BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Little-Known Details Emerge About the High-Profile Ledger Hack – The Question “Why Now?” Is Answered

A striking claim has emerged in the multi-million dollar theft case linked to cryptocurrency hardware wallet manufacturer Ledger. It has been suggested that former Mt. Gox CEO Mark Karpelès’s

AnonymousCryptoCompass newsroom
October 10, 2026
2 min read
NEWS
Little-Known Details Emerge About the High-Profile Ledger Hack – The Question “Why Now?” Is Answered
CryptoCompass editorial visual for altcoins coverage.

A striking claim has emerged in the multi-million dollar theft case linked to cryptocurrency hardware wallet manufacturer Ledger. It has been suggested that former Mt. Gox CEO Mark Karpelès’s public disclosure of compromised Ledger devices prior to large-scale asset transfers may have spurred the attackers into action.

On October 8th, Mark Karpelès warned users about counterfeit or physically modified Ledger devices being sold on the market, allegedly equipped with hidden SIM cards. These devices reportedly contain spyware hidden beneath the screens, which can intercept data sent to the screen during wallet setup and transmit users’ recovery words to attackers.

Karpelès stated that one of the devices he examined came from Malaysia and its packaging was perfectly intact. Despite this, it was reported that a cleverly concealed piece of spyware was found beneath the device’s screen.

One of the most striking aspects of the incident is that the modified devices were able to pass Ledger’s official Genuine Check test. This is because the attackers were able to install additional hardware without altering the device’s original security chip. While Ledger’s verification system can check the authenticity of the security chip, it cannot detect all physical modifications made to the device.

Related News: Allegations of a Massive Hack at One of the Largest Crypto Wallets—A Substantial Amount Stolen, CZ Issues a Warning

According to one theory, the attackers had been collecting users’ recovery words for a long time through compromised devices. However, instead of carrying out the attack immediately, they waited to empty numerous wallets simultaneously.

It is speculated that after Karpelès’ warning, which garnered approximately 90,000 views, the attackers may have realized their activities had been exposed and taken action. According to this scenario, the attackers quickly began transferring assets from the wallets they had compromised after their operation was revealed.

However, a direct link between Karpelès’ statement and the subsequent large-scale wallet robberies has not yet been confirmed. It is also unknown whether the spyware in question was responsible for all the attacks.

Initial findings suggest a supply chain attack involving the physical alteration of devices before they reach users, rather than a vulnerability in Ledger’s cryptographic security system.

*This is not investment advice.

Continue Reading: Little-Known Details Emerge About the High-Profile Ledger Hack – The Question “Why Now?” Is Answered