Ledger × CryptoBilis Incident: What Happened?

On October 9, 2026, several on-chain analytics accounts simultaneously discovered that a large number of wallets had been emptied within a short period of time. The common thread among the victims was that they had all purchased hardware wallets from CryptoBilis, a Ledger distributor in Southeast Asia. On the same day, Ledger’s official support account issued a statement indicating that it was investigating the financial losses suffered by the affected users and had requested that CryptoBilis suspend all sales and shipments of Ledger devices.

On October 10, Ledger provided an update on the investigation, confirming that one of the affected users' devices contained an "unauthorized hardware implant."

The key points of the incident can be summarized in three sentences:

  • Ledger stated that there are no indications that its security infrastructure, systems, or services have been compromised.
  • All users currently affected purchased their devices from CryptoBilis.
  • Ledger has confirmed that at least one affected device had hardware installed on it, but has not confirmed that the implant was the direct cause of the funds being stolen; the investigation is still ongoing.
Investigation Statement Issued by Ledger Support on October 9, 2026
First Official Announcement from Ledger: Investigating Financial Losses Suffered by Users Who Purchased Devices from CryptoBilis, and Requiring the Reseller to Suspend Sales and Shipments | Image Source:x.com

How big is the loss?

All of the following figures are based on third-party on-chain tracking; Ledger has not officially confirmed the total amount of losses or the number of people affected.

According to statistics from the on-chain data firm Bitquery, approximately $93.2 million was transferred out of 315 wallets, involving six blockchains: TRON, Bitcoin, Ethereum, Solana, BNB Chain, and Polygon:

鏈Number of Affected WalletsAmount Transferred (approx.)
TRON131$70.5 million (primarily in USDT)
Bitcoin122$16.8 million (approximately 203.8 BTC)
Ethereum33$3.7 million
BNB Chain27$1.45 million
Polygon13$580,000
Solana4$250,000

Source:Bitquery On-Chain Investigation Report, Data as of October 10, 2026, at 07:00 (UTC).

The survey also revealed several noteworthy characteristics:

  • About two weeks before the theft, the attacker made several small test transfers on TRON and Ethereum.
  • Twenty-five TRON wallets signed the same authorization within three seconds, indicating that it is highly likely a single attacker has obtained the private keys for all of them.
  • Tether has frozen approximately $10 million in USDT.
  • For about 60 percent of the affected wallets, the first time they received funds fell within the 90-day window recommended by Ledger; more than 80 percent did not begin receiving funds until June 2026 or later.

One of the most frequently cited examples: A user bought a device a week ago, and all 80 BTC were transferred out.

One of the affected addresses purchased 80 BTC about four months ago at approximately $65,000 per coin. About a week ago, the holder purchased a Ledger from CryptoBilis and deposited all 80 BTC into it; eventually, the entire amount was transferred out on October 9.

Arkham shows records of 80 BTC being transferred in and out
That address received 80 BTC about a week ago, all of which was transferred on October 9 to an address labeled “Ledger Drainer” | Image source:arkm.com

What Should You Do? Steps for Affected Users

If you purchased a Ledger from CryptoBilis within the past 90 days, please follow the official recommendations from Ledger:

  1. Devices that have not yet been set up: Do not power them on or configure them yet. Keep the packaging and proof of purchase, and watch for further announcements from Ledger.
  2. Already-Set-Up Devices: Purchase a brand-new Ledger device (we recommend buying it directly from Ledger Official Website (Purchase), then regenerate a completely new set of mnemonic phrases.
  3. Transferring Assets: Move your assets from your old wallet to the address of your new wallet. Never import your old 24-word mnemonic phrase into a new device, as this would be equivalent to continuing to use a private key that may have already been compromised.
  4. Start with a small test: Transfer a small amount first to confirm that the new address is correct, then transfer the rest of your assets.
  5. Beware of fake customer service representatives: Ledger will never ask you for your 24-word recovery phrase. Any private message, email, or phone call asking you to provide your recovery phrase is a scam.

If you have any information regarding the incident, Ledger says you can contact its reward program (bounty@ledger.fr).

Even if you didn’t purchase your device from CryptoBilis, we recommend checking where you bought it: If the device came from a secondhand marketplace, a reseller, or an online store where the price was significantly lower than the official retail price, you may want to consider following the steps above to exchange it.

Ledger Support confirmed on October 10, 2026, that it had discovered an unauthorized hardware implant
Ledger confirmed that an affected user’s device contained an unauthorized hardware implant and reiterated that users who have set up their devices should transfer their assets to a new device using a brand-new mnemonic phrase | Image source:x.com

Is Ledger Still Secure? Is the Problem with the Brand or the Distribution Channel?

Whenever there’s an issue with a hardware wallet, there are always people who say, “I told you not to use Ledger.” But based on the information currently available, the problem with this incident lies not with the brand itself, but with the supply chain before the devices reach users.

Where are the implants hidden?

On October 9, former Mt. Gox CEO Mark Karpelès revealed a Ledger device in his possession that had been “implanted with a spy device.” He stated that the device was shipped from Malaysia with the plastic wrap intact, and even after opening the case, the implant was not immediately visible because it was hidden in the space where the screen cushion would normally be.

It is important to note that Karpelès stated his samples did not necessarily come from CryptoBilis, and that his technical description of the implant is his personal interpretation—not an attack method officially confirmed by Ledger.

A Ledger package received by Mark Karpelès, shipped from Malaysia
The packaging and plastic wrap appear normal; it is impossible to tell from the outside alone whether the device has been tampered with | Image source:x.com
The Ledger Nano X After Removing the Case
Karpelès pointed out that the implant is hidden in the screen cushioning, a location that ordinary users would not typically disassemble to inspect, making it very difficult to detect | Image source:x.com

Will switching to a different brand make it safe?

