The box was sealed. The plastic wrap was perfect. But inside, the Ledger hardware wallet had a tiny circuit board designed to steal the password and the owner’s crypto. This is according to former Mt. Gox chief Mark Karpelès.
Karpelès, who ran the exchange that collapsed in 2014, says the spyware was hidden behind the screen, where a piece of padding should have been. It carried an antenna and a small SIM capable of transmitting a wallet’s 24-word recovery phrase.
Those words are enough to empty the crypto wallet remotely. An attacker would never need to touch the device again.
Ledger’s Security Check Might Miss the Spy Chip
Ledger’s Genuine Check confirms that a device contains an authentic security chip. But it cannot detect every physical alteration around that chip. This is a limitation Ledger acknowledges in its own guidance.
A tampered wallet could therefore pass the check while a hidden component watches the screen.
The discovery comes as Ledger investigates reports of emptied wallets involving Malaysian reseller CryptoBilis. Ledger has asked the company to stop selling and shipping its devices.
On-chain investigators initially estimated losses above $86 million.
A subsequent Bitquery analysis put the figure at $92.9 million across 311 wallets. Ledger has not confirmed those totals. One victim reportedly lost 80 Bitcoin.
Karpelès says his device came from a different seller. Ledger has not established that tampered hardware caused the CryptoBilis losses.
So Who Takes Responsibility?
Some blame the shoppers.
Yet Ledger itself recommends authorised resellers, including official storefronts on Amazon, Shopee and Lazada.
A hardware wallet is supposed to remove the need to trust anyone with your money. Yet buying one from a middleman means trusting a stranger with the very device that guards it.
For anyone trusting a pocket-sized device with their savings, that is a difficult warning to ignore.
The post Hidden Spy Chip Found Inside a Sealed Ledger Wallet appeared first on BeInCrypto.
