Author

Topic: Ledger Nano S scam device from Ebay. (Read 414 times)

legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
May 21, 2018, 05:25:27 AM
#36
Ledger send me info once - but no further step instruction.
Yes I bought device from official Ledger Reseller - package was original and all test passed from the first time.
Genuine test, start as a new device activations (not ask me a pin as in a pre activated device), also I update the firmware - all test was fine.


They give you instruction in that first info, did you send them picture of the device/box and other info they ask? After that they say you will get further information how to return your device to them for further analysis. If you do what they ask and they did not give you any feedback, it is not professionally from their side.

It is good that you have genuine device now, when it comes to cryptocurrency security is most important.
jr. member
Activity: 162
Merit: 8
May 20, 2018, 09:06:44 AM
#35
Ledger send me info once - but no further step instruction.
Yes I bought device from official Ledger Reseller - package was original and all test passed from the first time.
Genuine test, start as a new device activations (not ask me a pin as in a pre activated device), also I update the firmware - all test was fine.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
May 20, 2018, 06:31:11 AM
#34
do the ending of my story.
Ledger company - does not respond me.
Bought official device from official retailer with huge discount. We have sale on that device.
I am glad that my story is ended like that. Thanks for all authors of that thread.
Lesson learned: Buy Cold wallet ONLY FROM OFFICIAL RETAILER, otherwise you are on risk to loose your money.


Hm, but you say that Ledger send you official response and you even post it here :

today I receive official response from Ledger company -
"Hi,

Thank you for reaching out to Ledger Support regarding suspicious instructions for initializing your Ledger Nano S. We would first like to stress a few key security recommendations:
In order to benefit from the optimal level of security offered by the Ledger Nano S, it is crucial you initialize it yourself. The correct and official instructions to initialize your device are accessible from www.ledgerwallet.com/start. Once initialized, make sure you are the sole holder of the PIN code you created as well as the 24-word seed used to configure your Ledger Nano S.
Our dedicated support team is available to help you via our online contact form. Please note that Ledger does not provide phone support.
Regarding the instruction card delivered with your product, we would appreciate if you could provide the following information in order for us to investigate further:
send pictures of the device, of the box as well as the documentation in the box, including the instructions card(s);
send us your order receipt;
share with us any available information regarding the seller: identity, correspondence, location;
return your device with its packaging for analysis; our support team will contact you regarding the return procedure and will send you a new Ledger Nano S free of charge.
Many thanks in advance for your cooperation. Please rest assured that Ledger will take all appropriate measures to bring this infringement to an end.

Kind regards,
"


Did you follow all steps they ask and provide all information? There seemed to be a good will to solve your problem by what they wrote to you...

Did you buy Ledger Nano S from official retailer or some other hardware wallet? When you mention "huge discount" I thought you bought again some suspicious device. Anyway I hope you have a safe and legitimate device this time.
jr. member
Activity: 162
Merit: 8
May 19, 2018, 04:30:13 PM
#33
do the ending of my story.
Ledger company - does not respond me.
Bought official device from official retailer with huge discount. We have sale on that device.
I am glad that my story is ended like that. Thanks for all authors of that thread.
Lesson learned: Buy Cold wallet ONLY FROM OFFICIAL RETAILER, otherwise you are on risk to loose your money.
legendary
Activity: 1624
Merit: 2481
May 04, 2018, 06:39:26 AM
#32
Of course it could be great to change it to the original device from Ledger.
But I doubt that is possible. Ask them and wait for ther reply.

You have stated you received the reply from ledger itself. So i guess no reason to doubt ?
You contacted them via their official site, correct?


Ledger itself has a big incentive to provide a working non-malicious product.

I also do understand their interest in receiving/analysing the device you got from ebay.

