Ledger has confirmed an unauthorized implant inside a wallet bought from CryptoBilis, an official reseller in Southeast Asia. On-chain researchers estimate losses at $86M to $93M. Ledger has not confirmed any figure.
On 10 October, Ledger said that “one of the impacted users’ devices contained an unauthorized hardware implant.”
It was the first time the company confirmed physical tampering in the case. A day earlier, Ledger said it was investigating reports of missing funds from users in Southeast Asia who had bought Ledger devices through CryptoBilis, an official Ledger reseller in Indonesia, Malaysia and the Philippines.
Ledger also said: “We have no indication that Ledger’s security infrastructure, systems or services have been compromised.”
What Ledger has said so far
Ledger’s updates have come through its support account on X. The company says it is:
- Contacting impacted users as part of the investigation
- Cooperating with authorities
- Working on “further, enhanced anti-tampering solutions”
- Asking anyone with relevant information to contact its bounty program
Ledger thanked SEAL 911, a volunteer crypto security response group, for helping investigators.
On 9 October, Ledger asked CryptoBilis to pause all sales and shipments. According to Ledger, the reseller has since stopped selling all hardware wallet inventory until the investigation ends. No public statement from CryptoBilis has been reported.
How the implant reportedly worked
The most detailed public description so far comes from Mark Karpelรจs, former CEO of Mt. Gox, who examined suspect devices and published findings on a modified Ledger Nano X.
According to those findings, the device had a hidden circuit board with cellular communication equipment. It watched the data sent to the device’s screen during setup, which is when the 24-word recovery phrase is displayed, and could send those words out over a cellular connection.
The implant reportedly did not attack the device’s secure element, the chip that stores private keys.
A few points are still open. Ledger hasn’t said which model its confirmed device was. Investigators also haven’t shown that every affected wallet had the same hardware, or how many tampered devices were sold.
How much was taken
Ledger hasn’t published a loss figure. Independent on-chain estimates so far:
- Specter:ย more than $86M, traced to addresses on Bitcoin, Ethereum and Tron
- tanuki42:ย more than $72M sent to a cluster of suspected theft addresses
- Yfarmx:ย about $93.4M across 471 addresses
- Bitquery:ย about $92.9M across 311 unique addresses
It isn’t clear how much these estimates overlap. The number of victims is also unknown. Specter first described hundreds of affected wallets, then said the final count wasn’t known yet.
Crypto Briefing reports that Tether froze about $10M in USDT linked to some of the suspected theft addresses.
What Ledger is telling users
Ledger’s guidance for CryptoBilis customers:
- If you bought a device from this reseller in the last 90 days and haven’t set it up, don’t start setup.
- If you’ve already set it up, consider moving your assets to a new Ledger signer with a new recovery phrase.
- Ledger will never ask for your 24-word recovery phrase. Don’t type it into any website or app.
- If you were affected, contact Ledger’s bounty program or SEAL 911.
There’s a separate phishing risk. Security researcher Cyber Scrilla flagged a fake Ledger website and app appearing near the top of Google search results, built to collect recovery phrases. That site hasn’t been linked to the CryptoBilis losses.
Industry reaction
Binance co-founder Changpeng Zhao posted on 9 October: “Based on information so far, it seems to be localized to a supply chain attack with one vendor.”
He added that he expects BNB ecosystem players and the wider industry “to help trace and recover the funds.”
Ledger was founded in 2014, is based in Paris, and says it has sold more than 7 million devices worldwide.
What is still unknown
Ledger hasn’t announced any compensation for affected users, though some users on X have asked for it because CryptoBilis was an authorized reseller.
It also isn’t known who installed the implants or how many devices carried them.
Ledger said: “We will continue to inform customers of updates as the investigation progresses.”
