Mark Karpelès warns of tampered Ledger devices as coordinated wallet transfers draw scrutiny

Mark Karpelès warns of tampered Ledger devices as coordinated wallet transfers draw scrutiny

N
News Editor
2026-10-09 16:04:44
Former Mt. Gox CEO Mark Karpelès has warned that counterfeit or physically altered Ledger hardware wallets with hidden surveillance implants may have been sold on the market, raising concerns over a possible supply-chain compromise rather than a cryptographic flaw. According to monitoring cited by Bitcoin News, Karpelès publicly disclosed devices allegedly fitted with concealed SIM cards capable of transmitting stolen seed phrases. The implants were said to intercept data sent to the device screen, allowing attackers to capture recovery phrases shown during wallet setup. Karpelès said such devices could still pass Ledger’s official authenticity checks because the original secure element remained intact, while the verification process would not detect unauthorized physical modifications. One theory now circulating is that attackers collected seed phrases from affected devices and waited before moving funds from multiple wallets at the same time. The report said Karpelès’ warning drew roughly 90,000 views, which may have alerted the attackers that their operation had been exposed and prompted them to move stolen funds. Karpelès also said one affected device he examined came from Malaysia, arrived in intact shrink-wrap packaging, and had an implant hidden below the screen. Any connection between his warning and the later wallet transfers remains unconfirmed.

Former Mt. Gox CEO Mark Karpelès has publicly warned that tampered Ledger hardware wallets fitted with hidden monitoring implants may have surfaced in the market, and Bitcoin News said the disclosure may have preceded coordinated fund movements across multiple wallets.

Karpelès issued the warning on Oct. 8

On Oct. 8, Karpelès said counterfeit or altered Ledger devices were being sold with concealed SIM cards that could transmit stolen seed phrases. The implant was described as capable of intercepting data sent to the device screen, allowing an attacker to obtain the recovery phrase displayed when a user sets up a wallet.

He said such devices could still pass Ledger’s official authenticity check because the original secure element remained intact, while the verification process would not detect unauthorized physical modifications.

Theory points to staged theft followed by coordinated transfers

One emerging theory is that attackers collected seed phrases from compromised devices and then waited before moving funds from multiple wallets at the same time. The report said Karpelès’ warning drew about 90,000 views, which may have made the attackers aware that the operation had been exposed and pushed them to move the stolen funds.

Suspected attack vector is the hardware supply chain

Karpelès said one affected Ledger device he examined came from Malaysia, arrived in intact shrink-wrap packaging, and contained an implant hidden below the screen. The suspected attack path currently points to a compromised hardware supply chain rather than a flaw in cryptographic algorithms.

Still, no confirmed link has been established between Karpelès’ warning and the wallet fund transfers that followed. It also remains unconfirmed whether the same batch of implanted devices was involved. If verified, the case would show that even hardware that passes a manufacturer authenticity check can still undermine self-custody security when the device itself has been physically compromised.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.