BTC $82,711.82 +0.33%
ETH $2,492.73 -0.27%
BNB $748.39 +0.65%
XRP $1.40 +0.19%
SOL $109.81 -0.62%
TRX $0.3308 -0.29%
DOGE $0.0859 +0.90%
ADA $0.2530 +5.46%
BCH $278.16 -0.63%
LINK $12.88 -0.49%
HYPE $84.33 -1.86%
AAVE $173.51 +3.58%
SUI $1.10 +2.52%
XLM $0.1967 +0.69%
ZEC $1,231.35 +0.36%
AAPL $336.42 -0.31%
AMZN $262.60 +2.40%
GOOGL $352.37 +0.51%
MSFT $535.01 +1.63%
META $719.97 -0.50%
NVDA $230.25 -1.55%
TSLA $382.93 +0.94%
SNDK $1,588.58 -3.35%
INTC $104.61 -4.11%
SPCX $163.10 -2.19%
MU $1,031.93 -2.34%
AMD $608.97 -3.60%
BTC $82,711.82 +0.33%
ETH $2,492.73 -0.27%
BNB $748.39 +0.65%
XRP $1.40 +0.19%
SOL $109.81 -0.62%
TRX $0.3308 -0.29%
DOGE $0.0859 +0.90%
ADA $0.2530 +5.46%
BCH $278.16 -0.63%
LINK $12.88 -0.49%
HYPE $84.33 -1.86%
AAVE $173.51 +3.58%
SUI $1.10 +2.52%
XLM $0.1967 +0.69%
ZEC $1,231.35 +0.36%
AAPL $336.42 -0.31%
AMZN $262.60 +2.40%
GOOGL $352.37 +0.51%
MSFT $535.01 +1.63%
META $719.97 -0.50%
NVDA $230.25 -1.55%
TSLA $382.93 +0.94%
SNDK $1,588.58 -3.35%
INTC $104.61 -4.11%
SPCX $163.10 -2.19%
MU $1,031.93 -2.34%
AMD $608.97 -3.60%

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

Core Viewpoint
Summary: Cold wallets are no longer the absolute safe answer.
OdailyNews
2026-10-10 13:57:52
Cold wallets are no longer the absolute safe answer.

Original | Odaily Azuma

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

What has always been regarded as the "safest coin storage solution," cold wallets, is no longer safe.

On the evening of October 9, on-chain detective Specter reported that multiple Ledger user wallet theft reports had surfaced on X and Reddit. After tracking the relevant addresses, Specter discovered that the addresses involved had received funds from hundreds of wallets across multiple mainstream blockchains, including Ethereum, TRON, and Bitcoin, with total losses exceeding $86 million.

From supply chain anomalies to suspected hardware implants, where is the problem?

After the theft incident occurred, Ledger officially released a statement pointing the investigation towards a distributor named CryptoBilis.

Ledger stated that the company is investigating a theft incident involving assets of Southeast Asian users who had previously purchased devices through the distributor CryptoBilis. Ledger has requested that the distributor suspend sales and shipments and advised users who purchased devices through this channel in the past 90 days not to initialize them; users who have already set up their devices should create new Ledger signing devices using new mnemonic phrases and transfer their assets to new wallets.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

More specific clues came from former Mt. Gox CEO Mark Karpelès. As early as October 8, Karpelès warned that there were counterfeit or tampered Ledger devices for sale on the market that contained hidden SIM cards capable of transmitting stolen mnemonic phrases.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

After the incident, Karpelès further disclosed that a Ledger hardware wallet he purchased from Malaysia had intact packaging, but a suspicious module with a SIM card chip was hidden beneath the screen padding.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

Slow Mist's Chief Information Security Officer 23pds speculated that attackers might intercept data displayed on the device's screen through malicious modules, recording recovery phrases when users initialize wallets or view mnemonic phrases, and then transmit the information via LTE or eSIM.

The danger of such attacks lies in the fact that they may bypass users' conventional understanding of hardware wallet security. The secure element of a hardware wallet can protect private keys from being directly read, but it may not necessarily prevent external hardware from intercepting screen information. In other words, even if the core secure element has not been compromised, physical tampering with the device can still lead to mnemonic phrase leakage.

However, the aforementioned attack mechanism remains a technical speculation, and the specific cause of this security incident is yet to be further verified. Another viewpoint suggests that the attackers chose to act yesterday precisely because Karpelès's warning was gradually spreading, and the attackers, fearing their actions had been exposed, began to move funds.

If this attack path is ultimately confirmed, then the issue exposed by this incident is not just a security problem with a particular wallet, but a more fundamental risk: how safe can self-custody be when users cannot confirm that the hardware in their hands has remained trustworthy from factory to delivery?

Lamborghini, confidentiality restrictions, change of ownership… CryptoBilis is full of doubts

As the investigation deepens, the background of the involved distributor CryptoBilis is gradually coming to light.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

CryptoBilis is a Web3 e-commerce and self-custody tool seller located in Petaling Jaya, Malaysia, with business including hardware wallets and other products. According to public information, the company was co-founded by Arravind Prabu and Vimal Selvamany, with the former serving as CEO and the latter as CTO.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

However, after the incident drew attention, Arravind Prabu quickly clarified on X that the claim that he was still operating CryptoBilis was inaccurate. The company had been acquired as early as March of this year, and the original management team had exited all operational, management, and system permissions. Regarding the current incident, he suggested that the public contact a current responsible person, Nicholas Chang (nicholas@cryptobilis.com).

