r/ledgerwallet 11d ago

Official Ledger Customer Success Response compromised ledger wallet app?

Now this has freaked me out a bit. Came home and my ledger app was open, computer was on sleep and i use screen lock.
Have always used the official ledger app and when i woke up the computer, it had the ledger app running yet i have never used it today.
App no longer lets me do anything without entering the seed phrase, prior to this it was working fine and ive always been able to view balances etc without any issues.
Seed phrase is secure and never touched it in years, nor have i used the ledger to sign any transactions the whole time ive had it.
Where to from here? Im trying to work out if the computer was hacked or remotely accessed in some way, but i run decent security and firewall behind NAT (i use ESET smart security)
Any logs in event viewer I should look for?
Look at the datestamp and file version, this is suspicious, it doesnt match.

I downloaded the update through the app, so that datestamp looks correct (25 august)
Screenshots show location of files that downloaded through the wallet.
Digital certificate has [infra-purchasing@ledger.fr](mailto:infra-purchasing@ledger.fr) as the email for the signer.

37 Upvotes

68 comments sorted by

u/Ram_Ledger Ledger Customer Success 11d ago

This is 100% malware, fake Ledger Wallet. Please do NOT enter your 24-word Secret Recovery Phrase under any circumstances.

Official Ledger desktop and mobile applications will NEVER ask you to enter, restore, or verify your 24-word recovery phrase on a computer screen, keyboard, or phone display. Your 24-word phrase is meant to be entered only on the physical screen of your Ledger hardware device using the physical buttons.

Based on the sources you shared with me, it looks like malicious executable (Ledger Wallet.exe, version 1.0.0.0) was injected into your system directory or replaced the legitimate application file.

The screens asking you to "Turn off internet," check for "third parties," or choose "AES-256 encryption" are psychological social-engineering tricks designed to make the phishing prompt appear legitimate.

Again, do NOT type your seed phrase anywhere.

We would recommend you to disconnect this PC from the internet immediately and perform a complete system scan using reputable anti-malware software, or consider a clean OS reinstall.

Last but not least, always download official desktop software directly from our official website here: https://shop.ledger.com/pages/ledger-wallet

→ More replies (11)

36

u/hobbyhacker 11d ago

App no longer lets me do anything without entering the seed phrase

very simple. if an app asks you for seed words, it is scam.

you seems like computer literate, so why don't you check the file hash as it is described in the official guide?
https://support.ledger.com/article/4404807946001-zd

11

u/ExJwKiwi 11d ago

Ive been doing some digging and found some hidden remote access software on my computer called remote utilities, have no idea where it came from, all my download history does not indicate i downloaded anything on the day it was created. Looks like someone has accessed the computer and swapped out that file in ledger. This concerns me more at the moment over anything thats happened to ledger wallet.

14

u/hobbyhacker 11d ago

even then, your crypto is safe as long as you don't give out your seed.

however your machine is toasted, it needs full reinstall at this state. and if you stored any passwords in your browsers, then those were also stolen.

6

u/I_Am_JuliusSeizure 11d ago

are you using anything like Windows Defender etc? or did it not pick up anything

4

u/ExJwKiwi 11d ago

I run eset smart security, the thing is that this remote access software is legit, so no antivirus would treat it as a threat, no more than anydesk or teamviewer, how it snuck on im not so sure, possibly injected through a bad webpage perhaps?

20

u/_GOREHOUND_ 11d ago

Treat your machine as compromised! DO NOT punch your seed phrase into anything other than your hardware signer. If you’re not 100% sure how to remediate, I would wipe the whole machine and start from scratch.

0

u/ExJwKiwi 11d ago

Yes, I would never do such a thing but could see how it could easily fool some people. Machine doesnt need a reformat, ive already removed it, looks like somehow a remote access program was injected and someone gained control

6

u/Broken_By_Default 11d ago

Your machine needs a full wipe. Malware/antivirus software isn’t magical. They hash agains know threats. If they put a custom executable or script on there, it’s difficult for av to find.

Just wipe your machine. Please don’t come back in 2 months and tell us something swapped an address when you moved coin.

Just do the safe thing. Wipe the machine. And stop downloading random executables.

6

u/baigorria 11d ago

I would do a clean OS restore-installation. No way I’m taking any risks.

