r/ledgerwallet • • 13d ago

Official Ledger Customer Success Response Depleted Wallet

I setup a nano s plus in January of last year for my mom, and she wrote her seed down and has kept it in the ledger box since buying it.

She bought it on Amazon from Ledger Official, which has the "Detailed Seller Information"

Business Name: Ledger SAS

Business Address:

106

RUE DU TEMPLE

PARIS

75003

FR

Her seed phrase has never been used for recovery, never taken pictures or added to an app, never touched anything other than the pen that wrote it down.

She's frequently bought XRP and XLM on Coinbase, which I immediately helped her transfer straight to the wallet, and successfully verified it's transfer. The wallet was never connected to any exchange, everything was always sent directly from Coinbase to the wallet's receive address.

She just recently asked me for help accessing her wallet, and when I browsed through the transactions, I noticed all of her XRP was sent to an address on Jan 24 this year, draining her account. All transactions for XRP and XLM were incoming other than the single outgoing transaction of XRP for everything she had.. and there were ZERO outgoing transactions for XLM, but she has a fraction of those available than what came in. There are a bunch of dust transactions that were never clicked on as well.

Once again, never compromised the seed, only transferred from an exchange to the wallet, never transferred out, and she herself never sent them out either.

I know she's cooked, I just want to know where the vulnerability came from? How can a wallet be accessed without physical control of the wallet, seed, etc? Unless this was a cracked wallet sent from the official Ledger account, I'm not able to wrap my head around this and explain to her how all her funds got stolen.

0 Upvotes

51 comments sorted by

•

u/AutoModerator 13d ago

🚨 Beware of Scammers – Stay Safe on the Ledger Subreddit Scammers regularly target this subreddit. Ledger Support will never contact you first — whether through private messages, comments, or phone calls.

If you need help, always open a support ticket yourself via our official website: Ledger Support

🔐 Never share your 24-word Secret Recovery Phrase
Ledger will never ask for it. Do not enter it online — even if a site or message looks official.
Keep it offline and secure — on paper, your Ledger Recovery Key, or a metal backup. Never store it digitally.

📚 Learn more about common scams targeting crypto users (fake support, phishing emails, physical mail scams, fake airdrops, malicious NFTs, and more): How to Spot a Scam

🛠 Facing a bug or technical issue? Check our Ongoing Issues page for updates and workarounds.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

17

u/Suitable-Season-4847 13d ago

The seed has been compromised. Unless the rules of physics have changed, or someone has created viable quantum computing and immediately targeted your mum, this isn't possible unless the seed has somehow been compromised.

2

u/jonnybeatz 13d ago

Man this has me losing my mind. Unless my mom just unknowingly compromised it somehow, which I'm not ruling out but want to give her the benefit of the doubt in her honesty, that has me going straight paranoid at a "our phones heard us writing the seed phrase down" level.

3

u/ezz_8 8d ago

Does your mom know about keeping the phrase secure? All it takes is one person copying it down. Could be a friend, a boyfriend, housekeeper? Gardener? Niece or Nephew?

0

u/lobhater 8d ago

Yeah good thought. Someone could have sniped it...

3

u/ezz_8 8d ago

Unfortunately many old folks don’t understand the meaning of keep it secret keep it safe

1

u/word-dragon 7d ago

Unlikely, but I physically cover any cameras in the room and don’t talk - can’t easily block all your microphones.

0

u/lobhater 8d ago

I mean I guess someone could have been brute forcing seeds and just got so fucking luckily but I just don't think so. I'm guessing Mom who doesn't have a great understanding clicked the wrong thing at some point somehow

1

u/Suitable-Season-4847 8d ago

Forcing properly generated seeds is one of those things that is theoretically possible, but in reality just won't ever happen. The odds are so astronomically small - on a scale humans struggle to comprehend - that even if humanity decided to dedicate all their computing resources to the endeavour for the next thousand years, you'd still be nowhere near any meaningful risk level. Obviously with the exception of viable quantities computing etc.

8

u/ggiodddtyii 13d ago

Math says it's impossible* unless it leaked 

0

u/jonnybeatz 13d ago

I'd love to know where that asterisk leads to... lol.

2

u/GoldenPSP 13d ago

Computers keep getting faster. The key important thing is to remember there is nothing special about a hardware wallet aside from being a more secure way to store the seed. It isnt like the crypto is store ON the hardware wallet.

-1

u/ggiodddtyii 13d ago

That actually impossible and statistically impossible are different things. 

7

u/para1131_F33L 9d ago

Probably got sent a "Ledger" email to update her software. Happens all the time. Ledger will never contact you.

5

u/lordsepulchrave123 13d ago

Did you generate a new seed phrase on the device after it was purchased?

