KryptoFeed
Crypto● Neutral 2 min

Ledger Investigates Crypto Losses as Spy Chip Allegations Surface

Ledger Wallet

Mark Karpelès, former chief executive of Mt. Gox, said on Oct. 9 that a Ledger hardware wallet he obtained in Malaysia contained a concealed cellular module, despite intact shrink-wrap packaging. He alleges the implant could capture a wallet’s recovery phrase during setup and transmit it over LTE.

Security analyst 23pds outlined a possible mechanism: a microcontroller taps the display’s data line, records the seed words when they appear on screen, then sends them through LTE or an eSIM. That route could bypass the secure element’s protection against direct private-key extraction by reading information displayed during setup. However, the reported hardware and attack method have not been independently confirmed.

The claim surfaced as Ledger investigates reports of crypto losses among Southeast Asian customers who bought devices through reseller CryptoBilis. Ledger has asked the reseller to pause sales and shipments, and advised buyers from the past 90 days not to initialize devices or to move funds to a new signer with a newly generated recovery phrase. On-chain analysts have estimated losses at $72 million to more than $86 million, but the total and cause remain unconfirmed. Karpelès has not said his device came from CryptoBilis, and Ledger has not blamed the reseller or confirmed a spy-chip link.

Why it matters

A compromised hardware wallet could undermine crypto self-custody without breaching the manufacturer's core software. Establishing how the devices were altered and where the tampering occurred will be critical to determining responsibility and the extent of the risk.

Yasmin Farouk
Economy Editor

Yasmin writes about central banks, inflation and IMF programmes with a focus on Egypt, Turkey and the wider region. She spent six years at a Cairo business weekly before joining KryptoFeed.

Up next