Ledger Hardware Wallets Compromised via Spy Module; Chinese-Linked Dealer Involved

iconTechFlow
Share
AI summary iconSummary
Ledger hardware wallets were compromised via a spy module, with CryptoBilis, a dealer linked to China, at the center. Over $86.9 million in Bitcoin and altcoins—including Ethereum and USDT—was stolen. Ledger advises users who purchased from CryptoBilis in the past 90 days to transfer their funds. The attack targeted recovery phrases during device setup. The dealer was acquired in March 2026, raising alarms. Bitcoin analysis shows no direct impact yet, but the breach raises broader security concerns.

Author: Schen TechFlow

Someone transferred 80 BTC into a newly purchased Ledger hardware wallet—bought from an official authorized dealer, handwritten seed phrase, stored in a safe. $5.2 million, did everything right.

Then the coins were gone.

On October 9, Ledger issued a statement saying it is investigating the loss of assets among some users in Southeast Asia. All affected users shared a common trait: their devices were purchased from a distributor called CryptoBilis.

Ledger directly ordered CryptoBilis to cease all sales and shipments, and warned users who purchased devices from this store in the past 90 days: do not power on devices that have not been activated; if you already stored crypto assets, immediately transfer them to a brand-new device with a completely new mnemonic phrase.

How big is this incident? Chain analyst Specter tracked addresses reported by victims on X and Reddit, estimating involvement of approximately 98 wallets and losses exceeding $86.9 million. Another analyst, tanuki42, independently estimated losses above $72 million. Bitquery covered 311 wallets and reported a figure of approximately $92.9 million, distributed across Ethereum (around $42 million), Bitcoin (around $17.6 million), and USDT (around $16.5 million).

These are estimated figures based on on-chain tracking; Ledger has not confirmed the final numbers or verified that all tracked addresses are directly linked to CryptoBilis. However, even with just the information currently known, this is the largest hardware wallet supply chain security incident ever recorded in the crypto industry.

The distributor quietly changed its shareholders.

CryptoBilis is not some shady operation. It is listed on Ledger’s official website as an authorized distributor, covering Malaysia, Indonesia, and the Philippines. Founded in Kuala Lumpur in 2020, it calls itself “Southeast Asia’s trusted Web3 brand” and sells not only Ledger products but also Trezor, OneKey, Tangem, and SafePal.

The user’s logic is simple: they found this store on Ledger’s official website, bought the device from it, and the words “officially authorized” equate to a security guarantee.

The issue is that "official authorization" certifies the right to sell, which is unrelated to supply chain security. From the moment a device leaves Ledger’s factory, it passes through logistics, warehouses, sorting centers, distributors, and finally reaches consumers. At any point along this chain, the device could be intercepted, opened, or tampered with.

Another more critical clue: CryptoBilis was acquired in March 2026.

Company records show that a person named "Jiaming," registered in Heilongjiang Province, China, has held 100% ownership of the company since August 3. The original founding team later stated that, following the handover, they no longer had control over the company’s actual operations, declared they "are no longer part of the company," and called on "the current management to handle this matter transparently."

More intriguingly, the acquirer signed a confidentiality agreement with the former executives, restricting them from publicly disclosing details of the transaction, with the agreement valid until October 19. This means that when the incident came to light on October 9, the former executives were legally prohibited from revealing the acquisition details.

Is there a causal relationship between the acquisition and the lost coins? There is no conclusive evidence. But every coincidence in the timeline only intensifies the question marks.

What’s hidden in the device?

Ledger has not officially confirmed the specific mechanism of the attack, but some individuals have already disassembled the device.

Former Mt. Gox CEO Mark Karpelès said he purchased a Ledger device from Malaysia, and upon opening it, discovered a spy module hidden inside containing a SIM card chip. The module was concealed beneath the screen gasket, and the device’s outer packaging showed no signs of tampering, with no visible abnormalities to the naked eye.

23pds, Chief Information Security Officer of SlowMist, provided a more detailed technical analysis: the attacker installed a microcontroller inside the device, connected to the SPI data lines of the screen. When the user sets up their wallet and the mnemonic phrases are displayed one character at a time on the screen, this module simultaneously records each character output. After recording is complete, the full mnemonic is transmitted to the attacker via an integrated LTE or eSIM chip.

This attack path works because it completely bypasses Ledger’s core defense. Ledger’s Secure Element protects private keys from being directly read, but it cannot control what is displayed on the screen. The few seconds during which the mnemonic phrase appears on the screen constitute the attack window—the attacker doesn’t need to crack the chip, only to “peek at the screen.”

This is not speculation. Mark Karpelès took photographs of the physical hardware, and 23pds provided a technical analysis. Although independent third-party verification of either analysis has not yet been conducted, they corroborate each other and point to the same conclusion: this was a meticulously planned hardware-level supply chain attack.

In addition to hardware tampering, two other possibilities cannot be ruled out. One is the simplest and most direct method: pre-setting the mnemonic phrase—attackers power on the device in advance, set up the wallet, record the mnemonic phrase, reseal it, and when users receive it, they believe they are setting up a new device, when in fact they are using a set of phrases already known to the attackers. The other is phishing: attackers obtain CryptoBilis’s customer database and impersonate Ledger to send emails or text messages, tricking users into entering their mnemonic phrases on a phishing website.

About an hour after the message was released, CZ posted: “Based on the information available so far, this appears to be a supply chain attack limited to a single vendor. A small number of people may have received counterfeit or tampered Ledger devices.” He also endorsed Ledger, calling it “one of the most secure and longest-standing hardware wallets in the industry.”

What should I do now?

Tether has begun freezing some of the stolen USDT. However, decentralized assets like Bitcoin and Ethereum are essentially unrecoverable once transferred.

For CryptoBilis customers, Ledger’s advice is straightforward: if you’ve already deposited coins, treat your seed phrase as compromised and immediately transfer your assets to a new device with a completely new seed phrase; if you haven’t powered on your device yet, don’t turn it on.

For all hardware wallet users, this incident drives home an old recommendation: always buy devices directly from the manufacturer’s official website. While authorized distributors add a layer of brand trust, that intermediary can itself become an attack surface.

A Reddit user perfectly captured the dilemma in a discussion: "The whole point of a hardware wallet is that you don't have to trust anyone—but now you have to trust your dealer hasn't opened your package."

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.