1 min read
Add as a preferred source on Google

Mark Karpelès Says Ledger Device Contained Module That Could Capture Seed Phrases

Mark Karpelès said a Ledger device purchased in Malaysia contained a hidden module with a SIM card, while 23pds outlined a possible screen-interception attack.

Hardware wallet beside a disassembled cellular communication module / TokenPost.ai
Hardware wallet beside a disassembled cellular communication module / TokenPost.ai

A Ledger device allegedly modified with a cellular-enabled module could expose wallet seed phrases by capturing words displayed during setup, creating a security risk beyond direct private-key extraction.

Mark Karpelès, the former CEO of Mt. Gox, said a Ledger device he purchased in Malaysia contained a spy module with a SIM card. He said the component was hidden near the screen and the external packaging appeared intact.

23pds, chief information security officer at SlowMist, outlined a possible attack in which the module connects to the screen’s data line and records the words shown when a seed phrase is generated. The captured information could then be sent to an attacker through LTE or an eSIM.

The analysis distinguishes between protection of private keys and protection of displayed information. A secure element can prevent private keys from being read directly, but it cannot by itself stop malicious hardware from intercepting screen data.

The claims focus on a potentially compromised device in the supply chain, rather than a confirmed weakness in every Ledger wallet. Users’ exposure would depend on whether a device had been physically altered before reaching them.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…