Security Analyst Describes Potential Seed-Phrase Theft Path in Ledger Device
A suspected implant could read screen data and transmit seed phrases through LTE or an eSIM, but the attack path has not been independently confirmed.

A suspected hardware implant in a Ledger wallet may capture users’ seed phrases through the device’s display connection, creating a potential path to asset theft if the reported modifications are accurate.
Security analyst 23pds described a scenario in which a malicious module reads the characters sent to the screen while a user sets up a wallet. The module could record the full seed phrase and transmit it through an LTE connection or eSIM.
The suspected component reportedly includes a microcontroller linked to the wallet’s SPI display bus, along with an antenna and cellular hardware. The analysis assumes that the wallet’s circuit board was altered as described by Mark Karpelès, the former CEO of Mt. Gox.
Karpelès said he received a Ledger device from Malaysia with intact shrink-wrap. He identified a concealed module positioned where a display buffer pad would normally sit and said it could analyze characters shown to the user.
A wallet’s secure element is designed to prevent direct access to or export of private keys. It would not necessarily block an external component from reading information displayed on the screen, making the suspected hardware path materially different from a direct key-extraction attack.