Ledger Finds Unauthorized Hardware in Compromised Crypto Wallet

Ledger said it found an unauthorized component added after manufacturing in at least one user's hardware wallet, marking the first physical tampering evidence in its investigation. The device issue appears connected to the CryptoBilis security case, and the authorized dealer has paused hardware wallet sales. Former Mt. Gox CEO Mark Karpeles is separately reviewing images from affected users to verify the alterations.
Ledger's probe found an extra part inside at least one customer's hardware wallet that was not present when the device was made. The company links the matter to CryptoBilis, an authorized Southeast Asian seller that has stopped selling hardware wallets while inquiries continue. Ledger is working with affected users and law enforcement.
Separately, former Mt. Gox chief Mark Karpeles is reviewing user-submitted images and has removed a suspect component for examination. He previously reported finding a hidden electronic part in a Ledger Nano X from Malaysia whose packaging looked untouched. The tampering's scope and supply-chain point remain unknown.
Should the reported tampering prove more widespread, cryptocurrency holders who rely on hardware wallets may feel greater uncertainty about self-custody. Authorized resellers and manufacturers could face pressure to strengthen supply-chain checks and customer verification. Law enforcement and independent researchers may play a larger role in tracing compromised devices. For the broader public, the case could reinforce concerns that digital-asset security depends not only on software, but also on physical distribution and trust in vendors.