Newsroom
11 October, 2026 / News / AI / Tags: cryptobilis, ledger, implant, reseller, hardware

French hardware wallet maker verifies unauthorized component in a device sold by its Southeast Asian reseller amid reports of widespread fund drains
Ledger has confirmed the presence of an unauthorized hardware implant inside at least one device purchased from CryptoBilis, an official reseller operating in Indonesia, Malaysia and the Philippines. The finding marks the first public acknowledgment of physical tampering in a series of incidents that independent researchers have linked to losses ranging from more than $86 million to roughly $93 million.
On 10 October, Ledger stated that one of the impacted users’ devices contained an unauthorized hardware implant. A day earlier the company had begun investigating reports of missing funds from customers in Southeast Asia who obtained their wallets through the reseller. Ledger emphasized that it has no indication its own security infrastructure, systems or services have been compromised.
Ledger has been communicating updates through its support account on X. The company said it is contacting affected users, cooperating with authorities, developing further anti-tampering measures and inviting anyone with relevant information to use its bounty program. It also thanked the volunteer group SEAL 911 for assistance in the probe.
On 9 October Ledger asked CryptoBilis to halt all sales and shipments. According to the company, the reseller has since stopped selling its entire hardware wallet inventory pending the outcome of the investigation. No public statement from CryptoBilis has been reported.
The most detailed public analysis so far comes from Mark Karpelès, the former chief executive of Mt. Gox, who examined suspect devices. His findings describe a modified Ledger Nano X containing a hidden circuit board equipped with cellular communication hardware. The implant monitored data sent to the device’s screen during the initial setup process, when the 24-word recovery phrase is displayed, and was capable of transmitting those words over a cellular connection. The component did not target the secure element that stores private keys.
Several details remain unresolved. Ledger has not identified the specific model of the confirmed compromised device. Investigators have not established whether every affected wallet carried identical hardware or how many tampered units were distributed.
Ledger itself has not released a loss figure. Independent on-chain analyses have produced the following estimates:
The degree of overlap among these tallies is unclear, as is the precise number of victims. Specter initially referred to hundreds of affected wallets but later stated that a final count was not yet available. Crypto Briefing reported that Tether froze roughly $10 million in USDT connected to some of the suspected addresses.
Ledger has issued specific guidance for people who bought devices from CryptoBilis. Those who acquired a wallet in the past 90 days and have not yet set it up are advised not to begin the setup process. Customers who have already completed setup are encouraged to move assets to a new Ledger device using a fresh recovery phrase. The company reiterated that it will never request a user’s 24-word recovery phrase and that such information should never be entered into any website or application. Affected individuals are directed to contact Ledger’s bounty program or SEAL 911.
Separately, security researcher Cyber Scrilla identified a fraudulent Ledger website and application that ranked near the top of Google search results and was designed to harvest recovery phrases. That phishing operation has not been linked to the CryptoBilis incidents.
Zhao added that he expects participants in the BNB ecosystem and the broader industry to assist in tracing and recovering funds.
Ledger, founded in 2014 and headquartered in Paris, reports having sold more than seven million devices worldwide. The company has not announced any compensation plan for affected customers, although some users have called for restitution on the grounds that CryptoBilis was an authorized reseller. It also remains unknown who installed the implants or the total number of compromised devices that entered circulation. Ledger stated it will continue to provide updates as the investigation advances.









