{"id":24279,"date":"2026-10-11T16:50:00","date_gmt":"2026-10-11T16:50:00","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/10\/11\/ledger-confirms-hidden-chip-in-crypto-wallet-amid-92m\/"},"modified":"2026-10-11T16:50:00","modified_gmt":"2026-10-11T16:50:00","slug":"ledger-confirms-hidden-chip-in-crypto-wallet-amid-92m","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/10\/11\/ledger-confirms-hidden-chip-in-crypto-wallet-amid-92m\/","title":{"rendered":"Ledger confirms hidden chip in crypto wallet amid $92M&#8230;"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/media.crypto.news\/2023\/10\/crypto-news-Everscale-announced-theft-of-tokens01.webp\" \/><\/p>\n<div>\n<p class=\"is-style-lead\">Ledger has confirmed finding an unauthorized hardware implant inside one customer\u2019s cryptocurrency wallet during its October 10 investigation into reported thefts involving Southeast Asian reseller CryptoBilis, as blockchain researchers estimate suspected losses exceeding $86 million.<\/p>\n<div id=\"cn-block-summary-block_842e7ecda305490b2fa2fbaf15001276\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Ledger confirmed an unauthorized hardware implant inside one affected customer\u2019s device during its CryptoBilis investigation.<\/li>\n<li>CryptoBilis suspended sales of all hardware wallets while Ledger investigates reported losses involving Asian customers.<\/li>\n<li>Ledger advised customers with CryptoBilis devices against setup and recommended fresh recovery phrases for others.<\/li>\n<li>Researcher Mark Karpel\u00e8s reported finding suspicious electronics behind a Ledger Nano X screen in Malaysia.<\/li>\n<li>Bitquery estimated $92.9 million in cryptocurrency losses across 311 wallets, figures unconfirmed independently by Ledger.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>Ledger Support <a href=\"https:\/\/x.com\/Ledger_Support\/status\/2108968264055345381\" target=\"_blank\">confirmed<\/a> the discovery in an official statement, saying the modified device belonged to a user affected by the ongoing investigation. The company said CryptoBilis had stopped selling all hardware wallets as a precaution and that Ledger was contacting affected customers while working with authorities. It has not established whether the implant caused the reported cryptocurrency losses.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Situation Update: Ledger can confirm that one of the impacted users\u2019 devices contained an unauthorized hardware implant. Ledger is reaching out to impacted users as part of the ongoing investigation. If you have information regarding the investigation, please reach out to\u2026<\/p>\n<p>\u2014 Ledger Support (@Ledger_Support) <a href=\"https:\/\/x.com\/Ledger_Support\/status\/2108968264055345381?ref_src=twsrc%5Etfw\">October 10, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The discovery provides direct confirmation of physical tampering in at least one device, following earlier warnings about suspicious wallets distributed through the reseller.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>Ledger confirms unauthorized implant in customer\u2019s wallet<\/strong><\/h2>\n<p>During its investigation, Ledger identified an additional electronic component inside a wallet belonging to an affected customer.<\/p>\n<p>The company described the component as an \u201cunauthorized hardware implant\u201d but did not disclose the exact device model, how the component was installed or whether it had transmitted any information.<\/p>\n<p>According to Ledger\u2019s October 10 statement, its security team is examining the incident and contacting customers believed to have been affected. The manufacturer has not confirmed how many wallets contain similar modifications.<\/p>\n<p>Reports of unauthorized transactions emerged on October 9 among customers who purchased Ledger products through CryptoBilis, a reseller operating in Indonesia, Malaysia and the Philippines. Following the complaints, Ledger opened an investigation into the reported losses and asked the distributor to suspend sales and shipments of its devices.<\/p>\n<p>A subsequent <a href=\"https:\/\/www.theblock.co\/news\/business\/2026-10-09-ledger-cryptobilis-fund-losses-418163\" target=\"_blank\">report<\/a> from The Block said on-chain investigators had initially identified suspected thefts exceeding $72 million, while another estimate placed the losses above $86 million.<\/p>\n<p>Ledger has not confirmed either amount. The company emphasized in its latest statement that it has found no evidence suggesting its internal security infrastructure, systems or services were compromised.<\/p>\n<p>\u201cWe have no indication that Ledger\u2019s security infrastructure, systems or services have been compromised,\u201d the company stated.<\/p>\n<p>The manufacturer is developing additional protections against physical device tampering while investigators work to determine how the unauthorized component entered the affected wallet.<\/p>\n<h2 class=\"wp-block-heading\"><strong>CryptoBilis halts all hardware wallet sales during investigation<\/strong><\/h2>\n<p>Following Ledger\u2019s discovery, CryptoBilis confirmed that it had suspended sales of its entire hardware wallet inventory.