Hackers reportedly drain up to $93 million through compromised Ledger reseller

ledger logo bg 2

Hackers reportedly drain up to $93 million through compromised Ledger reseller

Hidden cellular implants inside Ledger devices sold by Southeast Asian reseller CryptoBilis allegedly leaked users' recovery phrases

A hardware wallet is supposed to be the vault you buy so you never have to trust anyone else. That premise just took a serious hit.

Attackers reportedly planted hidden hardware inside Ledger wallets sold through an authorized Southeast Asian reseller, CryptoBilis. Estimated losses range from $72 million to upwards of $93 million, spread across hundreds of wallets.

Ledger confirmed on October 10, 2026, that at least one affected device contained an unauthorized hardware implant. The company has told CryptoBilis to stop all sales and shipments of its devices.

How the attack allegedly worked

The implants are described as small circuit boards with cellular capabilities, tucked behind the device screens. Their job was to capture a user’s 24-word recovery phrase and send it out over cellular networks.

Advertisement

The recovery phrase is the master key to a crypto wallet. Anyone holding those 24 words can rebuild the wallet on another device and move the funds, no physical access required.

A post on X claimed the attackers went further than tampering with stock. According to that post, the hackers bought a reseller outright, had it sign a non-disclosure agreement, and stole over $80 million by slipping spy chips into the wallets. That account of the reseller purchase and the NDA has not been confirmed by Ledger.

The money trail

The unusual draining began around October 9, 2026. Researchers spotted significant inflows to theft addresses across several blockchains, including Bitcoin, Ethereum, and Tether’s USDT stablecoin.

Most of the losses were recorded between October 9 and October 10. Some of the stolen funds were reportedly routed through mixers such as Tornado Cash.

Tether has reportedly frozen approximately $10 million in USDT linked to the theft addresses.

Multiple generations of implants

Researcher Mark KarpelĆØs documented the hardware involved. His findings point to several generations of the implants in devices bought in Southeast Asia. According to KarpelĆØs’ documentation, the implants were built to quietly monitor and extract sensitive data without tripping Ledger’s security protocols.

Background: why resellers matter

CryptoBilis serves customers in Malaysia, Indonesia, and the Philippines. Ledger’s position is that the problem is confined to the reseller channel. The company says there is no evidence that its core systems or products sold directly were affected.

What this means

Anyone who bought a Ledger through CryptoBilis faces an uncomfortable question. If an implant captured the recovery phrase, the device itself cannot be trusted, and neither can any wallet created from that phrase. Moving funds to a wallet generated on a verified device with a fresh phrase is the logical response for anyone exposed.

Watch for three things next. First, whether Ledger or independent researchers confirm how many devices carried implants. Second, whether more of the stolen funds get frozen or traced as they exit mixers. Third, whether the claim that attackers acquired the reseller itself holds up, because that would turn a story about tampered inventory into one about a hostile takeover of a trusted sales channel.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
Hackers reportedly drain up to $93 million through compromised Ledger reseller
Hackers reportedly drain up to $93 million through compromised Ledger reseller

Hidden cellular implants inside Ledger devices sold by Southeast Asian reseller CryptoBilis allegedly leaked users' recovery phrases

Share

Add us on Google

ledger logo bg 2

A hardware wallet is supposed to be the vault you buy so you never have to trust anyone else. That premise just took a serious hit.

Attackers reportedly planted hidden hardware inside Ledger wallets sold through an authorized Southeast Asian reseller, CryptoBilis. Estimated losses range from $72 million to upwards of $93 million, spread across hundreds of wallets.

Ledger confirmed on October 10, 2026, that at least one affected device contained an unauthorized hardware implant. The company has told CryptoBilis to stop all sales and shipments of its devices.

How the attack allegedly worked

The implants are described as small circuit boards with cellular capabilities, tucked behind the device screens. Their job was to capture a user’s 24-word recovery phrase and send it out over cellular networks.

Advertisement

The recovery phrase is the master key to a crypto wallet. Anyone holding those 24 words can rebuild the wallet on another device and move the funds, no physical access required.

A post on X claimed the attackers went further than tampering with stock. According to that post, the hackers bought a reseller outright, had it sign a non-disclosure agreement, and stole over $80 million by slipping spy chips into the wallets. That account of the reseller purchase and the NDA has not been confirmed by Ledger.

The money trail

The unusual draining began around October 9, 2026. Researchers spotted significant inflows to theft addresses across several blockchains, including Bitcoin, Ethereum, and Tether’s USDT stablecoin.

Most of the losses were recorded between October 9 and October 10. Some of the stolen funds were reportedly routed through mixers such as Tornado Cash.

Tether has reportedly frozen approximately $10 million in USDT linked to the theft addresses.

Multiple generations of implants

Researcher Mark KarpelĆØs documented the hardware involved. His findings point to several generations of the implants in devices bought in Southeast Asia. According to KarpelĆØs’ documentation, the implants were built to quietly monitor and extract sensitive data without tripping Ledger’s security protocols.

Background: why resellers matter

CryptoBilis serves customers in Malaysia, Indonesia, and the Philippines. Ledger’s position is that the problem is confined to the reseller channel. The company says there is no evidence that its core systems or products sold directly were affected.

What this means

Anyone who bought a Ledger through CryptoBilis faces an uncomfortable question. If an implant captured the recovery phrase, the device itself cannot be trusted, and neither can any wallet created from that phrase. Moving funds to a wallet generated on a verified device with a fresh phrase is the logical response for anyone exposed.

Watch for three things next. First, whether Ledger or independent researchers confirm how many devices carried implants. Second, whether more of the stolen funds get frozen or traced as they exit mixers. Third, whether the claim that attackers acquired the reseller itself holds up, because that would turn a story about tampered inventory into one about a hostile takeover of a trusted sales channel.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.