Former Mt. Gox CEO Mark Karpelès stated on X on October 9 that a Ledger Nano X he received from Malaysia appears to have been implanted with a spy module containing LTE communication components, an antenna, an eSIM, and a microcontroller connected to the screen's SPI bus. The next day, 23pds, partner and chief information security officer at SlowMist, speculated on the process by which the mnemonic phrase may have been leaked, adding that these are currently only hypotheses.
(Prior context: Douyin sells cold wallet, $6.9 million stolen; SlowMist analysis: Private key leaked during generation process)
(Background supplement: Cold Wallet Scam: New Trezor Devices Infected with Microchip, Users Lose Millions in Cryptocurrency)
Key Highlights
- Mark Karpelès stated on October 9 that a Ledger device appears to have been implanted with a spy module.
- The embedded module includes four components: LTE, antenna, eSIM, and microcontroller.
- SlowMist speculated on October 10, 2023, that a module monitoring screen lines captured the mnemonic phrase.
At around 11 p.m. Taiwan time on October 9, Mark Karpelès, former CEO of Mt. Gox, posted on X that his Ledger device, suspected of having a spy module implanted, came from Malaysia and had intact shrink-wrapped packaging. He said that upon opening the casing, he initially saw no signs of the implant, as it was hidden in the spot where the screen’s cushioning was originally placed.
My spy-implanted ledger came from Malaysia and had flawless shrink wrap. Even when opening it, at first you don’t see the implant, which is cleverly hidden where the screen’s padding is supposed to be.
Follow Ledger's guidance to check yours: https://t.co/FlOjWvqkZwpic.twitter.com/D8mixF1o9L— Mark Karpelès (@MagicalTux) October 9, 2026
A netizen asked how the module sends out data; Mark Karpelès replied by listing the components. The components include an LTE communication module, an antenna, an eSIM, and a microcontroller connected to the Ledger SPI bus. The eSIM is a chip-type SIM card directly soldered onto the circuit board, enabling the module to connect to a mobile network on its own.
Mark Karpelès previously explained that the SPI bus is the pathway Ledger uses to send display data to the screen. By monitoring the signals on this line, one can view the screen content, including the recovery phrase displayed during setup. He said that this microcontroller analyzes the letters shown on the screen to the user and transmits the data once the seed is set. Attackers can then monitor the victim’s wallet address and choose the optimal moment to transfer all assets away.
The research page compiled by Mark Karpelès on the Tibane Labs website states that the implant does not interact with the secure element—the specialized chip in hardware wallets that generates and stores private keys. Therefore, Ledger’s verification process to confirm the device’s authenticity will still pass. He noted that the next step will involve analyzing the SIM card and microcontroller within the module, including extracting the firmware—the actual programs running on the chip.
SlowMist speculates on the theft process
SlowMist partner and Chief Information Security Officer 23pds responded with a post at around 8 a.m. Taiwan Time on October 10. He wrote: “If, as @MagicalTux said, the modification was made on the PCB, then this is a true expert…” PCB stands for printed circuit board—the board inside the device that holds the various chips.
23pds suspects that the seed is first generated inside a secure element, and the mnemonic phrase is then displayed on the screen for the user to write down. A malicious module connected to the screen’s data lines (e.g., SPI) captures the displayed words. Once all words are recorded, the module transmits them via LTE or eSIM, allowing attackers to steal the mnemonic and drain the assets.
If it's truly as @MagicalTux said, modifying the PCB, then this is a master...
Process:
The seed is generated in the SE—mnemonic words are displayed for you to copy—on the screen—malicious module connected to the screen data line (e.g., SPI)—records the displayed words—after collecting all, transmits them via LTE/eSIM.
The attacker obtained the mnemonic phrase and transferred the assets. … pic.twitter.com/Kti73LbJhA— 23pds (Shan Ge) (@im23pds) October 10, 2026
23pds said that the secure element only protects private keys from being read or transmitted outward, but cannot prevent someone from taking a screenshot of the screen. He later added, "This is currently all speculation," and that more information will depend on Ledger's final investigation results. Yu Xian, founder of SlowMist, stated that embedding LTE, eSIM, or other components into a hardware wallet to monitor and transmit plaintext displayed on the screen "also makes logical sense," and the team will verify this once they obtain a sample.
The device was purchased from Amazon Japan; Ledger has not yet made a statement.
Ledger announced on October 9 that it is investigating the fund losses of buyers from the Southeast Asian distributor CryptoBilis. Mark Karpelès's research page states that this device was purchased on Amazon Japan from a Chinese third-party seller, with the package shipped from Malaysia. The research page also notes that the device was not purchased from CryptoBilis, and there is currently no evidence linking the two.
As of 10 a.m. Taiwan time on October 10, neither Ledger’s official X account nor CTO Charles Guillemet have issued any statement regarding the module unveiled by Mark Karpelès; the investigation is ongoing.
Frequently Asked Questions
How does the Ledger spy module steal recovery phrases?
According to Mark Karpelès, the microcontroller of the module is connected to the SPI bus that transmits the screen display on Ledger, analyzes the letters shown on the screen, and sends the mnemonic phrase via LTE and eSIM as soon as it is set.
Has Ledger responded to the spyware module implantation?
As of October 10 in Taiwan time, Ledger has not yet issued a statement regarding the module split by Mark Karpelès, and has only informed Cointelegraph that its systems were not compromised and that the investigation is ongoing.
📍Related Reports📍
She bought a "scam cold wallet" on JD.com and lost 4.35 BTC deposited inside.



