BTC $82,749.73 +0.15%
ETH $2,492.63 -0.40%
BNB $749.20 +0.70%
XRP $1.41 +0.16%
SOL $109.91 -0.44%
TRX $0.3308 -0.34%
DOGE $0.0861 +0.97%
ADA $0.2561 +6.98%
BCH $278.29 -0.79%
LINK $12.91 +0.07%
HYPE $84.38 -1.80%
AAVE $174.51 +4.21%
SUI $1.11 +3.56%
XLM $0.1971 +0.97%
ZEC $1,227.27 +0.04%
AAPL $336.64 +0.68%
AMZN $262.49 +2.20%
GOOGL $352.36 +0.42%
MSFT $535.01 +1.38%
META $720.11 -0.61%
NVDA $230.28 -1.90%
TSLA $382.90 +0.75%
SNDK $1,588.57 -3.37%
INTC $104.67 -4.27%
SPCX $163.08 -2.16%
MU $1,032.09 -2.50%
AMD $609.03 -3.73%
BTC $82,749.73 +0.15%
ETH $2,492.63 -0.40%
BNB $749.20 +0.70%
XRP $1.41 +0.16%
SOL $109.91 -0.44%
TRX $0.3308 -0.34%
DOGE $0.0861 +0.97%
ADA $0.2561 +6.98%
BCH $278.29 -0.79%
LINK $12.91 +0.07%
HYPE $84.38 -1.80%
AAVE $174.51 +4.21%
SUI $1.11 +3.56%
XLM $0.1971 +0.97%
ZEC $1,227.27 +0.04%
AAPL $336.64 +0.68%
AMZN $262.49 +2.20%
GOOGL $352.36 +0.42%
MSFT $535.01 +1.38%
META $720.11 -0.61%
NVDA $230.28 -1.90%
TSLA $382.90 +0.75%
SNDK $1,588.57 -3.37%
INTC $104.67 -4.27%
SPCX $163.08 -2.16%
MU $1,032.09 -2.50%
AMD $609.03 -3.73%

Behind the evaporation of 86 million dollars: The Ledger supply chain heist and the most vulnerable link of hardware wallets

Core Viewpoint
Summary: And when the security boundary extends from the chip to the delivery at your doorstep, the last line of defense that users can really rely on may truly just be: don't rush to put your money in.
ChainCatcher Selected
2026-10-10 14:09:01
And when the security boundary extends from the chip to the delivery at your doorstep, the last line of defense that users can really rely on may truly just be: don't rush to put your money in.

Author: Gu Yu, ChainCatcher

A person transferred 80 bitcoins into a newly purchased Ledger. The device was bought from an officially authorized dealer, and the mnemonic phrase was handwritten and locked in a safe. This batch of coins was credited on September 29, with a purchase cost of about 5.2 million dollars, and at one point, the unrealized profit reached 1.38 million dollars. On October 9 at 05:54 (UTC), all 80 BTC were transferred in a single transaction.

He did everything that the textbook required correctly.

On the same morning, similar reports began to appear in large numbers on X and Reddit: a user’s Ledger Stax was transferred with nearly 100,000 USDT, with the mnemonic phrase also handwritten and locked in a safe. The common point among these users is only one—the devices were all purchased from the Southeast Asian dealer CryptoBilis.

On October 9 at 13:32 (UTC), Ledger confirmed that it was investigating and requested CryptoBilis to suspend all sales and shipments of Ledger devices; users who purchased devices from this channel within the last 90 days should not initialize them if they have not been initialized yet, and those that have been initialized should immediately transfer their assets to a new device generated with a new mnemonic phrase.

I. The scale of losses may exceed 90 million dollars

How large the losses are, can only be estimated on-chain at present.

On-chain investigator Specter first published ten aggregation addresses at 12:24, covering Bitcoin, Ethereum, and Tron, estimating losses exceeding 86 million dollars; another investigator, tanuki42, listed eight of those addresses, giving over 72 million dollars; SlowMist's MistTrack stated that the amount "is approaching 90 million dollars"; Bitquery covered 311 wallets, estimating about 92.9 million dollars, with approximately 42 million in Ethereum, about 17.6 million in Bitcoin, and around 16.5 million in USDT. Arkham has marked these addresses as "Ledger Theft," and as of Friday afternoon, about 71.5 million dollars remained in the marked addresses, with the largest positions including approximately 29.4 million dollars in ETH, 17.5 million dollars in BTC, 13.6 million dollars in USDD, and 10.8 million dollars in USDT.

