TLDR
- Ledger confirmed on Oct. 10 that one affected customer’s device held an unauthorized hardware implant.
- Estimates of suspected losses range from $72 million to $93.4 million, but Ledger has not verified any figure.
- Reseller CryptoBilis has stopped selling hardware wallets while the investigation continues.
- Researchers also found a fake Ledger website in Google search results that asks for recovery phrases.
- Ledger says it will never ask for a 24-word recovery phrase.
Ledger confirmed on Saturday, Oct. 10, that a hardware wallet belonging to one affected customer contained an unauthorized implant. The company said the finding came as it investigated reports of stolen cryptocurrency linked to the Southeast Asian reseller CryptoBilis.
⚠️ Beware if you use a Ledger hardware wallet, especially if you bought one recently.
Based on information so far, it seems to be localized to a supply chain attack with one vendor. A small number of people probably bought fake (or tampered) Ledgers.
Ledger is one of the most… https://t.co/zW8wkvdZNf
— CZ 🔶 BNB (@cz_binance) October 9, 2026
Ledger said “one of the impacted users’ devices contained an unauthorized hardware implant.” It was the first time the company confirmed physical tampering with an affected device.
The company also said it has “no indication that Ledger’s security infrastructure, systems or services have been compromised.” Its support account said it is contacting impacted users and working with authorities.
What Investigators Found
Estimates of the losses vary. Yfarmx put suspected losses at $93.4 million across 471 addresses. Bitquery estimated about $92.9 million across 311 addresses, and researcher Specter said losses topped $86 million.
On-chain investigator tanuki42 identified more than $72 million sent to addresses believed to be tied to the thefts. Ledger has not confirmed any of these numbers. Investigators have not set a final count of affected wallets.
Former Mt Gox CEO Mark Karpelès published findings on a modified Ledger Nano X. He described a hidden circuit board and cellular equipment that could intercept recovery phrases.
The equipment reportedly watched data sent to the device’s screen during setup. It could then send the recovery words over a cellular link. Investigators have not shown that every affected wallet held similar parts.
CryptoBilis, which operates in Indonesia, Malaysia and the Philippines, has stopped selling hardware wallets until the investigation ends. Ledger asked the reseller to pause sales and shipments on Oct. 9.
Ledger told customers who bought from the reseller in the past 90 days not to set up their devices. Those who already did were advised to move assets to a new Ledger signer with a new seed.
Ledger said it is working on stronger anti-tampering tools. It thanked SEAL 911 for helping investigators.
Some users on X asked whether Ledger will refund victims. Others said the company should take responsibility because CryptoBilis was an authorized reseller. Ledger has not announced any compensation.
Fake Ledger Website Appears in Search
Separately, researcher Cyber Scrilla warned that a fake Ledger site and app appeared near the top of Google results. The operators reportedly tried to get visitors to enter their 24-word recovery phrases.
FAKE LEDGER WEBSITE APPEARS AT TOP OF GOOGLE SEARCH AMID $86M WALLET THEFT INVESTIGATION
Security researcher @cyberscrilla has flagged a fraudulent Ledger website and app appearing prominently in Google Search, designed to trick users into revealing their 24-word recovery…
— Bitcoin News (@BitcoinNewsCom) October 10, 2026
Reports said the site showed more than 1 million visits over 30 days. That figure has not been confirmed. No victim count or amount stolen has been established for this site.
A September report from Zscaler described a similar scheme using fraudulent Google ads. The firm found that the claim of 1 million visits appeared to refer to google.com, not the phishing page.
Researchers have not shown that the phishing sites caused the CryptoBilis losses. They are separate issues that both involve Ledger users.
Ledger says users should never type a recovery phrase into a website, app or online form. It advises downloading its software only from its official website and checking web addresses closely.
The most recent update came Oct. 10, when Ledger said one confirmed device contained an implant. The number of other tampered devices and the people responsible remain unknown.
Stop guessing and start investing with confidence. KnockoutStocks gives you the AI insights, market intelligence, and stock research you need to spot opportunities, cut through the noise, and make smarter investment decisions — all in one powerful platform.
Sign up today and get 50% OFF full access to our premium stock picks.
Simply use coupon code SPECIAL50 at checkout to claim your exclusive discount.






Be the first to comment