inauthentic update can alter the wallet's behavior.
- Clipboard and address substitution: Malware alters the address copied to the clipboard, replacing it with the attacker's address. If the victim fails to verify the full address before sending, they transfer funds directly to the attacker.
- RNG vulnerability: Low entropy seed.
- Used devices: The seller initializes the wallet, keeps the recovery phrase, and delivers the device along with the seed. Although the packaging appears legitimate, the device is actually used.
- Software supply chain attack: dApps containing malicious code can present transactions designed to drain wallets.
- Blind signing: the victim approves a seemingly harmless transaction but actually signs a transfer, such as an unlimited ERC-20 approval or a Permit without the seed phrase being exposed.
- Cloned wallet applications: An app or website imitating services like Ledger Wallet or Ledger Live displays a fake error message, a synchronization request, or a mandatory update prompt, tricking the user into entering their 24-word recovery phrase.
- QR codes: tampered labels, QR codes or manuals can redirect users to a fake setup site, a cloned application, or a deposit address controlled by the scammer.
- Fake technical support: Social media accounts, Telegram profiles, or support websites impersonate the manufacturer; they promise to resolve issues or recover stolen funds while asking for the recovery phrase, a QR code scan or remote access to the computer.
If you are wondering whether it would be better to hold assets on exchanges or hold fiat instead of $BTC, the answer is obviously no. Self-custody offers great advantages but also entails significant responsibilities, and one must own up to mistakes when they happen (in yesterday's case, the mistake was buying a hardware wallet from a source other than the manufacturer). https://x.com/0x_Davide/status/2108853744053956722