You should definetely try to get your money back from ebay (report scam attempt) and send your nano s to ledger to receive a new one.
You may get your money back and receive a free device.
legendary
Activity: 2016
Merit: 1106
May 04, 2018, 05:53:49 AM
#31
I ask them about Ebay seller. So wait for the reply. Of course it could be great to change it to the original device from Ledger.
But I doubt that is possible. Ask them and wait for ther reply.

why would you doubt that?
you recieved an official letter from their support
or was it Ebay support letter too  Grin
a win win situation,you only pay for P@P and it is the offer you MUST take adantage of
besides,it is another portion of material for your youtube channel=more views,more profit
jr. member
Activity: 162
Merit: 8
May 03, 2018, 01:24:39 PM
#30
I ask them about Ebay seller. So wait for the reply. Of course it could be great to change it to the original device from Ledger.
But I doubt that is possible. Ask them and wait for ther reply.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
May 03, 2018, 05:23:04 AM
#29
return your device with its packaging for analysis; our support team will contact you regarding the return procedure and will send you a new Ledger Nano S free of charge.
WOW! That's pretty sweet Cool I guess Ledger are really keen to see if it is just a repackaged original or if it is actually a completely fake unit.

I would definitely take them up on that offer if I was the OP Wink



I must admit that this answer from Ledger surprised me,this is win-win situation for OP,and especially if it can get a refund from E-bay-then he will get completely free Ledger Nano S,it would be a nice ending story Smiley

I also think Ledger should add some notice on their site to warn users not to buy already used devices because of the potential risk.If you do not already buy it directly from the manufacturer then check all official retailers from Ledger site.

Ledger retailers network
HCP
legendary
Activity: 2086
Merit: 4316
May 03, 2018, 04:00:49 AM
#28
return your device with its packaging for analysis; our support team will contact you regarding the return procedure and will send you a new Ledger Nano S free of charge.
WOW! That's pretty sweet Cool I guess Ledger are really keen to see if it is just a repackaged original or if it is actually a completely fake unit.

I would definitely take them up on that offer if I was the OP Wink

sr. member
Activity: 2534
Merit: 332
May 02, 2018, 07:03:36 PM
#27
thanks for your attention comment.
it was risky bought from the beginning because it cost 50% of the retail price and it was described as a new.
I am really understand that device could be somehow pre activated or so.


You still have not answered how you know what is in the box before you opened it?It seems that the sound has not been added to the video after recording.So you open box,see what is inside and then decide to wrap the box again to make unboxing video?

In fact, it is very strange that someone decides to buy such a security-sensitive device from E-bay or Amazon when there are numerous documented examples of "fake" devices in the sense that seed is already generated.The basics of buying over the internet requests from the buyer to investigate all  possibilities of fraud.In this case this was 50% lower price and probably seller which has no positive feedback.

Only with using search engine you will get many results like this :

- 34000$ Lost/Fake Ledger
- FAKE Ledger Nano S unboxing
- Ledger Nano Ebay Scam
I bet you would really only read up those links or particular related topics when you do already lost up funds which these things should be done first before tending on purchasing any 2nd hand or cheap offered ledger nano's online.I was planning to buy one but would be only just directly into the company which which assure you that it is completely sealed and safe. Dont blind yourself into 50% off in exchange in the security of all of your coin holdings.
jr. member
Activity: 162
Merit: 8
May 02, 2018, 11:34:09 AM
#26
today I receive official response from Ledger company -
"Hi,

Thank you for reaching out to Ledger Support regarding suspicious instructions for initializing your Ledger Nano S. We would first like to stress a few key security recommendations:
In order to benefit from the optimal level of security offered by the Ledger Nano S, it is crucial you initialize it yourself. The correct and official instructions to initialize your device are accessible from www.ledgerwallet.com/start. Once initialized, make sure you are the sole holder of the PIN code you created as well as the 24-word seed used to configure your Ledger Nano S.
Our dedicated support team is available to help you via our online contact form. Please note that Ledger does not provide phone support.
Regarding the instruction card delivered with your product, we would appreciate if you could provide the following information in order for us to investigate further:
send pictures of the device, of the box as well as the documentation in the box, including the instructions card(s);
send us your order receipt;
share with us any available information regarding the seller: identity, correspondence, location;
return your device with its packaging for analysis; our support team will contact you regarding the return procedure and will send you a new Ledger Nano S free of charge.
Many thanks in advance for your cooperation. Please rest assured that Ledger will take all appropriate measures to bring this infringement to an end.

