Developing story, last reviewed 10 October 2026. Findings, affected-device scope and the cause of the current wallet-drain reports may all change. Ryder makes a competing hardware wallet, so weigh this accordingly.
A Ledger implant, in the research published so far, is a second small circuit added inside the case of a real device, wired to the display and reading your recovery words as the screen shows them to you during setup. It does not break the secure element, and that is the point of the design. What the research has not done is connect any examined implant to the wallet drains Ledger is currently investigating, and keeping those two things apart is the only way to read this story accurately.
What the Ledger implant research documents
Tibane Labs has published a photographed teardown of implanted Ledger Nano X units, tracking three generations since the first public report in August 2025. The implant is a flexible circuit soldered to the Nano X board, carrying a microcontroller, a cellular module, an antenna and an eSIM. It taps the display's data lines, reconstructs the words travelling to the screen, and sends them out over its own cellular connection.
The newest specimen is the part worth noting. It is cut to fit around the Ledger's own components so it drops into position without measuring or skill, which the lab reads as a design built for installation in volume rather than one-off jobs. Its chip markings were scraped off. Earlier versions gave themselves away with loose wires and a shrunken battery, and this one was built to survive an inspection.
Both specimens Tibane examined arrived through ordinary resale: one from Yahoo! Auctions in Japan, one from Amazon Japan via a China-based seller that shipped from Malaysia. Neither was bought from CryptoBilis, the reseller at the centre of the current investigation. Tibane describes its own work as ongoing and says the losses are not confirmed. We have not examined either specimen.
Ledger already documented this gap, before any of it
The most useful source here is Ledger's own purchasing guidance, which addressed this scenario ahead of the current reports. Ledger writes that its device authenticity check, the one that verifies the secure element, cannot detect unauthorized physical modifications to the hardware such as spying implants, so long as the original secure element is intact. The same page states that no global supply chain is entirely immune to highly sophisticated interception or tampering, and that the check confirms authenticity without verifying a device's supply chain history.
Read that alongside the teardowns and the mechanism stops being mysterious. The chip is authentic, so the check passes, and the implant was never pretending otherwise. Ledger also states plainly that one of its devices never arrives with a recovery phrase or a PIN already configured, which is the single most useful sentence in this whole story for anyone opening a box this week.
An eSIM is not the thing reading your screen
The shorthand circulating online, usually some version of "eSIM screen reader", squeezes four components into one label and makes the attack sound stranger than it is. An eSIM is a SIM: it supplies the subscriber identity that lets a device join a cellular network. The microcontroller captures the words, the cellular module and antenna move them off the device, and the eSIM only answers the question of which account the network should bill. Knowing which part does what matters when you are looking at a photograph of a suspected board and trying to work out what you are seeing.
How firm are the claims being quoted?
Mark Karpelès, the former Mt. Gox CEO, said on 9 October that a Nano X he had received from Malaysia appeared to carry a spy module with an LTE component, an antenna, an eSIM and a microcontroller attached to the screen's SPI bus. The following day, SlowMist's chief information security officer, who posts as 23pds, sketched out how a recovery phrase could leak through such a module and added that this remains guesswork at present.
That last clause does a lot of work, and most coverage drops it. A researcher explaining how an attack could function is describing a possibility, and ten outlets repeating one social post are still resting on a single underlying claim.
Why the display is the exposed moment
Keeping a secret safe while it sits in storage and keeping it safe while it is being shown to you are two different jobs, and a secure element is built for the first one. Keys are generated inside the chip and never leave it, which defeats an attacker trying to extract them. None of that helps when the device has to render words on a screen so a human can read them, because at that instant the secret is travelling along wires that something else can listen to.
This is why judging a wallet on its chip alone leaves most of the question unanswered. The route worth following runs from how a secret is generated, through how it is displayed, backed up, recovered and used to sign, and a certified component covers one stop on that route.
What would connect the implant to the drained wallets
Right now the implant research and the loss reports are two separate bodies of evidence. Joining them would take a device belonging to someone who lost funds, examined and preserved rather than reset, with an account of what the added parts captured and a demonstrated path from that capture to the wallet that was emptied, reviewed by someone outside the original investigation.
Until some of that exists, the fair summary is that a workable mechanism has been documented and a large theft has been traced, and nobody has yet shown they are the same event.
What this means for any wallet, ours included
The display question applies to us. Our own recovery documentation states that a Ryder One owner can view their seed phrase on the device at any time as a fallback, which means there is a moment when words are rendered on our screen too. Any manufacturer claiming a design immune to someone opening the case and adding parts is overstating what can be known, and no comparative testing exists that would let us make that claim about the Ryder One.
What we would say is narrower. Buy from the manufacturer or a seller you can trace, treat first setup as the moment that decides everything, and walk away from any device that arrives already configured or with words printed on a card in the box. If you are affected by the current reports, follow Ledger's own guidance rather than a competitor's. If you are weighing how a backup should be arranged for the longer term, our recovery documentation sets out how we split ours.




Share: