Former Mt. Gox CEO Mark Karpelès has publicly warned that tampered Ledger hardware wallets fitted with hidden monitoring implants may have surfaced in the market, and Bitcoin News said the disclosure may have preceded coordinated fund movements across multiple wallets.
Karpelès issued the warning on Oct. 8
On Oct. 8, Karpelès said counterfeit or altered Ledger devices were being sold with concealed SIM cards that could transmit stolen seed phrases. The implant was described as capable of intercepting data sent to the device screen, allowing an attacker to obtain the recovery phrase displayed when a user sets up a wallet.
He said such devices could still pass Ledger’s official authenticity check because the original secure element remained intact, while the verification process would not detect unauthorized physical modifications.
Theory points to staged theft followed by coordinated transfers
One emerging theory is that attackers collected seed phrases from compromised devices and then waited before moving funds from multiple wallets at the same time. The report said Karpelès’ warning drew about 90,000 views, which may have made the attackers aware that the operation had been exposed and pushed them to move the stolen funds.
Suspected attack vector is the hardware supply chain
Karpelès said one affected Ledger device he examined came from Malaysia, arrived in intact shrink-wrap packaging, and contained an implant hidden below the screen. The suspected attack path currently points to a compromised hardware supply chain rather than a flaw in cryptographic algorithms.
Still, no confirmed link has been established between Karpelès’ warning and the wallet fund transfers that followed. It also remains unconfirmed whether the same batch of implanted devices was involved. If verified, the case would show that even hardware that passes a manufacturer authenticity check can still undermine self-custody security when the device itself has been physically compromised.