More noteworthy than the total amount is the profile of the victims. Lookonchain monitored that a certain address deposited 7 million USDT three weeks after purchasing the device, and all of it was transferred out about ten hours before the report, possibly the largest single transaction; three other marked Bitcoin addresses held a total of about 211 BTC at 13:44 (UTC), with no transfers out at that time. According to Chain INK statistics, this incident involved about 98 wallets, averaging about 890,000 dollars each.

This is not just retail investors losing a few hundred dollars. This is the kind of wallet where someone put in their savings.

Comparing this with another incident this year, the difference in distribution is more telling than the total amount. In July, Coldcard suffered a loss of about 111 million dollars due to a firmware random number defect that allowed the mnemonic phrase to be inferred, but it was spread across more than 5,200 wallets, averaging about 21,000 dollars each; whereas this incident with CryptoBilis, which reached second place in less than a day (about 87 million dollars), only involved about 98 wallets, averaging close to 890,000 dollars.

Coldcard's incident was a wide net, while this one was precise harvesting. This distribution itself supports the inference of "implanted modules": the attacker has control over the mnemonic phrases generated on each modified device, allowing them to wait—wait until the money comes in before acting, and specifically targeting those worth attacking. The 80 BTC monitored by Lookonchain were transferred all at once after lying quietly in the device for ten days.

II. After opening the device: the microcontroller on the screen ribbon cable

Ledger has not explained the attack mechanism, but someone has already opened the device.

The most specific description comes from former Mt.Gox CEO Mark Karpelès. He stated that one device he received came from Malaysia—listed at half price on Amazon, shipped from Malaysia rather than Japan where he ordered it, which itself was the first warning sign. After opening it, he found a hidden module where the screen padding should have been: a single-strand wire of an antenna, space freed up by a shortened battery or removed screen padding, an LTE module with eSIM, and a microcontroller connected to the device's SPI bus.

His judgment is that this microcontroller can recognize the font used by Ledger on the 128×64 screen, lock onto the mnemonic phrase settings interface, and display the mnemonic phrase character by character as the user writes it down, sending it out via LTE.

SlowMist's Chief Information Security Officer 23pds provided the corresponding technical path: the attacker installed a microcontroller inside the device, connecting to the screen's SPI data line; after the mnemonic phrase is generated in the secure element, it is displayed on the screen for the user to write down, while the malicious module synchronously records every character output on the screen, then transmits it through the built-in LTE or eSIM. He emphasized that the role of the secure element is to prevent the private key from being directly read or exported, but it cannot control what is being displayed on the screen—the few seconds when the mnemonic phrase appears on the screen is the attack window.

This explains the most counterintuitive aspect of the entire incident: these devices can pass Ledger's authenticity verification. Because the secure element is real, it does correctly generate the mnemonic phrase and does sign normally; it is just being "watched." The firmware also cannot detect it, as the implanted module only listens during screen refreshes. In other words, the only way to detect it is—by opening the device.

Two other possibilities also exist: one is pre-set mnemonic phrases—attackers power on, set up, record, and repackage in advance, while users think they are "setting up a new device," but are actually using a set of words already mastered by the attacker; the other is phishing. Developer 0xQuit believes that some victims may have fallen victim to phishing, stating that it is irresponsible to simply say "Ledger was hacked."

III. "Officially Authorized" endorses sales qualifications, not supply chain integrity

CryptoBilis is not a street vendor.

It was established in Kuala Lumpur in 2020 and is listed in black and white on Ledger's official dealer page as an officially authorized dealer, covering Malaysia, Indonesia, and the Philippines, selling not only Ledger but also Trezor, OneKey, Tangem, and SafePal.