<\/p>\n<p>The temporary halt covers all hardware wallet products sold by the distributor, extending beyond the earlier request to pause Ledger sales and shipments.<\/p>\n<p>According to an October 10 <a href=\"https:\/\/www.tokenpost.com\/news\/technology\/29648\" target=\"_blank\">report<\/a> from TokenPost, CryptoBilis will maintain the suspension until the investigation concludes.<\/p>\n<p>Ledger said it remained in active communication with the reseller regarding the investigation and appropriate next steps. Customers who purchased a device through CryptoBilis have been instructed not to begin setting it up if they have not already done so.<\/p>\n<p>For customers who have used the devices, Ledger recommends considering a transfer of their cryptocurrency to a new hardware wallet initialized with a completely new recovery phrase. Moving an existing recovery phrase onto a replacement device would not address possible exposure of that phrase through the original hardware.<\/p>\n<p>The company further requested information from anyone with relevant evidence and directed security researchers to its bounty program at <a href=\"http:\/\/crypto.news\/cdn-cgi\/l\/email-protection#1775786279636e577b7273707265397165\"><span class=\"__cf_email__\" data-cfemail=\"accec3d9c2d8d5ecc0c9c8cbc9de82cade\">[email\u00a0protected]<\/span><\/a>. Ledger has contacted law enforcement and acknowledged assistance from the Security Alliance\u2019s SEAL_911 incident response initiative.<\/p>\n<p>The company\u2019s statement did not identify any suspects, announce arrests or provide a timetable for completing the investigation. Separately, former CryptoBilis executives Arravind Prabu and Vimalatheethan stated that they had transferred operational control of the business following an ownership change earlier in 2026.<\/p>\n<p>In a statement shared with researcher Mark Karpel\u00e8s and published by Tibane Labs, the former executives said they completed their management handover in March and no longer controlled company systems or customer databases.<\/p>\n<p>Their statement does not establish who modified the affected device or whether the ownership change had any connection to the incident.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Security researcher reports hidden electronics behind Ledger screen<\/strong><\/h2>\n<p>Before Ledger publicly confirmed the hardware implant, former Mt. Gox CEO Mark Karpel\u00e8s reported examining a suspicious Ledger Nano X device obtained from Malaysia. On October 9, Karpel\u00e8s described finding an additional electronic component hidden behind the device\u2019s display, inside material normally used to protect the screen.<\/p>\n<p>He reported that the wallet had arrived in packaging that appeared intact, raising questions about whether customers could identify a modified device through a routine visual inspection. In photographs shared publicly, the component appeared to contain electronic circuitry separate from the wallet\u2019s original hardware.<\/p>\n<p>Karpel\u00e8s subsequently reported examining the modification further and inspecting images provided by other affected users.<\/p>\n<p>A technical account <a href=\"https:\/\/www.tibane.net\/research\/ledger-nano-x-implant\" target=\"_blank\">published<\/a> by Tibane Labs described an arrangement involving a microcontroller, cellular communication hardware and connections to the screen\u2019s internal data lines. The analysis suggested that a component positioned along the screen connection could potentially capture information displayed during wallet setup.<\/p>\n<p>A recovery phrase typically consists of 24 words that allow a wallet owner to restore access to cryptocurrency holdings. If an attacker obtains those words, the attacker may be able to recreate the wallet and authorize transfers without possessing the original hardware device.<\/p>\n<p>Researchers have suggested that an implant capable of reading information sent to the display could potentially capture recovery words when a wallet is initialized.<\/p>\n<p>However, Ledger has not independently confirmed that the discovered implant performed that function or that it was responsible for the reported thefts.<\/p>\n<p>The company\u2019s official announcement confirms physical tampering in one affected device without establishing the technical method used to access customer funds. Ledger\u2019s historical security research has previously examined situations involving unauthorized modifications to wallet hardware.<\/p>\n<p>In a 2018 security <a href=\"https:\/\/www.ledger.com\/chaos-communication-congress-in-response-to-wallet-fails-presentation\" target=\"_blank\">response<\/a>, the manufacturer discussed how attackers with physical access could modify a wallet and use additional electronics to interfere with its operation. The earlier research concerned different attack scenarios and did not establish a connection to the CryptoBilis investigation.<\/p>\n<h2 class=\"wp-block-heading\"><strong>On-chain researchers estimate millions in suspected thefts<\/strong><\/h2>\n<p>As investigators examine the affected hardware, blockchain analytics researchers have attempted to calculate the value of cryptocurrency moved from suspected victim wallets.