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

Community users immediately continued to question why, since the company had changed ownership, there had been no public announcement, and the account's most recent post even showcased a Lamborghini… Arravind Prabu responded that the post was made by the new management team, and the original team had to wait until October 19 to publicly announce the transaction due to confidentiality clauses in the contract, and they currently no longer have access to the company's account, backend, and operational systems.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

The original management team has exited operations, which is the former CEO's public statement; however, there is still a lack of independently verified information regarding what exactly happened within the company after the handover.

Another more concerning clue comes from the company's equity. Bitcoin News reported after the incident that relevant equity transfer records show that an individual named JIAMING, registered at an address in Heilongjiang Province, China, has held 100% of CryptoBilis's shares since August 3.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

This means that at least from public information, CryptoBilis indeed changed ownership months before the suspected supply chain attack occurred. However, there is currently no conclusive evidence to confirm the specific transaction arrangements for the equity change, the actual operational situation of the new management team, or whether the new shareholder is related to the involved devices. One cannot directly link the new shareholder's registered address or acquisition time to the theft incident.

In response to the investigation, CryptoBilis has publicly announced through its official X account the suspension of hardware wallet sales and shipments at all stores and online channels in Malaysia, the Philippines, and Indonesia, with physical stores temporarily closed. The company stated that this move aims to cooperate with the Ledger security incident investigation and accept independent experts' review of internal processes; unfulfilled orders will be actively handled by customer service, and further progress is expected to be announced within three working days.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

As of the publication of this article, the most critical questions of the incident remain unanswered------at which stage was the device tampered with, whether the original supply chain was exploited, and whether the current management team can provide records sufficient to reconstruct the delivery process------these questions await further investigation and disclosure for answers.

Individual loss cases: A major user just bought a wallet a week ago…

From the current on-chain tracking situation, the losses from this incident are not only staggering, but the flow of funds also shows different characteristics.

Alex Thorn, head of research at Galaxy, analyzed that the Bitcoin losses related to this Ledger and CryptoBilis supply chain incident currently amount to 213.42 BTC, worth approximately $17.7 million at the time. Of this, about 92% of the Bitcoin was held for less than 90 days when it was aggregated. The related BTC currently tracked has not yet been spent and is concentrated in three aggregation addresses.

From Supply Chain Anomalies to Suspected Hardware Implants: A Comprehensive Analysis of the Ledger User Theft Incident

The losses of individual victims are even more shocking. Lookonchain monitoring indicated that a user marked with the address TY24Ya purchased the relevant Ledger device three weeks ago and subsequently deposited 7 million USDT into the wallet, but this fund was entirely transferred away within about 10 hours; another user bought 80 BTC for approximately $5.2 million four months ago, at one point showing a profit of about $1.38 million, but after purchasing a Ledger device from CryptoBilis a week ago, transferred all BTC into that device, ultimately suffering a total loss.

Can the funds be recovered?

Shortly after the incident occurred, the attackers quickly began the money laundering and mixing process.

On-chain analysis firm Onchain Lens tracked that the suspected attackers have deposited 430.2 ETH, worth about $1.07 million, into Tornado Cash through four wallets, attempting to sever the traceability chain on the Ethereum blockchain.

Meanwhile, the industry has also begun to "block" the attackers' illicit funds. Tether has currently frozen some USDT related to this incident, but the hackers' response has also been cunning and professional; after Tether's intervention, they quickly used the SUN.io and USDD PSM mechanisms within the TRON ecosystem to convert the unfrozen USDT into the more censorship-resistant decentralized stablecoin USDD, with some transfers also involving Binance hot wallets (which may become clues for identifying the hackers in the future).

Currently, the key to recovering stolen assets lies in the ability to timely identify and intercept funds still remaining on centralized platforms or in freezeable stablecoin addresses. For assets that have entered mixing protocols, cross-chain transfers, or other complex paths, the difficulty of tracking and recovering may further increase.

As of now, Ledger has not released a complete asset recovery plan, nor disclosed any compensation arrangements for victims. As the investigation progresses, whether assets can be recovered and who bears the responsibility remains to be further confirmed.

Cold wallets are no longer the absolute safe answer

For a long time, cold wallets have been regarded as one of the most reliable solutions for self-custody of crypto assets, with Ledger being the most representative brand in this market. Compared to exchange custody, users keeping their own private keys was originally meant to reduce reliance on third parties. However, this incident raises a disturbing question ------ if the device purchased by the user was tampered with before delivery, even if the packaging is intact and the core security components have not been compromised, the assets may still face risks.

Of course, the specific attack path of the current incident has not yet been definitively confirmed, nor can it be used to deny the overall security of hardware wallets, but it at least reminds users that security depends not only on the device itself but also on the purchasing channel, initialization process, and the way mnemonic phrases are stored.

When risks may begin at the source of the supply chain, even the seemingly safest self-custody solutions may fail. This time, it truly is a situation that is hard to guard against.

Join ChainCatcher Official
Telegram Feed: @chaincatcher
X (Twitter): @ChainCatcher_
warnning Risk warning
app_icon
ChainCatcher Building the Web3 world with innovations.