Ledger confirms the discovery of a spy device in a crypto wallet
Summarize this article with:

The Ledger affair takes a new turn. The crypto wallet manufacturer confirms that it has discovered an unauthorized hardware implant in the device of a user affected by the recent thefts in Southeast Asia. The possibility of physical handling before delivery is strengthening. Suspected losses now approach $93 million, but this amount has not been validated by Ledger.

An expert examines an open hardware wallet and spots a suspicious component on its electronic card.

In brief

  • Ledger confirms a hardware implant in the device of at least one affected user.
  • Crypto losses are estimated at up to $93.4 million by independent analysts.
  • Reseller CryptoBilis suspended sales of hardware wallets during the investigation.

Ledger finally confirms physical manipulation

A few days earlier, Ledger was still investigating without confirming the cause. More than $86 million in losses were then associated with wallets purchased from CryptoBilis, a reseller present in Southeast Asia. Saturday October 10, the company provided a much more concrete element.

A device belonging to one of the affected users contained an unauthorized hardware implant. This discovery seriously reinforces the hypothesis of a supply chain attack.

CryptoBilis notably sold Ledger devices in Indonesia, Malaysia and the Philippines. Ledger had already asked him to temporarily stop sales and shipments for the investigation. The reseller has since suspended the sale of all of its hardware wallets.

Ledger nevertheless emphasizes one point: there is currently no evidence that its infrastructure, systems or internal services have been compromised. The distinction is important. The problem could lie after manufacturing, somewhere between the manufacturer and the end user.

Your first cryptos with Binance
This link uses an affiliate program

An implant capable of spying on the recovery phrase

Former Mt. Gox boss Mark Karpelès had released images of a modified Ledger Nano X even before Ledger’s official confirmation. Inside, he claims to have discovered a small electronic card hidden behind the screen. The device notably included cellular communication components.

Its alleged operation is particularly troublesome for crypto security. The implant would not need to break Ledger’s Secure Element. It could simply monitor the information sent to the screen during wallet configuration.

This is precisely when the 24 recovery words appear. Once this sentence is intercepted, the attacker can theoretically recreate the wallet on another device and move the assets without needing the original Ledger.

The device could even leave the original secure chip intact. A device modified in this way would therefore be likely to appear authentic during certain checks. The case illustrates another face of supply chain attacks. Already in 2025, the CTO of Ledger warned of a compromise of NPM packages threatening crypto users. This time, the problem is not hidden in software. It is located directly in the hardware.

Up to $93 million in crypto under surveillance

The numbers continue to evolve. Yfarmx estimates suspected losses at approximately $93.4 million spread across 471 addresses. Bitquery comes in at around 92.9 million across 311 unique addresses.

Ledger has not confirmed any of these totals. It is also not established that each address counted corresponds to a physically modified device. For now, Ledger has only publicly confirmed the implant on a device owned by an affected user.

Bitcoin, ether and several stablecoins are among the assets tracked in suspicious transactions. Ledger recommends that people who have recently purchased a device from CryptoBilis do not start setting it up. For those who have already used it, the company advises considering transferring to a new sign with a new recovery phrase.

Reusing the same 24 words on a new device would obviously not solve anything if the sentence has already been intercepted. Ledger is also working on new protections against physical manipulation. The episode comes at a time when hardware wallets are being sold as a solution allowing you to keep your crypto keys far from centralized platforms. However, no system protects against all scenarios.

A fake Ledger app had already stolen nearly $9.5 million in crypto earlier this year. Here, the attack is different. The user can follow the usual rules, keep their recovery phrase offline and not sign any suspicious transactions. If the device itself was modified before it arrived, the threat begins even earlier. This is precisely what Ledger must now determine: how many devices were manipulated, when and by whom.

Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts