Author: Gu Yu, ChainCatcher
An individual transferred 80 bitcoins to a newly purchased Ledger device, bought from an official authorized dealer. The recovery phrase was handwritten and stored in a safe. The coins arrived on September 29, with an acquisition cost of approximately $5.2 million and a peak unrealized profit of $1.38 million. On October 9 at 05:54 (UTC), all 80 BTC were transferred out in a single transaction.
He did everything required by the textbook.
On the same morning, numerous similar reports began appearing on X and Reddit: a user’s Ledger Stax had been drained of nearly 100,000 USDT, with the recovery phrase similarly handwritten and locked in a safe. The only commonality among these users was that they had all purchased their devices from the Southeast Asian distributor CryptoBilis.
On October 9 at 13:32 (UTC), Ledger confirmed it is investigating and requested CryptoBilis to suspend all sales and shipments of Ledger devices; users who purchased devices from this channel within the past 90 days should not initialize them if they haven’t already, and those already initialized should immediately transfer their assets to a new device generated with a new mnemonic phrase.
I. Losses may exceed $90 million
The extent of the loss is currently only estimated on-chain.
On-chain investigator Specter was the first to disclose ten aggregated addresses at 12:24, covering Bitcoin, Ethereum, and TRON, estimating losses exceeding $86 million; another investigator, tanuki42, listed eight of these addresses, estimating losses over $72 million; MistTrack, under SlowMist, stated the figure is "approaching $90 million"; Bitquery covered 311 wallets and estimated approximately $92.9 million in losses, including about $42 million in Ethereum, $17.6 million in Bitcoin, and $16.5 million in USDT. Arkham has labeled these addresses as "Ledger Theft"; as of Friday afternoon, approximately $71.5 million remained in the flagged addresses, with the largest positions including about $29.4 million in ETH, $17.5 million in BTC, $13.6 million in USDD, and $10.8 million in USDT.
More revealing than the total amount is the profile of the victims. Lookonchain monitored that an address deposited 7 million USDT three weeks after purchasing equipment, and all funds were transferred out approximately ten hours before the report—possibly the largest single transaction in this incident. Additionally, three flagged Bitcoin addresses held a combined total of approximately 211 BTC at 13:44 (UTC), with no outgoing transfers at that time. According to Chain INK, this incident involved around 98 wallets, averaging approximately $890,000 per wallet.
This isn't a retail investor losing a few hundred dollars. This is a wallet where someone put their life savings.
When viewed alongside another incident this year, the distribution difference is more telling than the total amount. In July, Coldcard suffered a loss of approximately $111 million due to a firmware random number flaw that allowed mnemonic phrases to be guessed, but the losses were spread across over 5,200 wallets, averaging about $21,000 per wallet; in contrast, the CryptoBilis incident, which rose to second place in less than a day (around $87 million), involved only about 98 wallets, averaging nearly $890,000 per wallet.
The previous Coldcard incident was a broad net cast; this one is a precise harvest. The distribution itself supports the inference of a "modified module": attackers possess the mnemonic phrases generated on each compromised device, allowing them to wait—waiting for funds to arrive before striking, and specifically targeting those worth targeting. The 80 BTC monitored by Lookonchain were quietly held in the devices for ten days before being transferred all at once.
II. After disassembling the device: the microcontroller on the screen ribbon cable
Ledger has not yet disclosed the attack mechanism, but someone has already disassembled the device.
The most detailed account comes from Mark Karpelès, former CEO of Mt. Gox. He described receiving a device shipped from Malaysia—listed on Amazon at half price and dispatched from Malaysia rather than Japan, his intended order location, which was the first red flag. Upon opening it, he found a hidden module in place of the screen gasket: a single strand of antenna wire, a shortened or removed battery to create space, an LTE module with an eSIM, and a microcontroller connected to the device’s SPI bus.
His assessment was: This microcontroller can recognize the font used by Ledger on its 128×64 screen, lock the mnemonic phrase setup interface, capture the mnemonic phrase displayed word-by-word during user transcription, and transmit it via LTE.
23pds, Chief Information Security Officer of SlowMist, outlined the technical approach: attackers install a microcontroller inside the device, connecting it to the screen’s SPI data lines; after the mnemonic is generated within the secure element and displayed on the screen for the user to copy, the malicious module simultaneously records every character shown on the screen, then transmits it via built-in LTE or eSIM. He emphasized that the purpose of the secure element is to prevent private keys from being directly read or exported—but it cannot control what is displayed on the screen. The few seconds during which the mnemonic appears on the screen constitute the attack window.
This explains the most counterintuitive aspect of the entire incident: these devices can pass Ledger’s authenticity verification. Because the secure element is genuine, it correctly generates the mnemonic phrase and properly signs transactions—it’s merely being watched. The firmware also cannot detect it, since the implanted module only listens during screen refreshes. In other words, the only way to detect it is to physically disassemble the device.