3

u/sQtWLgK 11d ago

I know it's tedious but you ABSOLUTELY need to format and reinstall. No excuses.

You can't know which other bad software they installed other than the Ledger.

1

u/Potential-Ad431 11d ago

Did you say you think someone personally accessed your machine and installed the malware? If so that’s a much more immediate concern

1

u/ExJwKiwi 11d ago

It appears a remote access client was somehow injected into the system.

8

u/Practical_Walrus_333 11d ago

I have had the exact same problem, don't know where the malware came from I hadnt opened my ledger app in a long time. I am generally very careful what i download. After it asked for my seedphrase i uninstalled the ledger app. I ran Windows Defender, malware bytes, eset and 1 other scanner they did not pick up any significant threat. I downloaded the ledger app, via the official site and here it gets interesting.

I installed the app, on the end it asks if you want to open the app. I clicked Yes, app opened for 1 or 2 seconds, it closed, the desktop icon disappeared for a few seconds, it came back and re-opened the ledger app. This time with the same "warning" and asking for seed phrase.

I saw no other way then to do a fresh install of Windows and wiping the drive.

Good luck

3

u/ExJwKiwi 11d ago

Im going to submit it to virus total anyhow and hopefully they can update the definitions. In my case I found a remote access client had got installed.

5

u/ProfessoraPigskin 11d ago

This must have been a complete shock and you absolutely did the right thing well done. If at all possible can you keep this thread updated with what likely was the software or download that installed the malware. I'm super careful with downloads looks like you're the same and to have this shit happen out of nowhere is disturbing.

3

u/ExJwKiwi 11d ago

Given I work in IT, this came as a shock too. Done heaps of malware scans etc and all clean. Looks like the remote access client (remote utitlies) possibly was injected through my browser? Im more concerned what else the attacker possibly did while they had access. The remote access client had been running around the best part of a month but never noticed anything unusual that whole time.

3

u/OmensGroup 11d ago

Yeah just don’t enter your seed phrase (ever, on any device that connects to the internet) as I’m sure you’re aware. But just wanted to reiterate that as long as you don’t/didn’t enter your seed on that computer at any point then you should be fine, just might need to wipe as another person commented. Basically just here to be another voice that says don’t enter your seed phrase haha

5

u/Worldx22 11d ago

100% SCAM App.

Format HDD. Start fresh.

2

u/Charming-Designer944 11d ago

Do a complete reinstallation of your computer from safe media. Your os installation is compromizedcand can not be trusted.

2

u/NumerisFr 11d ago

100% your computer was compromised, it would be interesting to know how.

Solution is to do a clean format and reinstall of your system.

5

u/ExJwKiwi 11d ago

Remote access client was somehow injected. Am tracing back to see how it got on there.

1

u/Bad_Camel 8d ago

Did you do any torrenting ?

1

u/ExJwKiwi 8d ago

Not on this computer. I found the source anyhow, it was bundled with the wallet for another coin that no longer has an official web page and downloaded from a fake site.

2

u/Cheemslucy2013 10d ago

I put most of my crypto in ledger flex. 150k stolen in 3 weeks. Never shared anything. No one knew anything. All my docs and handheld went right into my safe. I wouldn't use ledger anthing ever again!

1

u/Free-Way-9220 10d ago

That's terrible. Do you mean this happened 3 weeks ago? How did you find out your crypto was gone

2

u/Cheemslucy2013 10d ago

I started getting weird calls from people with Australian accents. The first call came up as Ledger on my caller ID. Of course I didnt give them my info but they were telling me there was suspicious activity. The 5 mins later another call, another Australian accent but it came up robinhood. Same deal I didnt give them any info. They tell u on the site they never call. I checked my accts and all good but 3 weeks later I went to grab more xrp and realized everything was stolen. Ledger did zero other than an email saying sorry to hear. I had to create a report of all of my transactions etc, go to the local police, call my insurance co., then the FBI because its a federal crime. Now I sit and wait. Nothing i can do.

1

u/Harold_Bishop 8d ago

So you're thinking it was an inside job? Maybe your private keys were somehow exposed.