Kind regards,
"
HCP
legendary
Activity: 2086
Merit: 4316
May 01, 2018, 10:15:23 PM
#25
I reset it already - 3 times wrong pin - then use as a new device. I was surprised that even after that manipulations (resetting) - this device does not pass genuine test.
That isn't surprising at all... "wiping" the device only deletes the current seed and installed coin apps... it doesn't wipe or reset the firmware. So, if the underlying firmware is non-genuine, it will still be non-genuine after a "reset".

You need to reflash the bootloader and/or firmware with official ones before it will pass the genuine test.
jr. member
Activity: 162
Merit: 8
May 01, 2018, 04:48:38 PM
#24
I reset it already - 3 times wrong pin - then use as a new device. I was surprised that even after that manipulations (resetting) - this device does not pass genuine test.
This seller has only 48 start and he has Russian nickname. I told again - from the beginning this purchase evaluated by me as a risky.
Yea it was too stupid tamper that device(open- manipulate with chip and close it) and put non original paper.
 
legendary
Activity: 1624
Merit: 2481
May 01, 2018, 04:40:11 PM
#23
I highly doubt anyone would go as far as installing an additional chip as it requires alot of technical knowledge and is not really worth the effort

I'd say it is definetely worth the effort!
People are storing all their cryptos on a hardware wallet.
Manipulating the hardware of a hardware wallet is definetely complex, but mostly also worth it.

While it is true that this device probably isn't physically tampered (which attacker would be stupid enough to successfully open, manipulate, close the ledger just to put a hand-filled seed paper with it),
the safest way would be to demand your money back and buy one from the original website (https://www.ledgerwallet.com/products/ledger-nano-s).
hero member
Activity: 2996
Merit: 600
Eloncoin.org - Mars, here we come!
April 30, 2018, 04:38:30 PM
#22
I just ask for fun  Grin Sure no one gives me money.
You don't joke that way, it's begging and it's not allowed by the forum rules.
My video is a visual lessons what you can receive from Ebay and how danger it is. For me it was interesting what you can get and how you can protect yourself, at least for the basic understands.
I'm also curious on what urged you to video the unboxing and can you give what's the name of the re-seller from Ebay? Never trust hardware wallet on Ebay or any re-seller if they are not legit retailer from the main company.

Your experience was different from the guy who lost his life savings. His manual has it's seeds typed already and the seller waited for him to fill the wallet before stealing it.
This is the guy I'm talking about: All my cryptocurrency stolen

@OP did you hard reset it already?
jr. member
Activity: 162
Merit: 8
April 29, 2018, 09:06:49 AM
#21
I just ask for fun  Grin Sure no one gives me money.
My video is a visual lessons what you can receive from Ebay and how danger it is. For me it was interesting what you can get and how you can protect yourself, at least for the basic understands.
legendary
Activity: 2016
Merit: 1106
April 29, 2018, 07:49:43 AM
#20
ha,you want someone to sponsor you to open your device?
this is funny,if you are not sure -do not use it
I highly doubt anyone would go as far as installing an additional chip as it requires alot of technical knowledge and is not really worth the effort
think you are pretty safe using it,but I myself would never ever buy something sensitive like this from Ebay
you got your money's experience worth though+youtube channel content
maybe you can spend the money you get from ads revenue to buy another one soon ..from Ebay Smiley
HCP
legendary
Activity: 2086
Merit: 4316
April 29, 2018, 12:52:31 AM
#19
I'd be super-surprised if the physical device had actually been tampered with... As you say, the effort to do this without damaging the device is fairly substantial.

So it appears that the genuine test is only really testing that the firmware is all correctly signed and not tampered with in any way. Interesting that the old firmware that it had installed on it when it was shipped actually "failed" the genuine test. The scammers were obviously not using the method that Saleem Rashid had used to generate "hacked" firmware that fooled the attestation into believing it was real.

