Headlines

Ledger Confirms Hidden Hardware Implant in Affected User’s Wallet


Key Takeaways

Ledger Confirms Physical Tampering as Crypto Wallet Investigation Widens

On Saturday, Oct. 10, Ledger confirmed that an affected customer’s device contained an unauthorized hardware implant, a discovery that lends considerable weight to suspicions surrounding the recent wallet-draining episode linked to Southeast Asian reseller CryptoBilis. The confirmation follows estimates of losses reaching $93.4 million, although Ledger has not independently verified those figures.

The company also maintains that its security infrastructure remains intact, leaving investigators with a rather peculiar problem: a potentially compromised device that could still appear genuine. Ledger’s Saturday statement marked the first company confirmation of physical tampering involving an affected customer’s hardware wallet. The manufacturer announced that “one of the impacted users’ devices contained an unauthorized hardware implant,” giving investigators their strongest evidence yet that malicious hardware entered the picture.

In the X post, the company’s support account explained that it was “reaching out to impacted users as part of the ongoing investigation,” while encouraging anyone possessing relevant information to contact its bounty program. CryptoBilis has also taken action, with Ledger reporting that the reseller “has ceased sales of all hardware wallet inventory until the investigation is concluded.”

The confirmation follows Friday’s reports of drained wallets across Southeast Asia, where investigators traced suspicious transactions involving bitcoin, ether, and stablecoins. Independent estimates have ranged considerably, with Yfarmx placing suspected losses at $93.4 million across 471 addresses and Bitquery estimating approximately $92.9 million across 311 unique addresses.

Hidden Hardware Raises Questions About Wallet Security

The discovery also lends credibility to independent findings published by former Mt Gox CEO Mark Karpelès, who documented a modified Ledger Nano X containing a concealed circuit board, cellular communications equipment, and components allegedly capable of intercepting recovery phrases.

The alleged trick was particularly clever. Rather than attacking the wallet’s secure element, the equipment reportedly monitored information traveling to the device’s display during setup, potentially capturing recovery words before transmitting them through a cellular connection.

That approach could allow an otherwise authentic device to pass conventional verification checks while secretly exposing its owner’s recovery phrase. However, investigators have not established that every affected wallet contained comparable equipment.

The hardware wallet manufacturer Ledger sought to draw a distinction between tampered hardware and its underlying security systems, stating, “We have no indication that Ledger’s security infrastructure, systems or services have been compromised.”

X screenshot.
Several accounts on X took issue with Ledger’s explanation of the situation.

Ledger’s X post drew a great deal of criticism, and some were less than pleased with Ledger’s handling of the situation. The X post features several accounts asking, “Are you gonna refund the victims?” Others said they believe Ledger is responsible for its outsourcing. “Isn’t this your responsibility since they were official authorized reseller from you? You bear that responsibility to compensate victims,” another individual wrote on Ledger’s X thread.

Ledger Issues Fresh Warning to CryptoBilis Customers

With the investigation gathering steam, Ledger reiterated its advice to customers who purchased devices through the reseller. The company recommended that affected purchasers “not initiate set up if they have not yet done so.”

X screenshot.
A great deal of X accounts asked Ledger if the losses would be compensated.

For customers who have already initialized their wallets, Ledger advised them to “consider moving assets to a new Ledger signer (with a new seed).” The distinction matters because a recovery phrase captured during setup can potentially expose assets long after the compromised hardware has been disconnected.

Ledger also confirmed that it was “working on further, enhanced anti-tampering solutions,” suggesting that physical modifications capable of evading existing checks have become an immediate security concern.

The company thanked SEAL 911 for assisting investigators and said it was cooperating with authorities. Meanwhile, Ledger warned customers that “Ledger will never ask for your 24-word recovery phrase.”

For all the developments, the biggest questions remain unanswered. One compromised device is now confirmed, but the number of additional implants, their connection to the reported losses, and the identity of those responsible remain unresolved. A device built to keep secrets apparently had a second set of ears, and investigators are still determining how many others might have been listening.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *