Odaily Planet Daily reports that hardware wallet provider Ledger has once again experienced a security incident, with third-party security firms estimating losses nearing $90 million. Ledger is investigating funds lost in connection with devices sold by its authorized Southeast Asian distributor, CryptoBilis, and has requested that the distributor suspend all sales and shipments. Users who purchased devices through this channel within the past 90 days are advised to exercise caution or transfer their assets. The cause of the incident has not yet been confirmed but is suspected to involve supply chain compromise or device tampering.
Ledger's historical major incidents related to attacks and fund losses include:
In 2018, a concentration of vulnerabilities in early hardware and supply chain research emerged. Security researchers demonstrated the possibility of tampering with Nano S devices before shipment, as well as MCU bootloader bypasses, isolation vulnerabilities, and Bitcoin change address injection. Ledger subsequently issued security advisories and implemented fixes; most of these issues were research-level vulnerabilities or required physical access to the device to exploit.
In 2020, Ledger experienced a large-scale customer data breach. Attackers exploited third-party API keys and vulnerabilities related to Shopify to gain access to its e-commerce and marketing databases, exposing over one million email addresses and approximately 272,000 to 292,000 customer records, including names, addresses, and phone numbers. Hardware wallets and private keys were not compromised; however, the incident triggered long-term phishing, social engineering, and impersonation scams involving forged official communications.
In December 2023, the Ledger Connect Kit suffered a supply chain attack. After a former employee fell victim to a phishing attack, their NPMJS account was compromised, allowing attackers to release a malicious version of Connect Kit that injected malicious code into DApps relying on the library, tricking users into signing transactions that stole their funds. The attack window lasted approximately two hours, resulting in losses of $480,000 to $600,000. Neither the hardware devices nor Ledger Live itself were directly compromised.
In January 2026, a third-party Global-e order data breach occurred. Unauthorized access to the payment and logistics partner’s systems exposed certain Ledger.com order-related information, including names, addresses, and contact details. Ledger’s own systems and private keys were not affected, but phishing risks have increased again.
In April 2026, a counterfeit Ledger Live app appeared on the App Store, scamming users into entering their seed phrases. The fake app remained available for about a week, resulting in losses of approximately $9.5 million across more than 50 victims and multiple blockchains. Apple subsequently removed it, and Ledger emphasized that it will never ask for a 24-word seed phrase.
In August 2026, Ledger disclosed vulnerabilities related to Ethereum app signing, including issues such as command interleaving causing display content to be out of sync with signing parameters and clear-signing bypasses. The vulnerabilities required cooperation from a malicious host, and Ledger stated there was no evidence of actual user exploitation; the issues have been resolved in newer versions.
On October 9, 2026, a large-scale wallet draining incident involving CryptoBilis distributors occurred, with estimated losses nearing $90 million. Ledger is currently investigating, and the incident appears to involve a supply chain or device tampering attack targeting a single channel. The company has suspended sales and advised affected users to migrate their assets.