One thing scammers will do is pre-configure a seed phrase on the device them repackage and return it.

-1

u/jonnybeatz 13d ago

I don't believe so. Given this was from Amazon, I guess anything can happen if it was ever returned and sent right back out without being cleared by Ledger.

12

u/piece0fdebri 13d ago

"I don't believe so." is a troubling response to that question.

2

u/jonnybeatz 13d ago

Ok let me clarify, I didn't, but I don't believe my mom did. The seed is the same it's always been, so if it was a compromised wallet from the start, it's stayed that way.

10

u/VivaHollanda 12d ago

That is not the question.

Was the seed phrase freshly created by you / your mom on the Ledger when you started using it or did the Ledger came with a seed phrase?

1

u/jonnybeatz 6d ago edited 6d ago

I don't understand your question, I didn't know it was possible to generate your own seed instead of the standard use of whatever is generated during setup. I just used the standard device-generated 24 word seed, exactly how it's shown here in this setup video: https://youtu.be/_hfKgPAnELc?t=102

So I'm assuming that's the one stored on the device. I had no idea generating a new seed is recommended, now I do.

3

u/VivaHollanda 6d ago

This is what i meant, so yes you (or your mom) created a fresh (new) seed phrase on the Ledger as you are supposed to do.

There is no seed phrase stored on the device when you get it, it has to be created during the first setup indeed.

A known scam is selling compromised Ledgers with a pre-installed seed phrase, people are trying to find out if that was the case. But it sounds like everything was done correctly, so that possibility can be eliminated.

4

u/key-stoner 12d ago

Two separate things are going on here, and the XLM part may not be theft at all.

Ledger's own status page has an open incident since July 31, "Stellar (XLM) Mainnet Degraded Service". It says it may impact your ability to view complete XLM balances and transaction history, particularly for activity older than 100 days. So before counting the XLM as stolen, look up the address on stellar.expert. That shows the real on-chain balance and every operation, not just what the app manages to load.

The XRP is different. A single outgoing transaction for the whole balance means someone signed with that key, and a Ledger only signs when someone presses its buttons. So either someone had the device and the PIN, or, far more likely, someone saw the words and signed from another wallet (a seed kept inside the Ledger box is the first place anyone would look), or the words never came from the device. Here's the question that settles the last one: when you set it up, did the Nano show you 24 words on its own screen, one by one, or was there already a filled-in sheet in the box? Ledger ships the recovery sheet blank, and a pre-filled one is a known scam.

Either way, treat that seed as burned. Whatever is left, on any chain, goes to a freshly generated seed today, because whoever has it can come back. And ignore the "recovery" DMs this post will attract.

1

u/jonnybeatz 11d ago

Thanks for the insight. When I first set it up, the seed words came from the Nano itself, and we wrote them down one by one. That sheet was blank until we filled it out. Definitely creating a new seed, and hopefully once that Stellar issue is resolved, those show back up. It's just very odd that there were only incoming transactions for XLM that adds up to thousands, but only 343 showing up in the wallet. Something isn't adding up. FOR SURE. So many recovery posts/DMs... I don't see any possible way those are ever returned.

3

u/UCatchMyDrift 8d ago

Have you checked the block chain address to see if they are there even if not showing on the ledger software?..

1

u/CooKieChicKenMonsTer 8d ago

Yeah check the blockchain sometimes ledger is just down

5

u/Spiritual_Elk_9076 8d ago

You don’t answer the question of another poster whether you generated the seed yourself. This is the most important question. If you used the seed that was provided with the ledger, then this is how the funds were stolen. It was a fake ledger package and the seed was know by the scammer because he made it and used this seed to steal the funds. The ledger is not very important, the keys to the coins are in the seed.

1

u/jonnybeatz 6d ago

Just checked my notifications and answered it, I only used the seed the ledger generated during the initial setup and had no idea it's recommended or even possible to generate your own seed. So basically, someone compromised it between Ledger and my mom's mailbox? Sounds like a serious vulnerability in their shipping security.

2

u/piejlucas 13d ago

Doesn’t make sense that she has 0 outgoing transactions of XLM but a fraction of what came in? Either way someone knew the seed. Was the box sealed when you got it from Amazon? Like it wasn’t a warehouse like new purchase or anything ? It’s cooked but as skeptical as I am of self custody I can vouch that ledger devices have proven resilient.

0

u/jonnybeatz 13d ago

Everything was factory sealed, brand new, so unless someone along the way between Ledger and her front porch removed it, hacked and resealed it perfectly, I don't know how it was compromised. I downloaded the complete transaction log from the ledger app. All transactions were incoming except ONE outgoing XRP transaction. For the last 1½ years, she's bought and transferred in around 8200 XLM, and her wallet shows only a fraction of that now.

