Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Ledger Confirms Hardware Implant in Affected Customer's Wallet Amid Supply Chain Investigation

Ledger confirmed on October 10, 2026, that an affected customer's hardware wallet contained an unauthorized implant, validating concerns about a supply chain attack linked to Southeast Asian reseller CryptoBilis. Suspected cryptocurrency losses have reached approximately $93.4 million across hundreds of addresses.
3 hours ago 14 views
Ledger Confirms Hardware Implant in Affected Customer's Wallet Amid Supply Chain Investigation

Ledger confirmed Saturday, October 10, 2026, that an affected customer's hardware wallet contained an unauthorized hardware implant, strengthening suspicions of physical tampering in a supply chain attack involving Southeast Asian reseller CryptoBilis. The discovery follows estimates of cryptocurrency losses approaching $93.4 million, though Ledger has not independently verified the figures.

Physical Tampering Confirmed

In its statement, Ledger announced that "one of the impacted users' devices contained an unauthorized hardware implant." The company's support account stated it was "reaching out to impacted users as part of the ongoing investigation" and encouraged anyone with relevant information to contact its bounty program.

CryptoBilis has halted sales of all hardware wallet inventory pending the investigation's conclusion, according to Ledger's report.

How the Attack Allegedly Worked

Independent findings published by former Mt Gox CEO Mark Karpelès documented a modified Ledger Nano X containing a concealed circuit board, cellular communications equipment, and components allegedly capable of intercepting recovery phrases.

The suspected attack method targeted information displayed during device setup rather than the wallet's secure element. The equipment reportedly monitored data traveling to the device's display, potentially capturing recovery words before transmitting them through a cellular connection. This approach could allow a device to pass conventional verification checks while secretly exposing the owner's recovery phrase.

Scope of Losses Remains Uncertain

Independent estimates of suspected losses have varied. Yfarmx placed suspected losses at $93.4 million across 471 addresses, while Bitquery estimated approximately $92.9 million across 311 unique addresses. The suspicious transactions involved bitcoin, ether, and stablecoins, primarily traced to Southeast Asian accounts.

However, investigators have not established that every affected wallet contained comparable equipment to the one confirmed device.

Company Response and Customer Guidance

Ledger stated that "we have no indication that Ledger's security infrastructure, systems or services have been compromised," drawing a distinction between tampered hardware and its underlying security systems.

The company advised customers who purchased devices through CryptoBilis not to initialize wallets if they have not yet done so. For customers who have already initialized their wallets, Ledger recommended they "consider moving assets to a new Ledger signer (with a new seed)." Ledger emphasized that recovery phrases captured during setup could potentially expose assets long after compromised hardware has been disconnected.

Ledger confirmed it is "working on further, enhanced anti-tampering solutions" and stated it is cooperating with authorities. The company thanked SEAL 911 for assisting investigators.

Outstanding Questions

One compromised device has been confirmed, but the total number of implants, their connection to the reported losses, and the identities of those responsible remain unresolved.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $83,043.54+0.66% EthereumETH $2,508.24+1.01% Tether USDUSDT $0.9999+0.01% BNBBNB $750.81+1.23% XRPXRP $1.41+0.98% USDCUSDC $1.00+0.01% SolanaSOL $110.36+1.35% TRONTRX $0.3309-0.39% HyperliquidHYPE $85.58+1.75% ZcashZEC $1,223.87+1.13%
Prices by Coinranking. Informational only.