Community Trust ScoreVerified
A hidden circuit board. A stolen fortune. Ledger has confirmed it found an unauthorized hardware implant inside a device connected to a recent theft, and the numbers being thrown around are staggering — somewhere near $93 million in losses, though Ledger itself hasn’t put a firm stamp on that figure.
Why It Matters
The discovery of a tampered Ledger hardware wallet underscores the ongoing vulnerabilities in the cryptocurrency ecosystem, particularly concerning security practices in hardware wallet resales. With a significant amount reportedly tied to this incident, it highlights the critical need for enhanced security measures and due diligence among both retailers and consumers in the crypto space, as breaches can lead to substantial financial losses and undermine trust in digital asset management solutions. This incident may also prompt regulatory scrutiny and drive demand for more robust verification processes within the market.
The tampered device was sold through CryptoBilis, a reseller operating across Indonesia, Malaysia, and the Philippines. Mark Karpelès — yes, the former Mt. Gox CEO — had already shared images online of a modified Ledger Nano X with a hidden circuit board carrying cellular components. That implant, if real and functional, could intercept the 24-word recovery phrase that every hardware wallet relies on. Get that phrase, and you can recreate the wallet anywhere, move the assets, and vanish. It’s a pretty clean attack vector, honestly. And it’s one that doesn’t require any breach of Ledger’s own systems — the company is clear on that point. Whatever happened, it happened after production, somewhere between the factory floor and the customer’s hands.
The Numbers Don’t Quite Match Up
Two different trackers put losses in the same ballpark but can’t agree on the details. Yfarmx pegged it at roughly $93.4 million spread across 471 addresses. Bitquery came in at $92.9 million but counted only 311 addresses. The gap matters, because Ledger has so far confirmed only one tampered device. One. That’s it. Whether the hundreds of flagged addresses all connect to modified hardware is unclear — and that’s probably the most important unanswered question right now.
Bitcoin, Ether, and several stablecoins are among the assets tracked in the suspicious transactions. Big names, big values. But the full scope of what’s been compromised is still murky.
CryptoBilis has suspended all hardware wallet sales at Ledger’s request. Ledger is telling anyone who bought from that reseller recently not to initialize their device. If they already have — if they’ve already set it up and generated a recovery phrase — Ledger wants them to move their assets to a completely new wallet with a fresh phrase. Reusing a compromised phrase on a new device does nothing. If the phrase was intercepted the moment it was generated, it’s already burned.
Supply Chain Attacks Are a Different Kind of Problem
Software hacks are bad. But hardware tampering is harder to catch, harder to prove, and harder to fix at scale. You can push a software patch overnight. You can’t remotely de-solder a rogue circuit board. And that’s basically the wall Ledger is up against here.
The company now has to figure out how many devices were modified, trace exactly where in the supply chain the tampering happened, and build new safeguards that can catch physical modifications before they reach customers. None of that is fast work. And in the meantime, users who bought through CryptoBilis are sitting on potentially compromised hardware with no clear timeline for answers.
It’s not Ledger’s first brush with this kind of crisis, either. Earlier in the year, a fake Ledger app diverted nearly $9.5 million in crypto. And back in 2025, Ledger’s CTO flagged a compromised NPM package that put software-side users at risk. But this current situation is different — it’s physical, it’s in the hardware, and that makes it a fundamentally different category of threat.
Hardware wallets exist precisely because people don’t trust centralized platforms with their keys. The whole pitch is that your private keys never leave the device. But that pitch breaks down completely if someone has added components to the device before you ever touched it. You can follow every best practice — keep your phrase offline, never share it, avoid sketchy transactions — and still get cleaned out if the device itself was tampered with before it arrived.
What Ledger Is Doing Now
Ledger says it’s focused on three things: determining how many units are affected, identifying who is responsible for the tampering, and putting new protections in place. No timeline has been given publicly. The investigation is ongoing.
For users, the advice is blunt — don’t use a CryptoBilis device, and if you already have, move your funds now with a fresh recovery phrase on a clean device.
Ledger confirmed only one tampered device so far. The $93 million figure remains unconfirmed by the company.
Frequently Asked Questions
What exactly did Ledger find in the tampered device?
Ledger found an unauthorized hardware implant — a hidden circuit board with cellular components — inside a device linked to recent thefts, which could intercept a user’s 24-word recovery phrase.
Which reseller sold the affected Ledger devices?
CryptoBilis, a reseller operating in Indonesia, Malaysia, and the Philippines, sold the devices in question and has since suspended all hardware wallet sales at Ledger’s request.
How much money is estimated to have been stolen?
Yfarmx estimates losses at roughly $93.4 million across 471 addresses, while Bitquery puts the figure at $92.9 million across 311 addresses; Ledger has not confirmed either number.





