BTC $82,949.05 +0.62%
ETH $2,506.15 +1.00%
BNB $750.15 +1.26%
XRP $1.40 +0.80%
SOL $110.23 +1.22%
TRX $0.3306 -0.42%
DOGE $0.0857 +0.65%
ADA $0.2525 +5.13%
BCH $280.69 +2.05%
LINK $13.05 +2.21%
HYPE $85.52 +1.65%
AAVE $169.18 +1.28%
SUI $1.11 +5.16%
XLM $0.1971 +1.70%
ZEC $1,221.81 +1.03%
AAPL $336.37 +0.01%
AMZN $262.43 -0.11%
GOOGL $351.32 -0.19%
MSFT $535.23 -0.01%
META $719.39 +0.10%
NVDA $230.55 +0.46%
TSLA $382.73 -0.03%
SNDK $1,599.25 +1.15%
INTC $105.19 +0.60%
SPCX $163.69 +0.56%
MU $1,036.89 +0.65%
AMD $609.21 +0.25%
BTC $82,949.05 +0.62%
ETH $2,506.15 +1.00%
BNB $750.15 +1.26%
XRP $1.40 +0.80%
SOL $110.23 +1.22%
TRX $0.3306 -0.42%
DOGE $0.0857 +0.65%
ADA $0.2525 +5.13%
BCH $280.69 +2.05%
LINK $13.05 +2.21%
HYPE $85.52 +1.65%
AAVE $169.18 +1.28%
SUI $1.11 +5.16%
XLM $0.1971 +1.70%
ZEC $1,221.81 +1.03%
AAPL $336.37 +0.01%
AMZN $262.43 -0.11%
GOOGL $351.32 -0.19%
MSFT $535.23 -0.01%
META $719.39 +0.10%
NVDA $230.55 +0.46%
TSLA $382.73 -0.03%
SNDK $1,599.25 +1.15%
INTC $105.19 +0.60%
SPCX $163.69 +0.56%
MU $1,036.89 +0.65%
AMD $609.21 +0.25%

ledger

Ledger is a company focused on cryptocurrency hardware wallets, providing secure storage solutions to protect users' digital assets. Its products include the Ledger Nano S and Ledger Nano X, which support multiple cryptocurrencies and enhance security through offline storage of private keys. Ledger's devices are widely used by individual and institutional investors, aiming to prevent hacking and theft of digital assets.
All
Article
Flash

Hardware wallet distributor CryptoBilis announced the suspension of Ledger device sales to cooperate with the investigation into financial losses

Hardware wallet dealer CryptoBilis announced that, due to Ledger investigating a case involving fund losses for Southeast Asian users, the company has suspended all sales and shipments of Ledger devices and is cooperating with Ledger's investigation. Ledger previously stated that it is investigating reports of fund losses from Southeast Asian users who purchased products from this dealer, and as a precaution, has requested CryptoBilis to suspend the sales and shipments of related devices, advising users who purchased devices in the past 90 days not to set them up if they have not completed initialization.CryptoBilis reminds users who have completed setup to follow Ledger's advice and transfer their assets to a new Ledger signing device generated with a new mnemonic phrase. It emphasizes that the mnemonic phrase must be generated by the device during initialization and handwritten by the user; if the device comes with a pre-printed or written mnemonic card or paper, or if the mnemonic has been seen by others, the wallet should be considered unsafe, and users should not disclose their mnemonic phrase or PIN to anyone. The notice also warns to be cautious of third parties claiming to assist in recovering lost funds, as such proposals are often scams.For users who have already experienced fund losses, CryptoBilis recommends contacting their official customer service channels and providing the order number, purchase time and location, device serial number, affected wallet address, and transaction ID, while keeping the device and packaging, not resetting or discarding them, and suggests reporting to the police. The company stated that it will not send users links requesting them to connect wallets, input mnemonic phrases, or install software.

Slow Fog Analysis suggests hardware implantation to steal mnemonic phrases from Ledger

The Chief Information Security Officer of Slow Mist Security, 23pds, stated that if the modification of the Ledger device's PCB is indeed as described by former Mt. Gox CEO Mark Karpelès, the attacker would possess a considerable level of technical skill.23pds mentioned that the possible attack process involves the wallet generating a mnemonic phrase within a secure element and displaying it on the screen for the user to write down. A malicious module could obtain the displayed content through screen data lines such as SPI, record the complete mnemonic phrase, and then send the data to the attacker via LTE/eSIM. The secure element can prevent the private key from being directly read or exported, but it cannot stop external modules from accessing the information currently displayed on the screen. He noted that the above analysis is based on the premise that the PCB has indeed been modified in the described manner, and the relevant attack paths and hardware implantation still require independent verification.Mark Karpelès previously stated that a Ledger hardware wallet he received was suspected of being implanted with a spy module. The device came from Malaysia, the outer packaging was intact with shrink wrap, and the implant was hidden in the position where the screen originally had a cushion, containing LTE communication components, an antenna, eSIM, and a microcontroller connected to the Ledger SPI bus, capable of analyzing the characters displayed to the user and sending relevant data after the mnemonic phrase setup is completed.

