Cold wallets compromised by distributors, resulting in the theft of over $86 million. Users of cold wallets should check immediately.

Ledger's supply chain attack was more severe in both scale and directness.

The Ledger cold wallet supply chain attack is still unfolding. All users of hardware wallets are urged to read this and share it with their friends who hold Ledger wallets.

This wasn't a breach of the Ledger firmware or core system, but rather a supply chain attack limited to specific distributor channels in Southeast Asia. The attackers stole the mnemonic phrase through hardware tampering before the devices even reached the users.

7Txnq5xFFlrrtOfGypC4o8aEcHbpd4CUbprIsX1a.jpeg

Event Timeline

On October 9th, numerous users on X and Reddit reported their wallets being stolen. Tracing the source, the funds originated from hundreds of victim wallets across three blockchains: Bitcoin, Ethereum, and Tron. Initial estimates put the losses at over $86 million, with a potential maximum of $90 million.

On the same day, Ledger's official customer service responded quickly, confirming that an investigation was underway and pointing the finger at its Southeast Asian distributor, CryptoBilis. As a precaution, Ledger requested CryptoBilis to suspend the sale and shipment of all Ledger devices.

That evening, Changpeng Zhao (CZ) publicly addressed the issue, characterizing the incident as a "supply chain attack limited to a single supplier" and reminding users who recently purchased Ledger devices to remain vigilant.

On October 10, SlowMist security team CISO 23pds and former Mt.Gox CEO Mark Karpelès further disclosed details of the hardware-level attack, explaining how the mnemonic phrase was stolen.

Attack methods: hardware implantation, bypass screen recording

According to analysis by the SlowMist security team and hardware security researchers, this attack represents a high level of PCB-level physical tampering.

Malicious module implantation

The attackers implanted a miniature spy module inside the Ledger device, hidden in the original screen cushioning area. The outer packaging's heat-shrink film was intact, making it difficult for the user to immediately detect after opening it.

Bypass monitoring screen

This module includes LTE communication components, an antenna, an eSIM card, and a microcontroller. It passively listens to and records all characters displayed on the screen by connecting to the SPI data bus of the device screen.

Stealing mnemonic phrases and disseminating them

When the user initializes the device and the screen displays the 24 newly generated mnemonic words, the malicious module records them completely. Then, it sends the mnemonic words directly to the attacker via the built-in LTE/eSIM module.

theft of assets

Once an attacker obtains the mnemonic phrase, they can rebuild the wallet anywhere, monitor addresses, and transfer assets at opportune moments. This attack method bypasses Ledger's Security Element (SE), because the SE only protects the private key from direct reading but cannot prevent screen data from being eavesdropped on externally.

Simply put: the mnemonic phrase on your screen was seen and transmitted by an "insider" inside the device.

Official response: This only applies to purchases through CryptoBilis; purchases from the official website are unaffected.

Ledger's response focused on controlling channel risks and explicitly distancing itself from its own system.

Official statement: This incident is limited to devices purchased through CryptoBilis. Products purchased directly from the Ledger website, as well as Ledger's own infrastructure, systems, and services, were unaffected.

Urgent advice: Users who purchased devices from CryptoBilis within the past 90 days should not perform initial setup. If setup has already been completed, assets should be immediately transferred to a new Ledger device using the new mnemonic phrase.

Channel control: In addition to suspending the sale of CryptoBilis, the distributor also voluntarily suspended the sale of all hardware wallets in Malaysia, the Philippines and Indonesia, and cooperated with independent experts to review internal processes.

If you or a friend have recently purchased Ledger, please check immediately.

recall purchase channels

Have you purchased any Ledger devices from CryptoBilis or its affiliates in the past 90 days?

Uninitialized: Never initialize.

If the device is still unopened or unconfigured, do not initialize it or generate a mnemonic phrase. Contact Ledger official support or a reliable source for assistance.

Initialized: Transfer assets immediately

If you have already generated a mnemonic phrase and deposited assets using this device, please create a new wallet immediately, use a completely new mnemonic phrase, and transfer your assets to the new device. Do not continue to use the old device, which may have been tampered with.

Do not attempt to "reset" and continue using it.

The hardware may have been physically tampered with, and resetting cannot guarantee security. The safest approach is to replace the device, and the new device must come from an official or absolutely trustworthy source.

Never type your mnemonic phrase into any electronic device.

Do not take photos, do not save to cloud storage, and do not enter into your phone or computer. The mnemonic phrase is the asset itself.

This is not the first time Ledger has had an incident this year.

This is another major security incident that occurred with Ledger in 2026.

Previously: In April, a fake Ledger Live app on the App Store caused more than 50 users to lose approximately $9.5 million; in August, Ledger disclosed a vulnerability related to Ethereum application signatures, but stated that there was no evidence of actual exploitation.

In comparison, this supply chain attack is more severe in both scale and directness.

Source:Global Cybersecurity Alliance (GCSA)
Website:www.gcsa.org