Also, what happened to Part 3 of your series? Wink
jr. member
Activity: 162
Merit: 8
April 28, 2018, 06:25:55 PM
#18
I shot a new video with the firmware update till 1.4.2 and then passing the Genuine test. https://youtu.be/0LeLQVBk5oc
I found the answer that if you update firmware and your device does not pass the test. With the last firmware it pass it!
with the new firmware my device PASS GENUINE TEST!
Firmware update
https://support.ledgerwallet.com/hc/en-us/articles/360002731113
Genuine Test
https://support.ledgerwallet.com/hc/en-us/articles/115005321449-How-to-verify-the-security-integrity-of-my-Nano-S-
So I have only one test to pass - physical device opening and check the security chip - does the additional chip added or not.
I scary to do that, because this can break my device. If anyone donate me 0.01BTC Grin - I open my Ledger Nano S and check the last test.
jr. member
Activity: 162
Merit: 8
April 28, 2018, 02:35:11 PM
#17
I do not know about hardware  - just scary to open device physically.
probably to try new firmware today - mean I have now 1.3.1 will made actual 1.4.2 and re check device again.
 
HCP
legendary
Activity: 2086
Merit: 4316
April 28, 2018, 09:34:35 AM
#16
The question is... is the actual hardware in the device compromised? or is it just a fake firmware?

If you force an update and/or flash the official firmware... does it still give the non-genuine error?
jr. member
Activity: 162
Merit: 8
April 28, 2018, 06:11:15 AM
#15
so my case is not done. I check today does my device original or not and it is not pass that check!  https://youtu.be/hp5w6B9pDT0
"The Secure Element itself is personalized at factory with an attestation proving that it has been created by us. You can verify it by running

pip install --no-cache-dir ledgerblue

Then on firmware 1.3.1 or below

python -m ledgerblue.checkGenuine --targetId 0x31100002"
Original link here - https://support.ledgerwallet.com/hc/en-us/articles/115005321449-How-to-verify-the-security-integrity-of-my-Nano-S-
So I do not want more even hope about that device and try to refund it via ebay.
Hope my lessons and videos help not to loose money with the faked -  Ledger Nano S.


Don't USE Ledger Nano S until watch this video. Scam Alert. Part4. Not Genuine Device!

Title of your video is quite exaggerated,why should people stop using Ledger Nano S just because you bought fake one from E-bay?Hardware wallets are the safest way to store coins,although a lot of suspicions have emerged recently especially on the Ledger account.Nothing is 100% safe,so not even hardware wallet is not something you should blindly trust.

Your case just confirmed once more that buying hardware wallets from sites like E-bay,Amazon and similar are not safe,in most cases it is just too much risk for some discount-in the end it still is not worth it.
In this video I show how to check is your device genuine or not. Imagine if you bought and use device without genuine check? The page of this check in original site not from the first page. Yes my video prove that Ebay buys could be risky and it also show how you can check your device. Fro you point of view this video is simply because you have much exp. in a crypto fields. Many people are really dum with the crypto and with cold wallet. So my video just warn them. About title - if title been some boring long word - it could be not any attention of the people. What also do you like to ask me? Smiley
member
Activity: 195
Merit: 41
April 28, 2018, 05:41:36 AM
#14
so my case is not done. I check today does my device original or not and it is not pass that check!  https://youtu.be/hp5w6B9pDT0
"The Secure Element itself is personalized at factory with an attestation proving that it has been created by us. You can verify it by running

pip install --no-cache-dir ledgerblue

Then on firmware 1.3.1 or below

python -m ledgerblue.checkGenuine --targetId 0x31100002"
Original link here - https://support.ledgerwallet.com/hc/en-us/articles/115005321449-How-to-verify-the-security-integrity-of-my-Nano-S-
So I do not want more even hope about that device and try to refund it via ebay.
Hope my lessons and videos help not to loose money with the faked -  Ledger Nano S.


Don't USE Ledger Nano S until watch this video. Scam Alert. Part4. Not Genuine Device!

Title of your video is quite exaggerated,why should people stop using Ledger Nano S just because you bought fake one from E-bay?Hardware wallets are the safest way to store coins,although a lot of suspicions have emerged recently especially on the Ledger account.Nothing is 100% safe,so not even hardware wallet is not something you should blindly trust.