The hardware wallet distributor CryptoBilis changed ownership in March, with the equity pointing to a person from Heilongjiang, China

The Malaysian hardware wallet distributor CryptoBilis has been revealed to have changed ownership during the investigation into a suspected supply chain attack on Ledger devices. Newly disclosed company records show that an individual named Jiaming, with a registered address in Heilongjiang Province, China, has held 100% of the company's shares since August 3.The former co-founder of CryptoBilis confirmed that the company was acquired in March of this year, and the original shareholders subsequently withdrew from all operational, management, and administrative positions. The founding team has been unable to understand the actual operations of the company after the handover, only continuing to assist with some activity coordination, and stated that they are no longer part of the company, urging the current management to handle the matter transparently.As the change in ownership was exposed, CryptoBilis has come under scrutiny for its alleged involvement in the supply chain attack on Ledger hardware wallets, with related devices reportedly implanted with hidden modules capable of stealing recovery phrases. There is currently no conclusive evidence linking the change in ownership to the wallet theft incident. CryptoBilis has temporarily suspended sales and shipments of all brand hardware wallets at its stores and online channels in Malaysia, the Philippines, and Indonesia, and has closed offline stores until further notice.

The theft incident at Ledger today is its largest security event, with a fake application causing a loss of 9.5 million dollars

Hardware wallet manufacturer Ledger has once again experienced a security incident today, with third-party security agencies estimating the losses to be close to 90 million USD. Ledger is investigating the financial losses related to devices sold by its Southeast Asian authorized distributor CryptoBilis and has requested the distributor to suspend sales and shipments, advising users who purchased devices through this channel in the past 90 days to exercise caution or transfer their assets. The cause of the incident has not yet been definitively confirmed, but it is suspected to involve supply chain or device tampering risks.Major historical attacks and financial loss incidents related to Ledger include:In 2018, early hardware and supply chain research vulnerabilities emerged. Security researchers demonstrated the possibility of tampering with the Nano S before it left the factory, as well as issues such as MCU bootloader bypass, isolation vulnerabilities, and Bitcoin change address injection. Ledger gradually released security announcements and completed fixes, with related issues mostly being research-level vulnerabilities or requiring physical contact with the device to exploit.In 2020, Ledger experienced a massive customer data leak. Attackers obtained e-commerce and marketing databases through third-party API keys and vulnerabilities related to Shopify, exposing over 1 million email addresses and approximately 272,000 to 292,000 detailed customer records, including names, addresses, and phone numbers. The hardware and private keys were not affected, but this incident triggered long-term phishing, social engineering, and counterfeit official letter scams.In December 2023, the Ledger Connect Kit suffered a supply chain attack. After a former employee fell victim to a phishing attack, their NPMJS account was compromised, and attackers released a malicious version of the Connect Kit, injecting malicious code into DApps that relied on the library, enticing users to sign fraudulent transactions. The active window of the attack was about 2 hours, with losses estimated between 480,000 to 600,000 USD. The hardware and Ledger Live itself were not directly breached.In January 2026, third-party Global-e order data was leaked. The payment and logistics partner's system suffered unauthorized access, exposing some Ledger.com order-related information, including names, addresses, and contact details. Ledger's own systems and private keys were not affected, but the phishing risk rose again.In April 2026, counterfeit Ledger Live application scams appeared on the App Store. The counterfeit application was listed for about a week, tricking users into entering their recovery phrases, with over 50 victims losing approximately 9.5 million USD across multiple blockchains. Apple subsequently removed it, and Ledger emphasized that it would never ask for 24-word recovery phrases.In August 2026, Ledger disclosed vulnerabilities related to Ethereum application signatures, including command interleaving causing display content to be out of sync with signature parameters, and Clear-signing bypass issues. The vulnerabilities required malicious hosts to cooperate, and Ledger stated that there was no evidence of actual user exploitation; related issues have been fixed in the new version.On October 9, 2026, a large-scale wallet draining incident related to the CryptoBilis distributor occurred, with estimated losses close to 90 million USD. Ledger is investigating, and the incident is suspected to involve supply chain or device tampering attacks targeting a single channel. The official sales have been suspended, and affected users are advised to migrate their assets.

Zhao Changpeng warned about the risk of supply chain attacks on Ledger hardware wallets, suspected to involve a single distributor selling counterfeit or tampered devices

Zhao Changpeng issued a reminder for Ledger hardware wallet users to remain vigilant, especially those who have purchased devices recently. According to the information currently available, this incident appears to be limited to the supply chain, involving a supplier, and a few users may have purchased counterfeit or tampered Ledger devices.Zhao Changpeng stated that Ledger is a well-established and relatively secure hardware wallet brand in the industry, but such incidents can still occur. He anticipates and calls for the BNB ecosystem and the entire cryptocurrency industry to assist in tracking the stolen funds and promoting recovery.Previously, Ledger confirmed that it is investigating an asset theft incident involving Southeast Asian users, who had purchased devices through the distributor CryptoBilis. Ledger has requested CryptoBilis to suspend sales and shipments and advised users who purchased devices through this distributor in the past 90 days not to initialize their devices; if they have already completed the setup, they should create a new Ledger signing device using a new mnemonic phrase and transfer their assets to the new wallet.On-chain investigator Specter estimates that this incident has led to the theft of hundreds of wallets on the Bitcoin, Ethereum, and TRON networks, with losses exceeding 86 million dollars. Security researcher tanuki42 previously estimated the losses to be over 72 million dollars and stated that the amount is still increasing. Currently, the specific cause of the incident and whether the involved devices have security vulnerabilities are still under investigation.