Two other possibilities may also exist: first, preloaded recovery phrases—where attackers power on, set up, copy, and reseal the device in advance, leading users to believe they are “setting up a new device” when in fact they are using a set of words already known to the attacker; second, phishing. Developer 0xQuit believes some victims may have fallen prey to phishing, noting that it is irresponsible to simply claim “Ledger was hacked.”
Three: "Official Authorization" endorses sales rights, not the supply chain.
CryptoBilis is not a street vendor.
Founded in Kuala Lumpur in 2020, it is an officially authorized distributor listed on Ledger’s official dealer page, serving Malaysia, Indonesia, and the Philippines. In addition to Ledger, it also sells Trezor, OneKey, Tangem, and SafePal.
The problem lies precisely here. Users follow the security guidelines taught by the industry: if you can’t buy directly from the official website, find an “official authorized distributor.” But the authorization only certifies the company’s right to distribute, not the integrity of every device in its warehouse or the trustworthiness of every employee handling and sorting them. From the factory, through logistics, warehousing, sorting, the distributor, and finally to your doorstep—any link in this chain could be intercepted, opened, and resealed. The heat-shrink film on Karpelès’s device was intact.
Once the device leaves Ledger’s custody, the word "authorized" provides no physical protection.
More subtly, the timeline. Newly disclosed corporate records show that CryptoBilis was acquired in March this year, and an individual named "Jiaming," with a registered address in Heilongjiang Province, China, has held 100% ownership of the company since August 3. The former co-founders confirmed the March acquisition, stating that the original shareholders subsequently stepped down from all operational, managerial, and administrative roles, and after the handover, lost visibility into the company’s actual operations. They urged the current management to act transparently. According to DeepChain TechFlow, a confidentiality agreement signed by the acquirer and former executives restricts them from disclosing details of the transaction, with its validity extending until October 19—when the incident erupted on October 9, the former executives were still legally prohibited from revealing the acquisition details.
There is currently no conclusive evidence linking the equity change to the equipment theft, and Ledger has only suspended sales without making any allegations.
On October 10, CryptoBilis announced the suspension of sales and shipping for all branded hardware wallets through its physical stores and online channels in Malaysia, the Philippines, and Indonesia, and reminded users: mnemonic phrases must be generated by the device during initialization and manually written down by the user; any device accompanied by pre-printed or pre-written mnemonic cards should be considered insecure.
CryptoBilis is not the only channel to have faced issues this year. In September, Trezor acknowledged that its logistics provider, ShipMonk, was compromised, exposing the real names, phone numbers, and home addresses of approximately 81,000 U.S. customers; in January, Ledger disclosed that its payment processor, Global-e, had leaked the names and contact information of some buyers from its official website. While these incidents did not directly result in lost funds, they repeatedly handed attackers lists detailing who received a hardware wallet and when.
Over the past three months, the weakest link in cold storage has shifted from code to logistics.
Four: Recovery, Self-Help, and the Cheapest Advice
The window for recovery is closing.
According to MistTrack, Tether has frozen a large amount of USDT at the relevant addresses; in response, the attackers began converting USDT into USDD, a Tron-based stablecoin that Tether cannot freeze. According to Onchain Lens, 430.2 ETH (approximately $1.07 million) has entered Tornado Cash through four wallets. Bitcoin and Ethereum have no freeze switches—once funds leave, the exchange is the only remaining barrier.
SlowMist and the Security Alliance have opened assistance channels, with the latter urging users whose funds were transferred to the relevant addresses to contact their SEAL 911 emergency response team.
The most practical advice from the industry came from CZ. While determining this was a "supply chain attack limited to a single distributor," he provided a specific, action-oriented solution:
After purchasing a hardware wallet (or downloading a new software wallet), wait several weeks before transferring any significant amount of funds. During this time, stay updated on relevant news… the hardware could be tampered with, or the official website of the software could be compromised. Self-custody means additional responsibility.
The logic behind this "isolation period" is not technical, but informational: if a batch of devices was already tampered with when delivered to distributors, on-chain analysts need time to detect the first stolen devices and issue alerts—those two weeks are the buffer they’ve bought for themselves.
But what this incident truly redefined was the boundary of the term "self-custody."
Over the past decade, the industry has built almost its entire self-custody security narrative on cryptography and hardware: secure elements, EAL5+, PIN wiping, open-source audits. None of these have been compromised. What has been compromised is the journey from the factory to your doorstep—a path composed of logistics providers, warehouses, distributors, and couriers, with no step verifiable by the user.
Hardware wallets promise that "the private key never leaves the device." The irony here is that the private key indeed never left the device—it was just seen a little too closely by someone during the few seconds it was displayed to the user.
And when the security boundary extends from the chip to the package at your doorstep, the last line of defense users may truly have is: don’t rush to put your money in.