<\/p>\n<p>In an October 9 investigation, Bitquery <a href=\"https:\/\/www.bitquery.io\/investigations\/ledger-cryptobilis-hack\" target=\"_blank\">estimated<\/a> that approximately $92.9 million had been removed from 311 wallets across Bitcoin, Ethereum, TRON, BNB Chain and Polygon.<\/p>\n<p>The estimate exceeded earlier reports of suspected losses ranging from $72 million to more than $86 million. Bitquery attributed the difference to additional wallets and blockchain networks included in its analysis. Its researchers reported that the largest portion of the suspected losses involved USDT transactions on TRON, followed by Bitcoin and Ethereum transfers.<\/p>\n<p>The report identified approximately $70.5 million in assets transferred from TRON wallets and $16.8 million in Bitcoin. Using transaction timing and address relationships, Bitquery argued that the activity was consistent with an attacker already possessing control over multiple wallets.<\/p>\n<p>The research company identified closely timed transactions across several networks and examined where the transferred assets subsequently moved. Bitquery reported that approximately $10 million in USDT had been frozen in addresses linked to the suspected thefts.<\/p>\n<p>It further identified transactions involving cryptocurrency swaps and transfers to Tornado Cash, a service used to obscure the transaction history of digital assets. The analysis remains an independent assessment. Ledger has not confirmed Bitquery\u2019s estimated losses, number of victims or conclusions about the attacker.<\/p>\n<p>More recent <a href=\"https:\/\/publicaml.org\/ledger-cryptobilis-hack\/\" target=\"_blank\">on-chain reporting<\/a> from PublicAML described additional movements involving suspected stolen Ether on October 10, including transfers to Tornado Cash. The analysis estimated that 900 ETH reached Tornado Cash during another series of transfers, although the researchers\u2019 wallet attribution and loss calculations remain separate from Ledger\u2019s confirmed findings.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Ledger urges users to protect recovery phrases<\/strong><\/h2>\n<p>Ledger\u2019s investigation has prompted warnings about the possibility of criminals exploiting public concern surrounding the reseller incident. The company cautioned customers to rely on official communication channels for information about affected devices, investigations and potential security measures. Its public statement reminded customers that Ledger support personnel will never request their 24-word recovery phrase.<\/p>\n<p>Earlier <a href=\"https:\/\/crypto.news\/ledger-faces-fake-website-warning-amid-86m-theft-probe\/\" target=\"_blank\">research into fraudulent Ledger websites<\/a> documented phishing pages that attempted to obtain recovery phrases through fake wallet verification requests.<\/p>\n<p>The report, published October 11, discussed malicious Google advertisements that directed users toward imitation Ledger websites and applications. The phishing campaign has not been linked to the CryptoBilis hardware investigation. In its latest notice, Ledger said it was preparing additional measures intended to make unauthorized physical modifications harder to carry out.<\/p>\n<p>The company did not announce a release date for those protections or provide details of any hardware redesign. For customers seeking guidance, Ledger directed inquiries to its official support website at <a href=\"https:\/\/support.ledger.com\/\" target=\"_blank\">support.ledger.com<\/a>.<\/p>\n<p>Its security team said affected users would continue receiving direct communication as the investigation proceeds, while information about the incident can be submitted through its bounty program.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/ledger-confirms-hidden-chip-in-crypto-wallet-amid-92m\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ledger has confirmed finding an unauthorized hardware implant inside one customer\u2019s cryptocurrency wallet during its October 10 investigation into reported thefts involving Southeast Asian reseller CryptoBilis, as blockchain researchers estimate suspected losses exceeding $86 million. Summary Ledger confirmed an unauthorized hardware implant inside one affected customer\u2019s device during its CryptoBilis investigation. CryptoBilis suspended sales of [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":24280,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-24279","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/24279","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=24279"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/24279\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/24280"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=24279"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=24279"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=24279"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=24279"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}