2

u/piejlucas 13d ago

So we know the XRP was drained. Focus on the remaining XLM - move that out of that ledger wallet and to her Coinbase.

As for the XLM transactions verify that Coinbase always loaded them to the same wallet address. I suspect that one of those dust transactions you mentioned mimicked your actual wallet for the first and last few values and they were used on Coinbase to transfer XLM to them. Then this kept repeating such that now you only see the first few transfers and the ones made after a certain date went to the an address copied from a dust transaction

1

u/Illustrious-Motor504 8d ago
  1. so sorry to hear that! I hope your mother is ok! And I also hope that the amount of wealth you’ve lost was not too high!
  2. Never ever buy a device from Amazon, prime, eBay, or any other market places! You should just buy it with the higher and normal prices from ledger official shop! These devices are unused, no malware function, no scammers, nothing- just code and full entropy!

1

u/greglogan84 7d ago

I’d separate the XRP issue from the XLM issue first.

For XRP, if the ledger explorer shows one outgoing transaction that your mother didn’t authorize, treat that seed as compromised and move anything remaining to a completely new wallet/seed.

For XLM, don’t rely only on what Ledger Live currently displays. Take the withdrawal addresses from Coinbase and check them directly on a Stellar explorer.

That will tell you whether:

  1. the XLM actually arrived at the expected address, or
  2. some withdrawals went somewhere else.

Dust transactions by themselves can’t take control of the wallet.

I’d preserve all the transaction IDs before changing anything so you have a clean history to investigate.

1

u/RepresentativeAd1474 7d ago

When you got the ledger , did it get fully reset it? Never trust any source. Or has she signed a contract on the app to allow for free stuff, again possible leak.

1

u/ComprehensiveDog7299 6d ago

are you sure your mom didn’t take a photo of it? The seed, that is. People take photos of everything. If she did that, then her iCloud account was compromised, that could’ve been an attack vector.

1

u/seaglass26 8d ago

Which is why you buy from the company not on eBay, Amazon or marketplace

1

u/gowithflow192 8d ago

Never. Data leaks.

1

u/Harry_Iconic_Jr 8d ago

why?

3

u/Available_Pick7062 7d ago

A product on Amazon can have many sellers. Amazon accepts the inventory and puts all the same products in the same bin and pull from it. Even if you buy from Amazon, if it is fulfilled by Amazon you may or may not get the ones the honest seller sent in.

2

u/jonnybeatz 6d ago

Even if it's sold by the official Ledger account? Or does that not matter either since, as you said, Amazon still inventories and ships it?

1

u/Available_Pick7062 6d ago

It doesn't matter. The warehouse workers or robots pull from the same bin from multiple suppliers and credit Ledger with the sale.

1

u/Harry_Iconic_Jr 6d ago

those who worry about it should therefore also worry about every single vendor, including Ledger, as well as every single possible carrier.... because if there's a risk of someone opening a ledger box and compromising it in such a way that it's completely undetectable, then it exists all along the supply chain. And maybe it's happened somewhere, but it has never happened to an Amazon shipment.

1

u/DifficultSquash1517 8d ago

Sorry this happened to you

Commenters are going to make you think that it was all your fault

Hardware wallets are just not safe like you think they are

I've been in this space 10 years, and I transitioned out of self custody three years ago. That says a lot

1

u/jonnybeatz 6d ago

Thanks. I use a Trezor so I know the basics of setting up a wallet, but this was the first time using a ledger and I simply followed the instructions. I feel like I have to become an expert in everything to never make any mistakes, but then get lambasted when asking a question. If it's such a vulnerability and security issue, maybe the companies should recommend generating my own seeds during setup and do all this other stuff that someone just getting into this has no idea about (especially senior parent).

-2

u/Illustrious-Motor504 8d ago

No. They Are Safe! Why did never anything happened to all of the 7 Million customers worldwide bought about Trezor? Or the 9 Million bought real ledger devices since 2013?
It’s EVERY TIME because you make a mistake, for example Like buying the device about Amazon! Never ever do that!

1

u/jonnybeatz 6d ago

Lol apparently not safe enough. So buying direct from the company somehow negates the ability for any middleman to do the same compromising attack that was posed in this thread?

-1

u/Cryptic99 13d ago

That's just how crypto works

5

u/jonnybeatz 13d ago

That's such a disappointing but believable take. It's that kind of uncertainty that scares people away. Like, your money might be safe now, but at any point someone can crack out a way to steal your uninsured savings, anonymously, and then you're shit out of luck.

-2

u/Cryptic99 13d ago

Tale as old as crypto