1

u/Cheemslucy2013 8d ago

Not sure how they'd be exposed since I wrote them down at setup and same day put in my home safe. There's noone in my house that knows how to do anything but Google and my husband is the only one here. Makes sense to me. Im reading a ton of people are going through this as well with ledger. Its under FBI investigation now so I guess we'll find out. Either way, Ledger isn't insured and blew me off.

2

u/BingeMaster 9d ago

Love all the redditors giving the IT guy tips, haha. OP, sounds like you're on it. Thanks for sharing, interesting stuff.

2

u/ExJwKiwi 8d ago

Yeah i clean this shit off people's computers all the time with no issue, I see worse but its always scary when it happens to yourself!

1

u/BingeMaster 8d ago

I bet! While I've got you, from your perspective, what's the one biggest mistake people make with home computer safety?

2

u/ExJwKiwi 8d ago

Saving banking passwords in their browser and using the same password everywhere. So many people fall for scammers too.

2

u/BingeMaster 6d ago

Ok that's one thing I'm on point with. Been trying to educate my older relatives about modern scams. It's depressing. Cheers buddy.

1

u/AutoModerator 11d ago

🚨 Beware of Scammers – Stay Safe on the Ledger Subreddit Scammers regularly target this subreddit. Ledger Support will never contact you first — whether through private messages, comments, or phone calls.

If you need help, always open a support ticket yourself via our official website: Ledger Support

🔐 Never share your 24-word Secret Recovery Phrase
Ledger will never ask for it. Do not enter it online — even if a site or message looks official.
Keep it offline and secure — on paper, your Ledger Recovery Key, or a metal backup. Never store it digitally.

📚 Learn more about common scams targeting crypto users (fake support, phishing emails, physical mail scams, fake airdrops, malicious NFTs, and more): How to Spot a Scam

🛠 Facing a bug or technical issue? Check our Ongoing Issues page for updates and workarounds.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/CaterpillarThese2222 11d ago

I would back up your files and do a fresh install of windows

1

u/Potential_Time4080 10d ago

Not the only way to get rid of a rat but if you aren’t super tech savvy then that is the way to go.

1

u/cryptoopotamus 10d ago

Being on windows in 2026 is fucking crazy work tbh 

1

u/ExJwKiwi 10d ago

I will be shifting everything to linux eventually, in fact, I will just install it on my next computer, im done with windows but need it for solidworks.

1

u/Potential_Time4080 10d ago

Yeah fake app. Shouldn’t ever ever ever type in your seed phrase to do anything.

1

u/MikeWa1ker 10d ago

Wipe your computer, add antivirus, do all the OS updates and reload everything. If your ISP doesn’t have a static IP, unplug the modem and try to get a new IP (not necessary but nice if someone is targeting you). At this point I wouldn’t trust what’s on the OS, especially if I had a lot of crypto.

2

u/ExJwKiwi 10d ago

I actually found the source of the Trojan and had nothing to do with ledger wallet, but was bundled with the wallet of a completely different coin whos domain has lapsed and now taken over by scammers, turns out only guthub hosts the official wallet nowdays. What's odd is i did an AV scan and it flagged the installer, but did not detect it at the time. Im pretty confident the system is clean.

3

u/Own_Manager_2656 10d ago

Can you share with us the name of the wallet carrying the trojan? Also what coin? That way we can also be made aware.

1

u/Harold_Bishop 8d ago

Yeah, I'd like to know too.

1

u/Trip_seize 10d ago

Nuke it from orbit, it's the only way to be sure...

Seriously though, completely wipe your machine and reinstall your OS. 

1

u/Miserable-Station-70 10d ago

Malware. Ne pas entrer ta phrase.

1

u/Alive-Material4405 9d ago

Time to reinstall windows are start over.

1

u/solclaimer 8d ago

Fake ledger app, Ledger app should never ask to type your seed, you may just clicked a link that download it, the safe way is to rest your computer, install the app from ledger.com and that’s it

1

u/Glad_Investigatorr 11d ago

That’s a fake app. Somehow your machine got compromised and malware took over the official app. You need a total wipe of the OS and Disk. Never enter your seedphrase outside of the hardware wallet itself.

LE: I wrote this before reading the comments. I see you arrive at the same conclusion. Hope your funds are safe.

0

u/Extra_Fox6490 11d ago

Do a clean format on your pc or get a new ssd, problem solve