Live Prices
Bitcoin

Mark Karpelès Finds Hidden Spy Chip Inside Sealed Ledger Hardware Wallet

TheCryptoDesk Editorial · 2m read
Mark Karpelès Finds Hidden Spy Chip Inside Sealed Ledger Hardware Wallet

Former Mt. Gox chief Mark Karpelès revealed on October 9, 2026, that he discovered a hidden spyware circuit board fitted with an antenna and a small SIM card inside a factory-sealed Ledger hardware wallet. The modified device, which originated from Malaysia and arrived in pristine shrink wrap, was designed to transmit a wallet's 24-word recovery phrase remotely to attackers without leaving physical signs of tampering.

Hardware Tampering Bypasses Genuine Checks

According to Karpelès, who managed Mt. Gox prior to its 2014 collapse, the malicious hardware was cleverly concealed behind the device screen where protective padding is usually located. The integrated SIM card and antenna allow malicious actors to extract the 24-word seed phrase required to empty funds remotely, removing the need for physical access after the initial compromise.

Crucially, Ledger's standard Genuine Check verification system fails to detect these hardware modifications. While the automated check confirms the authenticity of the primary security chip, Ledger acknowledges in its documentation that the software cannot identify external physical components added around the chip. Consequently, a compromised wallet can successfully pass authentic validation while actively leaking sensitive screen data.

Supply Chain Risks and Millions in Wallet Losses

The revelation comes amid ongoing scrutiny over security vulnerabilities in third-party retail channels. On-chain investigators initially linked compromised devices to $86 million in drained funds, leading Ledger to investigate reseller CryptoBilis and ask the Malaysian distributor to stop selling and shipping inventory. Subsequent analysis by Bitquery raised the total estimated losses to $92.9 million across 311 wallets, with one individual victim losing 80 Bitcoin.

Key details of the security discovery include:

  • Mark Karpelès identified a hidden spyware board with a SIM card and antenna inside a shrink-wrapped Ledger device.
  • The implant sits behind the display screen and extracts the 24-word recovery phrase while bypassing Ledger's software-based Genuine Check.
  • Bitquery estimates total connected exploit losses at $92.9 million across 311 wallets, though Ledger has not confirmed these figures.
  • Ledger previously requested Malaysian vendor CryptoBilis to pause operations following widespread reseller sales suspensions, though Karpelès stated his unit came from a different vendor.

Why It Matters

This discovery highlights a critical vulnerability in self-custody infrastructure: software-based authenticity checks are insufficient to guarantee supply chain integrity against sophisticated hardware interdiction. As hardware wallet manufacturers rely on third-party distribution partners like Amazon, Shopee, and Lazada, physical tampering before delivery undermines the core promise of cold storage security. Going forward, institutional and retail users will likely demand tamper-evident hardware designs or direct-from-factory verification protocols to mitigate supply chain intercept attacks.

Read next