PANews reported on October 10 that Mark Karpelès, former CEO of Mt.Gox, said a Ledger device he purchased from Malaysia contained a spy module with a SIM card chip hidden in the screen padding, while the outer packaging was intact. SlowMist Chief Information Security Officer 23pds analyzed that the attack flow may involve a malicious module connected to the screen data cable, recording the words displayed when the mnemonic phrase is generated, and then sending them to the attacker via LTE/eSIM; the secure element can only protect the private key from being read, but cannot prevent screen content from being intercepted.