The theft incident at Ledger today is its largest security event, with a fake application causing a loss of 9.5 million dollars
Hardware wallet manufacturer Ledger has once again experienced a security incident today, with third-party security agencies estimating the losses to be close to 90 million USD. Ledger is investigating the financial losses related to devices sold by its Southeast Asian authorized distributor CryptoBilis and has requested the distributor to suspend sales and shipments, advising users who purchased devices through this channel in the past 90 days to exercise caution or transfer their assets. The cause of the incident has not yet been definitively confirmed, but it is suspected to involve supply chain or device tampering risks.
Major historical attacks and financial loss incidents related to Ledger include:
In 2018, early hardware and supply chain research vulnerabilities emerged. Security researchers demonstrated the possibility of tampering with the Nano S before it left the factory, as well as issues such as MCU bootloader bypass, isolation vulnerabilities, and Bitcoin change address injection. Ledger gradually released security announcements and completed fixes, with related issues mostly being research-level vulnerabilities or requiring physical contact with the device to exploit.
In 2020, Ledger experienced a massive customer data leak. Attackers obtained e-commerce and marketing databases through third-party API keys and vulnerabilities related to Shopify, exposing over 1 million email addresses and approximately 272,000 to 292,000 detailed customer records, including names, addresses, and phone numbers. The hardware and private keys were not affected, but this incident triggered long-term phishing, social engineering, and counterfeit official letter scams.
In December 2023, the Ledger Connect Kit suffered a supply chain attack. After a former employee fell victim to a phishing attack, their NPMJS account was compromised, and attackers released a malicious version of the Connect Kit, injecting malicious code into DApps that relied on the library, enticing users to sign fraudulent transactions. The active window of the attack was about 2 hours, with losses estimated between 480,000 to 600,000 USD. The hardware and Ledger Live itself were not directly breached.
In January 2026, third-party Global-e order data was leaked. The payment and logistics partner's system suffered unauthorized access, exposing some Ledger.com order-related information, including names, addresses, and contact details. Ledger's own systems and private keys were not affected, but the phishing risk rose again.
In April 2026, counterfeit Ledger Live application scams appeared on the App Store. The counterfeit application was listed for about a week, tricking users into entering their recovery phrases, with over 50 victims losing approximately 9.5 million USD across multiple blockchains. Apple subsequently removed it, and Ledger emphasized that it would never ask for 24-word recovery phrases.
In August 2026, Ledger disclosed vulnerabilities related to Ethereum application signatures, including command interleaving causing display content to be out of sync with signature parameters, and Clear-signing bypass issues. The vulnerabilities required malicious hosts to cooperate, and Ledger stated that there was no evidence of actual user exploitation; related issues have been fixed in the new version.
On October 9, 2026, a large-scale wallet draining incident related to the CryptoBilis distributor occurred, with estimated losses close to 90 million USD. Ledger is investigating, and the incident is suspected to involve supply chain or device tampering attacks targeting a single channel. The official sales have been suspended, and affected users are advised to migrate their assets.






