Hidden Chip in Sealed Ledger Wallet Puts Hardware Security Under Pressure
A hidden chip could intercept the 24 recovery words, increasing the risks of hardware wallets bought through third parties. At the same time, Ledger is investigating reports of drained wallets through a Malaysian reseller.

Key Takeaways
- Mark Karpelès says a sealed Ledger wallet contained a hidden circuit that could steal the 24 recovery words.
- Ledger’s Genuine Check confirms a real security chip, but it does not detect every physical modification around that chip.
- Ledger is also investigating drained wallets through reseller CryptoBilis and recommends buying through authorized sellers.
A sealed Ledger hardware wallet turned out to contain a hidden circuit that could steal the 24 recovery words, according to former Mt. Gox executive Mark Karpelès. If that is true, an attacker could drain a crypto wallet remotely without ever touching the device again. The case once again raises questions about the safety of hardware wallets bought through third parties.
Hidden Chip Behind the Screen
Karpelès says the box was still sealed and the plastic seal was intact. According to him, behind the screen, in the spot where padding would normally be, there was a small circuit board with an antenna and a SIM card. That chip could then send out the 24-word recovery phrase.
Those words are enough to access the wallet and take the funds out. Ledger’s Genuine Check does confirm that a device contains a real security chip, but it cannot detect every physical modification around that chip. Ledger itself also notes that limitation in its explanation.
Investigation Into Empty Wallets
The report comes as Ledger is also investigating reports of drained wallets through the Malaysian reseller CryptoBilis. The company has asked that party to stop selling and shipping Ledger devices. Investigators first estimated the damage at more than $86 million (€76.7 million), while a later Bitquery analysis put it at $92.9 million (€82.9 million) across 311 wallets. Ledger has not confirmed those amounts.
Karpelès says his device came from a different seller. That means it has not been established that the same kind of tampered hardware was behind the CryptoBilis cases. Still, the case fits into a broader wave of attacks on hardware wallets. In August 2026, for example, hackers used a firmware flaw in Coldcard wallets to steal more than $130 million (€116 million) in crypto without any physical contact with the devices. Earlier reports around CryptoBilis also show how big the damage can be when the hardware wallet supply chain is abused.
Why This Matters
For European crypto users, the main takeaway is that a hardware wallet is not just about software, but also about the chain around it. A sealed box or a real security chip does not automatically rule out tampering if a device is altered in transit or through an intermediary. Ledger itself recommends buying through authorized sellers, precisely because that makes the device’s origin easier to trace.