first_img XRP Ledger activates delegated permission functionality, supporting the separation of payment and compliance functions

On October 8, the XRP Ledger activated the PermissionDelegationV1_1 feature, allowing account owners to authorize other accounts to perform specific tasks without relinquishing control of the account's master key. According to the monitoring site XRPL Dashboard, such upgrades require over 80% support from trusted validators for two consecutive weeks; based on the current 35 validators, at least 29 must support it. The countdown for this feature was reset in September due to the support rate falling below the threshold.This feature allows enterprises to split permissions by function. Stablecoin issuers can authorize compliant accounts to approve new customers while keeping the master key offline. Authorized accounts use their own keys to sign and can only perform the granted operations; owners can change or revoke these permissions at any time. Each authorized account can receive up to 10 permissions, which limit the types of operations they can perform, rather than automatically setting spending limits. Banks have previously separated payment and compliance responsibilities at the employee level, and this upgrade enforces such division at the ledger level.According to a report shared by Evernorth, a subsidiary of XRP Treasury, the network held an average of $3.72 billion in tokenized assets and $539 million in Ripple's RLUSD stablecoin in the second quarter, totaling approximately $4.26 billion. Official guidance advises users not to delegate PaymentBurn permissions before separately fixing activation; this permission is intended for assistants to destroy tokens but, under certain conditions, also allows for the creation of new tokens. This warning pertains to tokens issued on the ledger rather than newly minted XRP.

first_img Taurus Lianchuang: Banks need to build a three-layer infrastructure to access the Swift blockchain ledger

Lamine Brahimi, co-founder and managing partner of the cryptocurrency custody and tokenization company Taurus, stated in an interview with CoinDesk that banks need to meet three conditions to access the newly launched blockchain ledger by Swift: a proprietary permissioned chain that interacts with the Swift ledger, wallet capabilities, and tokenization and smart contract capabilities to integrate Swift's smart contracts.He pointed out that this means the Swift ledger is not a replacement for banks' internal systems, but rather acts as an orchestration layer, helping institutions achieve cross-border, round-the-clock transfers of tokenized deposits, with final settlement still completed through existing arrangements. Banks still need to hold and manage tokenized deposits, digital asset wallets, and related smart contracts themselves. In July, Swift announced that 17 banks were preparing for real-time transactions of tokenized deposits; in August, HSBC and Standard Chartered completed the first real-time interbank transaction, followed by DBS and Citibank completing weekend cross-border USD payments, reducing settlement time from a maximum of two business days to just a few minutes.Brahimi stated that additional infrastructure should not be seen as a flaw in Swift's design; the ledger is still an early product but provides banks with a choice between existing payment channels and tokenized deposits that can circulate around the clock. Taurus announced in August that it had completed Swift integration, providing the aforementioned three layers of capability through a single platform. He added that tokenized deposits were used very little before Swift's announcement, primarily adopted by larger global banks like JPMorgan. The Swift model retains deposits on the banks' balance sheets, distinguishing it from stablecoins issued outside the banking system.

first_img Ledger launched a Bitcoin lending feature, allowing users to collateralize BTC to borrow stablecoins

Ledger launched its self-custody lending feature Crypto Loan at the TOKEN2049 conference in Singapore, allowing eligible users to collateralize wrapped Bitcoin cbBTC or wBTC in the Ledger Wallet to borrow stablecoins USDC or USDT, without needing to transfer funds to a centralized lending platform or sell their holdings. Users can open and manage loans directly within the wallet, track loan-to-value ratios, add collateral, make repayments, or increase borrowing, with key operations requiring physical confirmation on the Ledger signing device before execution.This feature is supported by the decentralized credit network Morpho, with technology provided by Yield.xyz, which is also the supplier of Coinbase's Bitcoin collateralized loans. Ledger also announced that its signing devices can directly connect to Morpho without the need for a browser plugin or software wallet. Morpho co-founder Paul Frambot stated that this integration creates a "powerful liquidity flywheel," where stablecoins deposited through Ledger's existing Earn products can fund current loans for Bitcoin holders.This move pushes Ledger, known for its hardware wallets, further into the financial services sector. Coinbase recently launched fixed-rate Bitcoin collateralized loans after expanding to UK users, and JPMorgan is also exploring Bitcoin and Ethereum collateralized lending. Ledger claims to have protected nearly 30% of the Bitcoin held by retail investors. Crypto Loan has begun to gradually open to eligible users, with availability expanding over time.
app_icon
ChainCatcher Building the Web3 world with innovations.