Key Takeaways
- Ledger users say funds were drained from their wallets, prompting a respond from the hardware wallet maker.
- The company said it is investigating reports tied to wallets purchased from a particular Southeast Asian reseller.
- An onchain investigator pegged the total known losses above $86 million across chains as of Friday morning.
Social media lit up with posts from Ledger users claiming that funds had been drained from their wallets, despite saying they’d protected their wallet and seed phrase and had not signed any transactions enabling the movement of funds.
“My Ledger wallet just got drained out of almost 100k USDT,” one purported user wrote on Reddit. “Seed phrase [was] handwritten and kept in a safe. Never touch my Ledger Stax. The Ledger wallet was used as a place to keep funds, and I dont interact with anything other than receiving funds.”
Early Friday, Ledger posted a statement to its official support account on X acknowledging the reported losses, and suggesting the attack could be localized to devices sold by a particular reseller.
“Ledger is investigating reports of loss of funds from users in Southeast Asia who purchased products from a reseller named CryptoBillis,” the company wrote. “As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices.”
Purported Ledger-Linked Losses Pile Up
Onchain investigators pointed to funds leaving wallets across Bitcoin, Ethereum, Tron, and other blockchains. Data compiled by an investigator known as Specter showed over $42 million in ETH, $17.5 million in BTC, and $16.5 million worth of USDT leading the losses across wallets, with total losses sitting above $86 million as of Friday morning.
Ledger cautioned users against activating wallets purchased from that particular reseller, and advised users who own wallets purchased from that company to move their funds elsewhere.
“We recommend Ledger users who purchased from this reseller in the last 90 days to not initiate setup if you have not done so yet,” the firm said. “If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed). We will continue to inform customers of updates as the investigation progresses.”
The reports fueled further panic across social media, though some industry experts warned that there is currently no evidence of a broader vulnerability across Ledger devices.
“Based on information so far, it seems to be localized to a supply chain attack with one vendor. A small number of people probably bought fake (or tampered) Ledgers,” said Binance co-founder and former CEO Changpeng Zhao, on X. “Ledger is one of the most secure and oldest hardware wallets in the industry. Stood the test of time. But these things happen.”
