Choose Rich Live
Crypto News

Ledger confirms unauthorized hardware implant in customer device amid theft probe

Ledger confirmed finding an unauthorized physical hardware implant inside an affected customer's device, while reseller CryptoBilis suspended wallet sales amid reported crypto losses exceeding $86 million.

A close-up view of a disassembled hardware wallet circuit board showing an unauthorized microchip implant.
Image: @WuBlockchain

Ledger confirmed that an unauthorized hardware implant was discovered inside an affected customer's device, confirming physical tampering prior to delivery. According to the company, there is no evidence that Ledger's own security infrastructure, systems, or services were compromised. Ledger stated that the incident appeared isolated to a single reseller and its Southeast Asian market, while distributor CryptoBilis confirmed it has suspended sales of all hardware wallet inventory until the investigation concludes.[1][3][5][8]

Reported losses linked to the thefts range between $86 million and $93.4 million. In parallel reports, former Mt. Gox CEO Mark Karpelès said a Ledger Nano X he received from Malaysia arrived in intact shrink-wrap packaging but concealed a spy module equipped with an LTE chip, antenna, and SIM card where the screen padding should be. Ledger stated that it is cooperating with authorities alongside security group SEAL_911, advising users who bought devices from the affected reseller not to initialize them or to migrate assets immediately using a new recovery phrase.[1][2][3][4][5][6][7][8]

Key facts

  • Ledger confirmed an unauthorized hardware implant was found inside an affected customer's device.
  • Ledger stated its own infrastructure, systems, and services were not compromised, indicating the issue appeared isolated to a single reseller in Southeast Asia.
  • Distributor CryptoBilis halted sales of all hardware wallet inventory pending the investigation.
  • Reported losses linked to the incident have been estimated between $86 million and $93.4 million.
  • Former Mt. Gox CEO Mark Karpelès reported finding a spy module with an LTE chip and SIM card hidden beneath the screen padding of a Ledger Nano X shipped from Malaysia.
  • Ledger recommended that users who bought devices from the affected reseller avoid setting them up or transfer assets using a newly generated recovery phrase.

Sources · 6 sources

  1. CT

    Coin TelegraphArticle ·

    Ledger confirms unauthorized hardware implant, says losses may exceed $86M Ledger said the incident appeared to be isolated to a single reseller and its Southeast Asian market.

    Open source
  2. BC

    Bitcoin.com News@BitcoinNewsPost on X ·

    🚨 JUST IN: Ledger confirms unauthorized hardware implant in customer wallet as $93.4M crypto theft mystery deepens. https://t.co/9VHAE6TY7w

    Open source
  3. SI

    Solid Intel 📡@solidintel_xPost on X ·

    INTEL: Ledger confirms an unauthorized hardware implant was found in an affected customer's device amid its investigation into major crypto wallet thefts https://t.co/uKftIoVNlL

    Open source
  4. CB

    Crypto Banter@crypto_banterPost on X ·

    🚨EX-MT. GOX CEO FINDS A CHIP IN A LEDGER! @MagicalTux, the former Mt. Gox CEO, says a Ledger Nano X he got from Malaysia had a spy module hidden where the screen padding should be. The shrink wrap looked fine. He says it had an LTE chip, an antenna, an eSIM, and a part wired to the screen bus that could read the seed as it is set. He bought it from a non-authorized seller, not Ledger. Always buy hardware wallets from the maker, not a reseller.

    Open source
  5. SN

    Saanjana Nikita@Saanjana_NikitaPost on X ·

    ledger confirmed a hardware implant was found in one of the affected devices the secure chip wasn’t hacked. someone added extra hardware before the wallet reached the buyer. it could capture recovery words during setup and send them out over a cellular connection that’s the scary part. the device could look completely normal if you bought through the affected reseller, don’t use it. already entered your seed? move your funds to a trusted device with a fresh seed. never reuse the old one ledger says its own systems are fine, but that doesn’t solve the problem for people who lost money reported losses are around $93m, though that figure hasn’t been verified buy direct from the manufacturer. and never treat your recovery phrase as safe just because your wallet looks legit

    Open source
  6. WB

    Wu Blockchain@WuBlockchainPost on X ·

    Former Mt.Gox CEO Says Ledger Device Purchased From Malaysia Contained a Spy Module With a SIM Chip Despite Intact Packaging Former Mt.Gox CEO Mark Karpelès said a Ledger Nano X hardware wallet he received from Malaysia had intact shrink-wrap packaging but contained a spy module hidden where the screen padding should have been, making it difficult to spot even after opening the casing. He shared comparison photos of the original circuit board and the implant, saying such implants have evolved from hand-soldered wiring into circuit boards that are easier to mistake for original hardware. Karpelès is requesting device photos from affected users to identify similar implants and advised following Ledger's official security guidance. Ledger has not been shown to have officially confirmed the module's functionality or any connection to recent CryptoBilis customer losses.

    Open source
  7. SI

    Solid Intel 📡@solidintel_xPost on X ·

    INTEL: Former Mt. Gox CEO finds suspected spy module with SIM chip inside Ledger wallet bought in Malaysia https://t.co/ij65p8t0bA

    Open source
  8. WB

    Wu Blockchain@WuBlockchainPost on X ·

    Ledger Confirms Hardware Implant Attack, Says Its Systems Were Not Breached Ledger said an unauthorized hardware implant was found inside an affected device, confirming physical tampering. The company said there is no evidence its own infrastructure, systems or services were compromised, while distributor CryptoBilis has suspended hardware wallet sales. Ledger advised affected users to avoid initializing unused devices and consider moving assets to wallets created with new recovery phrases. Earlier on-chain analysis estimated losses linked to the incident at more than $86 million.

    Open source