Ledger reports a $90 million security incident linked to CryptoBilis distributor.

iconChaincatcher
Share
AI summary iconSummary
Ledger is investigating a $90 million security incident linked to its CryptoBilis distributor in Southeast Asia. The company has halted sales through this channel and warned users who purchased devices in the past 90 days to take action. On-chain data suggests the breach may involve tampered hardware or a compromised supply chain. Traders are advised to monitor altcoins for potential market reactions. The full cause remains under investigation.

ChainCatcher report: Today, hardware wallet provider Ledger experienced another security incident, with third-party security firms estimating losses nearing $90 million. Ledger is investigating financial losses linked to devices sold by its authorized Southeast Asian distributor, CryptoBilis, and has requested the distributor suspend all sales and shipments. Users who purchased devices through this channel within the past 90 days are advised to exercise caution or transfer their assets. The root cause has not yet been confirmed but appears to involve potential supply chain compromise or device tampering. Historical major security incidents and associated financial losses involving Ledger include: In 2018, early vulnerabilities in hardware and supply chain security emerged. Security researchers demonstrated the possibility of Nano S devices being tampered with prior to shipment, as well as exploits involving MCU bootloader bypasses, isolation flaws, and injection of Bitcoin change addresses. Ledger subsequently issued security advisories and deployed fixes; most of these issues were research-grade vulnerabilities requiring physical access to the device. In 2020, Ledger suffered a large-scale customer data breach. Attackers exploited third-party API keys and Shopify-related vulnerabilities to gain access to e-commerce and marketing databases, exposing over 1 million email addresses and approximately 272,000 to 292,000 detailed customer records—including names, addresses, and phone numbers. While hardware wallets and private keys remained unaffected, the incident triggered prolonged phishing, social engineering, and impersonation scams using forged official communications. In December 2023, Ledger Connect Kit was targeted in a supply chain attack. After a former employee fell victim to phishing, their NPMJS account was compromised, enabling attackers to release a malicious version of Connect Kit that injected malicious code into DApps relying on the library, tricking users into signing fraudulent transactions. The attack window lasted approximately two hours, resulting in losses of $480,000 to $600,000. Neither Ledger hardware nor Ledger Live itself was directly compromised. In January 2026, third-party Global-e order data was leaked. Unauthorized access to the payment and logistics partner’s systems exposed certain Ledger.com order details—including names, addresses, and contact information. Ledger’s own systems and private keys were unaffected, but phishing risks increased again. In April 2026, counterfeit Ledger Live applications appeared on the App Store. The fake apps remained listed for about a week, tricking users into entering their recovery phrases; over 50 victims lost approximately $9.5 million across multiple blockchains. Apple subsequently removed the apps, and Ledger emphasized that it never requests users’ 24-word recovery phrases. In August 2026, Ledger disclosed vulnerabilities related to Ethereum app signing, including command interleaving causing display-content/signing-parameter mismatches and clear-signing bypasses. These vulnerabilities required a malicious host to be exploited; Ledger stated there was no evidence of actual user exploitation at the time, and the issues have since been patched in newer versions. On October 9, 2026, a large-scale wallet draining incident linked to the CryptoBilis distributor occurred, with estimated losses nearing $90 million. Ledger is currently investigating and believes the incident may involve a targeted supply chain or device tampering attack against a single distribution channel. The company has suspended sales through this channel and advises affected users to migrate their assets.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.