Ledger finds a hidden implant in a wallet sold by its reseller after a $93 million theft
Ledger says one of the hardware wallets tied to a theft of more than $90 million in Southeast Asia had an extra component inside it that the company did not put there. On October 10 the French manufacturer wrote that "one of the impacted users' devices contained an unauthorized hardware implant". Ledger links the losses to wallets bought from CryptoBilis, an official Ledger reseller in Malaysia, Indonesia and the Philippines. Ledger has told recent buyers not to set up those devices and says its own systems were not breached.
How the theft was found
On October 9 Ledger owners on X and Reddit began reporting empty wallets. The pseudonymous blockchain investigator Specter traced the money to a handful of addresses on Bitcoin, Ethereum and Tron and put the losses at more than $86 million from hundreds of wallets. The same day Ledger asked CryptoBilis to stop all sales and shipments. A day later the reseller stopped selling hardware wallets of any brand until the investigation ends.
Blockchain analytics firm Bitquery has since counted $93.2 million taken from 315 wallets on six networks. Most of it, $70.5 million, was USDT on Tron, followed by about 204 BTC worth $16.8 million. The pattern points to a single thief who held every key:
- two control addresses were set up on September 25 and ran small test transfers for about two weeks;
- on October 9 wallets on all six networks were emptied within 47 minutes;
- 25 Tron wallets signed the same approval to the same address within three seconds.
What a tampered wallet can do
A hardware wallet is safe only if the recovery phrase it generates during setup never leaves the device. If someone opens the device before it reaches the buyer, they can learn that phrase, wait until the owner moves real money in, and take it. Kaspersky described the same scheme in 2023 with a tampered Trezor Model T: the attackers waited about a month before emptying the wallet.
Ledger has not said what the implant does or whether every stolen wallet contained one. Former Mt. Gox chief Mark Karpelès posted photos of a small extra board under the screen of a Ledger device bought in Malaysia; Ledger has not confirmed his find. According to Bitcoin.com, the implant reportedly reads what the screen shows during setup and does not touch the secure chip, which would let a device pass the usual checks. Ledger says it is working on "further, enhanced anti-tampering solutions".
Most stolen seed phrases leak through software, such as malicious code editor extensions or fake prompts. Here the attack happened before the buyer ever opened the box, so careful habits on the owner's side would not have helped.
Where the money went
Tether began blocking linked addresses about ten minutes after the first public posts and froze $10 million in USDT. The thief had already swapped about $15 million into USDD, a stablecoin Tether cannot freeze, and sent 2,990 ETH through the Tornado Cash mixer. Ledger says it is working with law enforcement and the volunteer security group SEAL 911.
If you bought a Ledger from CryptoBilis
- If the device is still sealed or not set up, do not set it up.
- If you already use it, move the funds to a new device bought directly from the manufacturer, with a newly generated recovery phrase. Ledger asks this of buyers from the last 90 days, but Bitquery found that only about 6 in 10 drained wallets first received funds inside that window, so older purchases may be affected too.
- Ledger never asks for your 24-word recovery phrase. Anyone who offers to "recover" stolen funds in exchange for it is running a scam.
The wider lesson applies to any hardware wallet: buy it from the manufacturer's own store, not from a reseller or a marketplace, even an authorised one.
• Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen - CoinDesk
• Ledger Confirms Hidden Hardware Implant in Affected User's Wallet - Bitcoin.com News
• Ledger CryptoBilis Hack: $92.9M Drained, Where It Went - Bitquery
• Ledger investigates suspected $86M theft affecting authorized reseller - Cryptopolitan