Notizie

Ledger Reseller Incident: How a Hardware Implant Reads a Seed Phrase

Ledger Reseller Incident: How a Hardware Implant Reads a Seed Phrase

Main Takeaway: On October 9, 2026, Ledger said it was investigating reports of lost funds from users in Southeast Asia who bought devices through one reseller. One buyer published photos of a hidden module behind the screen of a device that arrived in intact shrink wrap. The device passed the maker's genuine check, which verifies the chip and firmware, not what else sits inside the case.

Quick Reference

Term What it means here
Supply chain attack A device is modified between the factory and the buyer.
Hardware implant An extra board placed inside a device to capture or transmit data while the original parts keep working.
Genuine check A software test that confirms the secure chip and firmware are authentic, not what else sits inside the case.
Tamper-evident Built so that opening the device leaves visible damage.

What happened in the Ledger reseller incident?

Ledger posted on October 9, 2026 that it was investigating reports of lost funds from users in Southeast Asia who had bought products from a reseller named CryptoBilis. Ledger asked the reseller to pause sales, told recent buyers not to start setup, and advised anyone already set up to consider moving assets to a new seed phrase. Ledger also said it had no indication that its own systems were compromised.

On-chain analysts estimated losses above $86 million. Ledger has not confirmed a figure or a root cause, and ELLIPAL has not verified these numbers.

The clearest technical evidence so far comes from one buyer. Mark Karpelès, the former Mt. Gox chief executive, posted photos of a device shipped to him from Malaysia. He reported that it arrived in flawless shrink wrap, passed the vendor's genuine check, and carried a module behind the screen with an LTE radio, an eSIM and a small controller wired to the display. Hardware like that would be able to read the seed phrase as the screen shows it during setup and transmit it, though Ledger has not confirmed that this is what happened. Whether every reported loss involves the same kind of implant is still being investigated.

How does a hardware implant read a seed phrase?

A hardware implant targets the one moment the seed phrase has to be visible: during setup, when the device shows the words so the owner can write them down. In the device Karpelès described, an implant would leave the secure chip, the firmware and the private keys untouched. It would listen to the signal that drives the screen, decode the letters and transmit them. The keys stay inside the chip, and the attacker already holds the words that regenerate them. Any wallet that shows the seed phrase on a screen, including ELLIPAL Titan 2.0, has this moment during setup. What differs between designs is how hard it is to open the case without leaving a trace.

A genuine check is built to confirm that the secure chip and firmware are authentic, and by Karpelès's account the implanted device passed. A box seal only shows whether the box was opened with care. The device itself is where tampering can show, because reaching the display means opening the case, and each design makes that step easy or hard to hide. Makers answer the risk with an authenticity check in the app, an activation history or the construction of the case, and these approaches complement each other.

What makes tampering visible on ELLIPAL Titan 2.0?

ELLIPAL Titan 2.0 is milled from a single block of metal with no screws. The components go in from the front and are sealed in place with the display, so the display is the seal.

The adhesive is chosen to melt above what the touchscreen can tolerate, so the design intent is that the screen shows damage before the case comes apart. Opening the case is also designed to trigger the Self-Destruct Mechanism, which wipes all private keys and leaves the device inoperable.

A sealed body changes what a tampered unit looks like on arrival: the design intent is a damaged screen or a device that does not power on, and either is a reason to stop before setup. ELLIPAL describes this as design intent, since no construction puts a device beyond every attack.

How to check a hardware wallet before you set it up

  1. Buy from the maker's official store or from a channel the maker lists on its own website.
  2. Before powering on, check the body and screen edges for cracks, lifted corners, glue marks or scratches.
  3. Run the maker's genuine check if one exists, and treat a pass as one signal, not a verdict.
  4. Create the seed phrase on the wallet's own offline hardware, write it down by hand and do not enter it into any app, website or checker.
  5. If anything looks off, stop and contact the maker's support through its official website.

Which situation matches yours?

  • You bought from an official store. These reports concern one reseller, and the checklist above still applies.
  • You bought from a third-party seller and have not set up yet. Inspect the device, then contact the maker's support before you start.

Where an ELLIPAL wallet fits

ELLIPAL Titan 2.0 keeps private keys inside a secure chip and signs by QR code, with no Bluetooth, WiFi or USB data connection. ELLIPAL X Card is an NFC cold wallet: the seed phrase is created on the offline Starter, and the card signs with a tap. Different tools. Same mission. The ELLIPAL official store and the channels listed on ellipal.com are where to buy either device, and ELLIPAL support is the first stop if anything looks off.

Frequently Asked Questions

Is it safe to buy a hardware wallet from a reseller?

The maker's official store carries the least risk, followed by channels the maker lists on its own website. A reseller adds a stage between factory and buyer, and the reports in this incident point to that stage. Inspect the device first.

Does the Self-Destruct Mechanism help before the device is set up?

Before setup there are no private keys to wipe. At that stage the relevant design intent is that opening the case damages the screen and leaves the device inoperable.

Is a cheaper device from a third-party seller worth the saving?

The price gap is small next to what the device will hold. If the saving matters, buy from a channel the maker lists and keep the receipt.

Can I recover funds taken through a tampered device?

On-chain transfers are final, so recovery is rare. Move whatever remains to a fresh wallet created on a device you trust. Keep the device and packaging as evidence and report the case to the maker and local police. Do not pay anyone offering recovery.

About ELLIPAL

ELLIPAL has been on the market since 2018, with more than 1 million users in 140+ countries. ELLIPAL wallets support 10,000+ tokens across 45+ chains and follow the BIP39 and BIP44 standards. ELLIPAL does not hold customer funds or provide investment advice.

For how ELLIPAL devices are built, read the ELLIPAL Security Lab page or see ELLIPAL Titan 2.0

Perché le persone si fidano di ELLIPAL
ZeroViolazioni dei cold wallet
Oltre 1 milioneUtenti in tutto il mondo
140+Paesi raggiunti
12 miliardi di dollariRisorse protette
ForbesConsigliato
8 anniAir-gapped dal 2018

Fattelo tuo. Poi usalo.

Le tue chiavi, le tue criptovalute. Conserva la tua frase seed offline e al resto penserà tutto il sistema.

Scopri i cold wallet ELLIPAL

Nota sulla sicurezza: questo articolo ha finalità informative e non costituisce una consulenza finanziaria. Il comportamento del dispositivo, come i limiti dei tentativi, può variare in base al firmware; verifica sempre i dettagli aggiornati nel Centro assistenza ufficiale ELLIPAL. Eventuali funzioni di swap, staking o acquisto e vendita menzionate altrove sono fornite da terze parti e ELLIPAL non controlla tali servizi.