The problem lies precisely here. Users follow the security guidelines taught by the industry: if they cannot buy directly from the official website, they look for "officially authorized dealers." But the authorization endorses this company's sales qualifications, not the integrity of every device in its warehouse, nor the integrity of every employee handling and sorting them. Once a device leaves the factory, goes through logistics, passes through warehouses, is sorted, delivered to dealers, and then sent to the doorstep, any link in this chain could be intercepted, opened, and restored—the heat shrink film on Karpelès's device was intact.

Once the device leaves Ledger's custody, the word "authorized" no longer provides any physical guarantee.

Even more subtle is the timeline. Newly disclosed company records show that CryptoBilis was acquired in March of this year, and a person named "Jia Ming," registered in Heilongjiang Province, China, has held 100% of the company's shares since August 3. The former co-founder confirmed the acquisition in March, stating that the original shareholders subsequently withdrew from all operational, management, and administrative positions, and after the handover, they could no longer understand the company's actual operations, urging the current management to handle matters transparently. According to Deep Tide TechFlow reports, the acquirer signed a confidentiality agreement with former executives that restricts them from disclosing transaction details, effective until October 19—when the incident erupted on October 9, the former executives were still legally unable to freely discuss the acquisition details.

Currently, there is no conclusive evidence to suggest that the change in ownership is related to the device theft, and Ledger has only halted sales without making any accusations.

On October 10, CryptoBilis announced the suspension of sales and shipments of all brand hardware wallets in its stores and online channels in Malaysia, the Philippines, and Indonesia, reminding users: the mnemonic phrase must be generated by the device during initialization and handwritten by the user; if the device comes with a pre-printed or written mnemonic card, it should be considered unsafe.

Moreover, CryptoBilis is not the only channel that has encountered problems this year. In September, Trezor admitted that its logistics contractor ShipMonk was breached, resulting in the leakage of real names, phone numbers, and home addresses of about 81,000 U.S. customers; in January of this year, Ledger disclosed that payment processor Global-e leaked some official website buyers' names and contact information. These incidents did not directly result in lost coins, but they repeatedly handed over the list of "who received a hardware wallet and when" to attackers.

In the past three months, the weakest link in cold storage has shifted from code to logistics.

IV. Recovery, self-rescue, and that cheapest piece of advice

The window for recovery is closing.

According to MistTrack, Tether has frozen a large amount of USDT at the relevant addresses; the attackers immediately began exchanging USDT for USDD—a Tron stablecoin that Tether cannot freeze. According to Onchain Lens, 430.2 ETH (about 1.07 million dollars) has already entered Tornado Cash through four wallets. Bitcoin and Ethereum do not have freeze switches; once the money leaves, only exchanges remain as a barrier.

SlowMist and Security Alliance have opened a help channel, with the latter urging users whose funds have been transferred to relevant addresses to contact their SEAL 911 emergency response team.

Among the advice given by the industry, the most practical one comes from CZ. While judging this as a "supply chain attack limited to a specific dealer," he provided a specific actionable plan:

"After buying a hardware wallet (or downloading a new software wallet), keep it for a few weeks before transferring any meaningful amount into it. During these weeks, continuously monitor relevant news… The hardware may have been modified, and the software's official website may also have been attacked. Self-custody means extra responsibility."

The logic behind this "quarantine period" is not technical but informational: if a batch of devices has already been tampered with when delivered to the dealer, on-chain analysts need time to discover the first batch of stolen devices and issue alerts—these two weeks are the time you buy for yourself.

But what this incident truly rewrites is the boundary of the term "self-custody."

For the past decade, the industry has built the narrative of self-custody security almost entirely on cryptography and hardware: secure elements, EAL5+, PIN erasure, open-source audits. None of these have been breached. What has been breached is the journey from the factory to your doorstep—a journey composed of logistics providers, warehouses, dealers, and couriers, where no link can be verified by the user.

Hardware wallets promise that "private keys never leave the device." The irony this time is that the private keys indeed never left the device—they were just seen by someone else during those few seconds they were displayed to the user.

And when the security boundary extends from the chip to the delivery at your doorstep, the last line of defense that users can truly rely on may really just be: Don't rush to put your money in.

Join ChainCatcher Official
Telegram Feed: @chaincatcher
X (Twitter): @ChainCatcher_
warnning Risk warning
app_icon
ChainCatcher Building the Web3 world with innovations.