Ledger, the renowned manufacturer of cryptocurrency hardware wallets, has made a significant discovery in its investigation into alleged asset thefts. The company reports finding an unauthorized hardware component added post-manufacture to at least one user’s device, raising concerns that some Ledger wallets may have been tampered with before reaching their owners.
First Concrete Evidence in Ongoing Inquiry
In a recent update dated October 10, Ledger revealed that this extra component was found in the device of an affected user. The incident appears to be linked with the recent CryptoBilis security case. CryptoBilis, an authorized dealer in Southeast Asia, has suspended all hardware wallet sales as a precaution until the investigation concludes.
This marks the first tangible evidence of physical tampering uncovered during the inquiry. However, there remains uncertainty regarding whether this added hardware is directly related to the alleged thefts and the number of devices potentially compromised.
Ledger has stated that they are in contact with affected users and are collaborating with law enforcement to identify the culprits.
A key aspect of the investigation is the possibility that the attack might not necessitate direct access to the device’s secure element. Known for generating and safeguarding private keys, the secure element is a critical component. The unauthorized piece found was reportedly installed to monitor data flow by connecting to communication lines between the wallet’s internal components and the display.
Parallel Inquiry by Former Mt Gox CEO
This development coincides with a parallel independent investigation led by Mark Karpeles, the former CEO of the defunct cryptocurrency exchange Mt Gox. Karpeles claims to have independently verified these hardware alterations through images submitted by affected users. Notably, Mt Gox is infamous for its significant financial setback in 2014.
Karpeles confirmed he could validate these changes through images sent by affected users, inviting those willing to share their devices for analysis to contact him directly.
In a subsequent statement, Karpeles revealed he had begun examining one of the suspect components by removing it. He also reported previously discovering a concealed electronic part inside a Ledger Nano X device from Malaysia, even though its external packaging appeared intact.
As the investigation progresses, the exact scope of the tampering, its occurrence point within the supply chain, and whether other vendors might be affected remain unclear. While Ledger and independent researchers persist in their examinations, devices with suspected physical breaches are advised against use and should undergo detailed technical scrutiny.



