A hardware wallet is supposed to be the vault you buy so you never have to trust anyone else. That premise just took a serious hit.
Attackers reportedly planted hidden hardware inside Ledger wallets sold through an authorized Southeast Asian reseller, CryptoBilis. Estimated losses range from $72 million to upwards of $93 million, spread across hundreds of wallets.
Ledger confirmed on October 10, 2026, that at least one affected device contained an unauthorized hardware implant. The company has told CryptoBilis to stop all sales and shipments of its devices.
How the attack allegedly worked
The implants are described as small circuit boards with cellular capabilities, tucked behind the device screens. Their job was to capture a user’s 24-word recovery phrase and send it out over cellular networks.
Advertisement
The recovery phrase is the master key to a crypto wallet. Anyone holding those 24 words can rebuild the wallet on another device and move the funds, no physical access required.
A post on X claimed the attackers went further than tampering with stock. According to that post, the hackers bought a reseller outright, had it sign a non-disclosure agreement, and stole over $80 million by slipping spy chips into the wallets. That account of the reseller purchase and the NDA has not been confirmed by Ledger.
The money trail
The unusual draining began around October 9, 2026. Researchers spotted significant inflows to theft addresses across several blockchains, including Bitcoin, Ethereum, and Tether’s USDT stablecoin.
Most of the losses were recorded between October 9 and October 10. Some of the stolen funds were reportedly routed through mixers such as Tornado Cash.
Tether has reportedly frozen approximately $10 million in USDT linked to the theft addresses.
Multiple generations of implants
Researcher Mark Karpelès documented the hardware involved. His findings point to several generations of the implants in devices bought in Southeast Asia. According to Karpelès’ documentation, the implants were built to quietly monitor and extract sensitive data without tripping Ledger’s security protocols.
Background: why resellers matter
CryptoBilis serves customers in Malaysia, Indonesia, and the Philippines. Ledger’s position is that the problem is confined to the reseller channel. The company says there is no evidence that its core systems or products sold directly were affected.
What this means
Anyone who bought a Ledger through CryptoBilis faces an uncomfortable question. If an implant captured the recovery phrase, the device itself cannot be trusted, and neither can any wallet created from that phrase. Moving funds to a wallet generated on a verified device with a fresh phrase is the logical response for anyone exposed.
Watch for three things next. First, whether Ledger or independent researchers confirm how many devices carried implants. Second, whether more of the stolen funds get frozen or traced as they exit mixers. Third, whether the claim that attackers acquired the reseller itself holds up, because that would turn a story about tampered inventory into one about a hostile takeover of a trusted sales channel.
Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