Your case just confirmed once more that buying hardware wallets from sites like E-bay,Amazon and similar are not safe,in most cases it is just too much risk for some discount-in the end it still is not worth it.
Exactly. Why take the personal and financial risk in buying it from ebay and even marketplace sellers on amazon are looking to scam you. With all their filtered items by their security teams and buyer support can not protect people from buying knock-offs and tampered with items.
Buy the original item from France. There are so many reports and people sending screenshots of their nanos having fake packing then you clearly know it is not from the ledger company.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
April 28, 2018, 05:31:36 AM
#13
so my case is not done. I check today does my device original or not and it is not pass that check!  https://youtu.be/hp5w6B9pDT0
"The Secure Element itself is personalized at factory with an attestation proving that it has been created by us. You can verify it by running

pip install --no-cache-dir ledgerblue

Then on firmware 1.3.1 or below

python -m ledgerblue.checkGenuine --targetId 0x31100002"
Original link here - https://support.ledgerwallet.com/hc/en-us/articles/115005321449-How-to-verify-the-security-integrity-of-my-Nano-S-
So I do not want more even hope about that device and try to refund it via ebay.
Hope my lessons and videos help not to loose money with the faked -  Ledger Nano S.


Don't USE Ledger Nano S until watch this video. Scam Alert. Part4. Not Genuine Device!

Title of your video is quite exaggerated,why should people stop using Ledger Nano S just because you bought fake one from E-bay?Hardware wallets are the safest way to store coins,although a lot of suspicions have emerged recently especially on the Ledger account.Nothing is 100% safe,so not even hardware wallet is not something you should blindly trust.

Your case just confirmed once more that buying hardware wallets from sites like E-bay,Amazon and similar are not safe,in most cases it is just too much risk for some discount-in the end it still is not worth it.
jr. member
Activity: 162
Merit: 8
April 27, 2018, 08:37:28 PM
#12
so my case is not done. I check today does my device original or not and it is not pass that check!  https://youtu.be/hp5w6B9pDT0
"The Secure Element itself is personalized at factory with an attestation proving that it has been created by us. You can verify it by running

pip install --no-cache-dir ledgerblue

Then on firmware 1.3.1 or below

python -m ledgerblue.checkGenuine --targetId 0x31100002"
Original link here - https://support.ledgerwallet.com/hc/en-us/articles/115005321449-How-to-verify-the-security-integrity-of-my-Nano-S-
So I do not want more even hope about that device and try to refund it via ebay.
Hope my lessons and videos help not to loose money with the faked -  Ledger Nano S.
jr. member
Activity: 162
Merit: 8
April 27, 2018, 09:26:04 AM
#11
I shoot real unbox without my voice. Then write just a voice over.
Voice over was written after I read about scam Ledger Nano S packages. I does not repack this package again.
Most of this search results about pre activated device. 95% goes of the scam with pre activated device, where PIN and Seedphrases known to bad guy.
Chip modify potentially can be with probability about 1-2%.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
April 27, 2018, 09:17:38 AM
#10
thanks for your attention comment.
it was risky bought from the beginning because it cost 50% of the retail price and it was described as a new.
I am really understand that device could be somehow pre activated or so.


You still have not answered how you know what is in the box before you opened it?It seems that the sound has not been added to the video after recording.So you open box,see what is inside and then decide to wrap the box again to make unboxing video?

In fact, it is very strange that someone decides to buy such a security-sensitive device from E-bay or Amazon when there are numerous documented examples of "fake" devices in the sense that seed is already generated.The basics of buying over the internet requests from the buyer to investigate all  possibilities of fraud.In this case this was 50% lower price and probably seller which has no positive feedback.

Only with using search engine you will get many results like this :

- 34000$ Lost/Fake Ledger
- FAKE Ledger Nano S unboxing
- Ledger Nano Ebay Scam
HCP
legendary
Activity: 2086
Merit: 4316
April 27, 2018, 08:05:40 AM
#8
First, kudos for posting this up. If it saves just one person from losing coins it will have been worth it!

Given that the box has been opened (to insert the fake card) and the device has been "used" (already loaded with seed+PIN), you would be VERY wise to force an update of the bootloader and the firmware. This is the only way you can be sure that the firmware is an official firmware and not a compromised version that will generate "non random" seeds like the recent exploit.

