How to OPEN & Verify the Security Integrity of a LEDGER NANO S (and how to not ruin one in the process)

in #ledger7 years ago (edited)

First off, I would like to say congratulations on purchasing a hardware wallet! You are on the right path of protecting your assets and being your own bank. The fact that you are reading this also implies that you are doing your due diligence and ensuring that your LEDGER NANO S is authentic and unaltered.

There is a "guide" on ledger's website (https://ledger.zendesk.com/hc/en-us/articles/115005321449-How-to-verify-the-security-integrity-of-my-Nano-S-) that somewhat explains the process of checking that the chip inside is the original from the factory and no others have been added. I found this guide to be lacking in some crucial details on the actual process of opening the case and putting back together..


Here is what else you should know:
IMPORTANT

The following steps should be done BEFORE adding funds to your Ledger! If you already have funds on your ledger then make sure you have a back up of your seed!

OPENING THE LEDGER
IMPORTANT
Make sure the ledger is flat on a table, with the screen side down for the entirety of this process. The contents are loose inside of the case and if you pick up up or turn it upside down it will all fall out and you may break the device trying to put it back together again. Older versions had glue holding it together, which i assumed was still the case. I destroyed my ledger because of this mistake.. DO NOT PICK UP THE LEDGER DURING THIS PROCESS JUST LEAVE IT FLAT ON THE TABLE!!

  1. First, carefully pull open and remove the metal cover from the device

  2. Using a hobby knife, pry open from the back the Ledger case while taking extreme care as to not break the plastic or stab something inside the device. I recommend opening it at the end opposite of the micro usb port as there are no components there

  3. Once the case is open visually inspect the chip. We want to check that the MCU is an stm2f042k6...The markings may vary slightly but it should have the string "042K6" on it somewhere. Ensure that no chips have been added or replaced and visually compare to my photos and those at the link above.

  4. After you have verified the chip markings, replace the plastic cover on the back. Starting at one end click the cover back in place while taking care as to not break it...REMEMBER dont pick up your device if possible just leave it flat on the table. The micro usb port should line up with the case and the buttons should "click". If they do not you may have to do some VERY CAREFUL re-positioning of the board/screen/and or buttons.

  5. Once your case is back together you can plug your ledger into the computer and start up the ledger manager app. If everything works properly and you do not get any warnings from the app then your device is genuine and unaltered!

  6. Replace the metal cover, add funds, enjoy your peace of mind in knowing your funds are safe!

There are some additional commands you can run for the tinfoil hat types out there who would like even further verification that I have not covered in this guide. They can be found at the link posted in the beginning of the article.

Note: I did exactly what you should not do, which was pick up the device and turn it upside down while it was apart. I assumed there was something holding the components in there (such as glue according to ledger's "instruction"). Everything fell out and I broke part of the screen trying to fit it all together again with the buttons , screen, and usb port. This is actually extremely difficult and everything is super fragile.

*Any tips are greatly appreciated and will go directly towards replacing the ledger that was destroyed during this process!

BTC: 34yQfybHwvv76ibehTstZH4gxLdQuE1zqN

LTC: 344iFgCCeiwShiUPYSt1pc7vE8c99iyLF3

ETH: 0x1E1837E8C9783483c926BB51c739AC4D99cab733

XMR: 47bWcSg6gmnG91cZPWY7BR7SB8YSV2XRQaDNXZ9QvAPvYquMUiacNGP8ww1hMqGC7ra9AcXk8LD4oGVF8ZR5sBFUVAXSz1c

Sort:  

Very good information, you making sure all is secure.
Thanks for sharing

thank you for reading!

good information

Thank you, I am surprised that nobody had done this before. I felt responsible to share my experience as it could save someone a lot of heartache!

Congratulations @cryptohblock! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

You published your First Post
You made your First Vote
You made your First Comment
You got a First Vote

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here

If you no longer want to receive notifications, reply to this comment with the word STOP

By upvoting this notification, you can help all Steemit users. Learn how here!

I accidentally deleted half of this article while editing a typo..so I rewrote it from scratch.

This is a fantastic article! I was having heart palpitations after watching a video about a ledger nano scam, and after using your easy to follow instructions I was able to quickly validate my nano!

Thanks for this!

Well done. Thanks!
I got the link to this article from the amazon comments section of the ledger product page.
Going to resteem it, something I never do...

Congratulations @cryptohblock! You have received a personal award!

1 Year on Steemit
Click on the badge to view your Board of Honor.

Do you like SteemitBoard's project? Then Vote for its witness and get one more award!

Great info ~ thank you..! i might add that a guy lost his life savings from having his recovery seed phrase tampered with which might be worthwhile looking into also, the link to the article is here ..

https://news.bitcoin.com/mans-life-savings-stolen-from-hardware-wallet-supplied-by-a-reseller/

Congratulations @cryptohblock! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 2 years!

You can view your badges on your Steem Board and compare to others on the Steem Ranking

Vote for @Steemitboard as a witness to get one more award and increased upvotes!