Ledger Investigates $86M Crypto Drain as Reseller Supply-Chain Fears Grow
On-chain researchers estimate that somewhere between $72 million and $86 million may have been stolen, as Ledger begins investigating reports of these major crypto losses from users who bought hardware wallets from an authorized Southeast Asian reseller. The hardware wallet manufacturer said there is no indication that its own infrastructure, systems, or services were compromised. However, users are piling on X to complain about substantial losses. The official support channel of Ledger on X confirmed yesterday evening that it was investigating user reports from customers of CryptoBilis, which is listed as an authorized reseller in Indonesia, Malaysia, and the Philippines. Ledger asked CryptoBilis to pause all sales and shipments for the time being. More importantly, the post urged anyone who purchased a device from the reseller in the past 90 days and has not completed installation not to begin setup now. Customers already using such devices were advised to consider transferring their assets to a new Ledger signer using a newly generated seed phrase. On-chain sleuth tanuki42 traced more than $72 million to suspected theft addresses, while fellow investigator Specter estimated losses exceed $86 million, across BTC, ETH, and TRX. Ledger’s official account didn’t confirm either figure, and it remains unclear whether the two estimates include overlapping transactions. MistTrack noted that the losses could be closer to $90 million, while Tether reportedly froze USDT held in addresses connected with the incident. The details on what exactly transpired are still scarce, but Binance co-founder Changpeng Zhao said the currently available information suggests a localized supply-chain attack involving one vendor, with a small number of customers potentially receiving counterfeit or physically tampered Ledger devices. Former Mt. Gox CEO Mark Karpeles added that he had already been examining modified Ledger devices containing a hidden hardware implant and asked CryptoBilis to open units from its inventory to see whether similar components were present. He said an implant he examined could monitor internal communications used to display recovery words, potentially allowing an attacker to capture a seed phrase even though the genuine Ledger Secure Element itself remained intact. Ledger claimed that the reports appear limited to products sold through CryptoBilis and that it has
AI Analysis:
Disclaimer: This information is from public sources for reference only. Traceless does not guarantee accuracy.