BlockBeats news, on October 10, SlowMist Chief Information Security Officer 23pds posted that if the modification of the Ledger device's PCB is indeed as described by former Mt. Gox CEO Mark Karpelès, then the attacker would possess a very high level of technical expertise.
The attack process may be as follows: the wallet generates the mnemonic phrase within the secure element (SE), then displays it on the screen for the user to manually record; a malicious module intercepts the displayed content via SPI or other screen data lines, captures the complete mnemonic phrase, and transmits the data to the attacker via LTE/eSIM, ultimately resulting in the theft of the user’s assets.
The secure element prevents private keys from being directly read or exported, but it cannot prevent external modules from capturing information displayed on the screen. However, the above analysis assumes that the PCB has indeed been modified as described; the related attack vectors and hardware tampering require independent verification.
BlockBeats reported yesterday that Mark Karpelès, former CEO of Mt. Gox, disclosed in a post that a Ledger hardware wallet he received appears to have been implanted with a spy module. The device originated from Malaysia; the outer shrink-wrap packaging was intact, and the tampering was difficult to detect upon opening, as the implant was concealed in the location where the screen’s original cushioning should have been.
Karpelès further explained that the module includes an LTE communication component, an antenna, an eSIM, and a microcontroller connected to the Ledger SPI bus, which analyzes the characters displayed on the device and transmits relevant data after the mnemonic phrase has been set up.


