Researchers at Tibane Labs, among them former Mt. Gox chief executive Mark Karpelès, disclosed on October 9, 2026 that they had identified three successive generations of hidden implants built into Ledger Nano X hardware wallets. The implants, according to the researchers, are designed to intercept a user's 24-word recovery phrase and transmit it over a cellular network without any connection to a computer or smartphone.
For a European market where the Nano X has long been sold as a security-first self-custody device, the findings raise questions reaching well beyond the specific sales channel under scrutiny.
The mechanism described by Tibane Labs exploits the internal connection between the device's secure element and its OLED screen. A microcontroller planted inside the wallet intercepts the visual data sent to the display, recognises the characters being shown, and reconstructs the recovery phrase as it is revealed to the user during setup. A separate cellular module, fitted with its own SIM card and antenna, then sends that phrase out independently of any paired device.
Three generations of hardware
The first publicly known example of such an implant surfaced in August 2025. Researcher Joe Grand disassembled that unit and presented his analysis at Hardwear.io USA 2026, describing an additional circuit board connected by hand-soldered wires, with the original battery reduced to 70 milliamp hours to make room for the added components.
Tibane Labs examined two further examples in September 2026. One incorporated a flexible circuit laid over the original board and wired into its test points. The other had its board coated black with identifying markings scraped away, apparently to hinder identification. In that second case, the implant builders removed filler material rather than shrinking the battery, and fitted an nRF9151 communication module, compatible with LTE-M and NB-IoT networks, together with an L-shaped antenna shaped specifically for the Nano X casing.
Tibane Labs noted that none of the three versions require replacing the device's secure element, which continues to protect cryptographic signing operations as normal. As a result, a physically modified device can still pass Ledger's standard authenticity check, leaving the tampering invisible to routine verification.
Distributor under scrutiny
The disclosure coincided with an announcement from Ledger on the same day that it was investigating fund losses linked to devices sold through CryptoBilis, an authorised distributor operating in Malaysia, Indonesia and the Philippines. Ledger has asked for the suspension of CryptoBilis's sales and shipments while the inquiry continues.
Karpelès said his team would investigate a possible link between the manipulated devices described in the Tibane Labs research and the reported thefts. He has asked affected users to send photographs of the interior of their devices so that researchers can check for the presence of implants.
No findings have yet confirmed how many devices may have been affected or through which supply points the modified units entered circulation.