Even after doing that, I'm not sure I would personally trust that device to store coins... Undecided
jr. member
Activity: 162
Merit: 8
April 27, 2018, 06:37:52 AM
#7
thanks for your attention comment.
it was risky bought from the beginning because it cost 50% of the retail price and it was described as a new.
I am really understand that device could be somehow pre activated or so.
Here the official site recommendation I follow:

"How to erase or reset your Ledger Nano S?

If you acquired a second-hand Ledger Nano S, or if you want to create a second wallet, follow this tutorial to learn how to reset your device first.

Warning: only wipe your Ledger Nano S if you are sure about what you are doing!

Connect your Ledger Nano S
Enter a wrong PIN code and validate by pressing both buttons
Repeat the 2nd step two more times
Once your Nano S displays the message "Your device has been reset", press both buttons until the "Welcome" message is displayed, or disconnect and reconnect your device.
Then you will be able to restore a wallet or create a new one."

So now I would like to make some experiments with that device. Just test some assumptions.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
April 27, 2018, 04:26:19 AM
#6
Today I received my Ledger Nano S from ebay. So guys from Latvia try to scam me with pre activated Nano S. He gives me fake cards with manual. The funny that they need send SMS to +33 753215393 with my device number and then I receive PIN and 24 seedphrase. I shot video with unpacking that device - https://youtu.be/rFrNC8p7akc . Only two cards instead of originals.
So my question what have I do? Is the new passphrase genereting (reset or reprogram) is enough in my case. If anybody needs I can screen and upload fake manual.
These guys from Latvia-Riga try to scam me.

Why did you go to buy such a device from E-bay,when it has been repeatedly warned that only safe way is to buy only directly from the manufacturer?Did you want to make some kind of test to see what will happen or it is just ignorance?

I notice that even before you unpack Ledger,you were completely aware of what was happening and what is in the box,so how is that possible?

Regarding of using that device,I would not use it personally even though it can be reset to factory settings.There is suspicion that the seller has modified the hardware,in short let's say you threw money in the wind.
jr. member
Activity: 162
Merit: 8
April 26, 2018, 04:32:03 PM
#5
I made unbox because it is a new device for me. Just in case and for my youtube channel and for the memory:) also as a proof that I am a real person.
you can't believe but this is a real unbox, I noticed that it is wrong because read before about Ledger Nano S package from original site.
legendary
Activity: 1498
Merit: 1113
April 26, 2018, 04:09:00 PM
#4
thank you for posting the video.
why did you made a unboxing video? did you expect that something will be strange?

and its nice to see these scam attempts and not just read about them.
jr. member
Activity: 162
Merit: 8
April 26, 2018, 03:51:44 PM
#3
thanks. I check it now and first time plug in sure enough it asks me a pin.
Not the welcome screen as written in official page.
https://support.ledgerwallet.com/hc/en-us/articles/360002481534-Is-my-Ledger-hardware-wallet-genuine-
so they advise enter 3 time wrong ping and reset the device follow this link
https://support.ledgerwallet.com/hc/en-us/articles/360000613793
it seems the same you told me. I put official links just in case someone have the same situation
legendary
Activity: 3304
Merit: 3037
BTC price road to $80k
April 26, 2018, 03:30:59 PM
#2
Just hard reset your ledger nano it would be enough and update your nano s to the latest version so that you are far from the hacker.

Then generate a new wallet and make sure to backup your own seed phrase and change your pin code.

I tried to search the contact number, but zero results on google I'd also search it on the official edger nano s website, but I couldn't find it.

Just don't follow the manual for your safety and I think you need to get the pin of your ledger nano to open it and perform the reset and make new wallet account.
jr. member
Activity: 162
Merit: 8
April 26, 2018, 02:36:23 PM
#1
Today I received my Ledger Nano S from ebay. So guys from Latvia try to scam me with pre activated Nano S. He gives me fake cards with manual. The funny that they need send SMS to +33 753215393 with my device number and then I receive PIN and 24 seedphrase. I shot video with unpacking that device - https://youtu.be/rFrNC8p7akc . Only two cards instead of originals.
So my question what have I do? Is the new passphrase genereting (reset or reprogram) is enough in my case. If anybody needs I can screen and upload fake manual.
These guys from Latvia-Riga try to scam me.
Jump to: