Skip to content
Security & HacksLatest

Ledger Probes Wallet Tampering Linked to Multi-Million Crypto Heists

MissedBlock Desk · · 3 min read

Updated

Ledger Probes Wallet Tampering Linked to Multi-Million Crypto Heists

Ledger Investigates Southeast Asia Fund Losses Linked to Reseller

Ledger has launched an investigation into a series of reported fund losses experienced by customers in Southeast Asia. The common factor identified so far is devices purchased through CryptoBilis, an authorized Ledger reseller operating in Indonesia, Malaysia, and the Philippines.

The probe was announced by Ledger on October 9, 2026, with the company also instructing CryptoBilis to immediately cease all sales and shipments.

Ledger’s guidance for affected buyers varies depending on whether the device has been opened. Customers who purchased from the reseller within the last 90 days and have not yet set up their device are advised to leave it uninitialized. Those who have already set up a wallet are strongly encouraged to transfer their assets to a new Ledger device, ensuring that this new device generates a completely fresh seed phrase.

The company has emphasized that its own infrastructure and devices sold directly by Ledger remain secure and have not been compromised.

Tampering Allegations Surface Online

The theory of hardware tampering gained traction on social media platforms, with photos and videos shared on X and Threads appearing to show a small circuit board concealed beneath the device’s screen. According to these posts, the alleged implant is capable of capturing everything displayed on the screen, including the recovery phrase during the initial setup process – a critical vulnerability window.

Reports suggest the circuit board includes an embedded SIM card, which could be used to transmit captured data via a cellular connection directly to an attacker, enabling them to drain the victim’s wallet.

Mark Karpelès, the former CEO of Mt. Gox, has examined some of the suspect devices and called for a more thorough investigation.

As of October 10, 2026, no definitive link has been confirmed between the alleged hardware tampering and CryptoBilis. The investigation is ongoing.

Estimated Losses and Asset Freezes

On-chain analysts, rather than Ledger, have provided estimates of the financial losses. Analytics firms Specter and tanuki42 identified a pattern of inflows to addresses suspected of theft across multiple blockchains, with estimated losses ranging from $72 million to $93 million. Arkham Intelligence, at one point, tracked approximately $87 million across various wallets, reportedly holding significant amounts of Ethereum (ETH), Bitcoin (BTC), and Tether (USDT). Ledger has not officially confirmed these figures.

In response to the allegations, Tether has frozen roughly $10 million in USDT associated with some of the suspected theft addresses.

CryptoBilis has reportedly been linked to a recent change in ownership involving an individual from China, though no wrongdoing has been established in connection with this ownership change.

Next Steps for Affected Customers

For individuals who purchased a Ledger device through CryptoBilis, the recommended course of action is clear: follow Ledger’s guidance, transfer funds to a new device with a new seed phrase, and do not delay while the investigation proceeds.

Key developments to monitor include confirmation from investigators of a physical link between the implants and CryptoBilis, whether Ledger releases its own official loss figures, and if other stablecoin issuers follow Tether’s lead in freezing linked funds.

Ledger Probes Wallet Tampering Linked to Multi-Million Crypto Heists · MissedBlock