Ledger hardware supply chain attack may have been exposed before large-scale wallet transfers

iconjinse2
Share
AI summary iconSummary
A distributed ledger security breach may have been detected before large-scale wallet transfers occurred. Former Mt. Gox CEO Mark Karpelès revealed tampered Ledger devices containing hidden monitoring implants. These devices, allegedly sold with concealed SIM cards, could steal recovery phrases during setup. On-chain data indicates the implants bypassed Ledger’s authenticity checks. One device from Malaysia had a hidden implant located beneath the screen. Karpelès issued a warning about these devices on October 8. The attack vector involves a compromise of the hardware supply chain. The connection between the warning and the fund transfers remains unconfirmed.

Ledger hardware supply chain attack may have been exposed prior to large-scale wallet fund transfers, as former Mt. Gox CEO issued warning. According to Jinsecai, on October 10, Bitcoin News reported that former Mt. Gox CEO Mark Karpelès publicly disclosed physically tampered Ledger devices containing hidden monitoring implants, potentially inadvertently triggering coordinated fund transfers across multiple wallets. On October 8, Karpelès warned that counterfeit or tampered Ledger devices with hidden SIM cards were being sold on the market; these SIM cards can transmit stolen seed phrases. The alleged implants are capable of intercepting data sent to the device’s screen, thereby capturing the recovery phrase displayed during wallet setup. Such devices are reportedly still passing Ledger’s official authenticity verification, as the original secure element remains intact and the verification process cannot detect unauthorized physical modifications. A growing theory suggests attackers are collecting seed phrases from compromised devices and waiting to simultaneously transfer funds from multiple wallets. Karpelès’s warning, reportedly viewed approximately 90,000 times, may have alerted attackers that their activities had been exposed, prompting them to move the stolen funds. Karpelès stated that one compromised Ledger device he inspected originated from Malaysia, packaged in undamaged heat-shrink film, with an implant concealed beneath the screen. The suspected attack vector is a compromised hardware supply chain, not a cryptographic vulnerability. The connection between Karpelès’s warning and the subsequent wallet fund transfers has not been confirmed, nor has it been verified whether the same implants were responsible. If substantiated, this incident would demonstrate that even hardware passing manufacturer certification can compromise user asset self-custody if compromised.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.