Not necessarily. These types of attacks target devices that have been tampered with “after leaving the factory but before reaching the user.” In theory, any brand of hardware wallet purchased through unverified channels could face the same risk. Switching brands but continuing to buy from resellers or low-cost online stores does not eliminate the risk.

Conversely, Ledger stated that there have been no reports indicating that devices purchased directly from Ledger are affected, and there are no signs that Ledger’s own systems have been compromised.

Cold Wallet Brand Security Rankings 2026: Which Brand Is Currently the Safest?

Since the problem isn’t limited to Ledger, how do other brands fare? We’ve listed the publicly reported security incidents for eight major cold wallet brands from 2020 through October 2026, ranked by severity:

  • Most serious: Product, system, or supply chain issues that result in actual financial losses for users.
  • Level 2: Customer data breaches, phishing campaigns triggered by such breaches, or counterfeit products and tampering by distributors.
  • Level 3: Vulnerabilities that have been discovered and patched by researchers, with no user losses.
  • Least significant: Policy disputes.

The fewer and less serious the negative incidents, the higher the ranking. This ranking reflects only public records as of October 11, 2026, so it is "provisional" and does not guarantee that no incidents will occur in the future.

rankingsBrandMajor Adverse Events (2020–October 2026)Loss of User FundsOpen-Source Firmware
1KeystoneThe anti-tamper circuit issue identified in the 2023 audit and the firmware vulnerability discovered in January 2024 have both been fixed.No public records foundPart
2OneKeyThe 2023 OneKey Mini vulnerability requiring a device teardown has been patched, and a bounty has been paid.No public records found是
3BitBox02Multiple vulnerabilities were proactively disclosed and patched in 2020, 2022, and 2026; in September 2026, the email service provider was exploited to send phishing emailsNo public records found是
4TangemIn December 2024, the app log recorded a private key; in July 2026, a laser-based attack could reset the password on old cards, and the old cards could not be patched.No public records foundPart
5SafePal2021 Privilege Escalation Vulnerability (Patch Applied); August 2026 Order Plugin Vulnerability Led to Data Breach Affecting 39,798 PeopleNo public records found否
6TrezorMultiple third-party service data breaches and phishing incidents from 2022 through September 2026 (including incidents involving a logistics provider and an email service provider in 2026); the 2023 "Fake Model T" caseThe product itself is not affected; however, victims of counterfeit goods and phishing scams may suffer individual losses.是
7Ledger2020 customer data breach; 2023 Recover controversy; December 2023 Connect Kit supply chain attack (approximately $600,000; official compensation promised); January 2026: Payment partner data breach; October 2026: CryptoBilis implant incident有Part
8ColdcardIn July 2026, a firmware random number generation error was identified, which made it possible to deduce some mnemonic phrases generated since 2021.Yes, estimated at approximately 1,367 BTC or morePart

Keystone is ranked number one—why is it currently the safest?

Among the eight brands, Keystone is the only one with a public record of only “vulnerabilities identified during audits and subsequently patched,” and it has never experienced a data breach or financial loss for its users. OneKey is in a similar situation, with only one vulnerability—one that could only be exploited by disassembling the device and which has long since been patched—so it ranks second.

Ledger ranks seventh and Coldcard ranks eighth—what’s the reason?

Both Ledger and Coldcard have a history of “actual losses of user funds,” which is the most serious category of incident. Coldcard’s issue stemmed from its own firmware, as confirmed by the company, and third-party estimates put the amount stolen at approximately 1,367 BTC or more, making it an even more serious incident; Ledger, meanwhile, has the confirmed 2023 Connect Kit incident, as well as the CryptoBilis incident, which is still under investigation.

Three Things to Know Before Checking the Rankings

  1. Fewer negative news stories do not necessarily mean stronger security capabilities. Keystone and OneKey have smaller user bases and receive less attention than Ledger and Trezor, so they are less likely to be the subject of research or attacks.
  2. Trezor ranked sixth, primarily due to frequent data breaches and phishing incidents involving third-party services; the product itself has no record of causing financial losses to users.
  3. No matter which brand you choose, these three factors—where you purchase it, generating your own mnemonic phrase, and storing it offline—are equally important. Even if you buy from the top-ranked brand, there’s still a risk if you purchase it from an unverified source.

How to Safely Buy a Cold Wallet? Pre- and Post-Purchase Checklist

Before Purchasing

  1. Buy only from the official website: Placing an order directly on the brand’s official website is the best way to minimize the number of intermediaries involved.
  2. Verify dealers using the official list: If you plan to purchase through a dealer, first check the brand’s official website to see if the dealer is listed on the authorized dealer page. However, please note that CryptoBilis itself is an authorized dealer, so purchasing directly from the official website remains the best option.
  3. Avoid secondhand devices, purchases through intermediaries, and low-priced online stores: You should avoid devices that are priced significantly below the official retail price, for which the seller cannot provide an official invoice, or that have been resold multiple times.

After receiving the package

  1. Inspect the packaging: Check for any signs that the packaging has been opened or resealed. However, this incident shows that even if the plastic wrap is intact, it does not necessarily mean the device has not been tampered with, so you cannot rely solely on its appearance to make a judgment.
  2. Complete the authenticity check in the official app: Ledger users can perform the official authenticity check when connecting their device to the Ledger Wallet app. This check primarily verifies the device’s security chip and may not detect any additional circuitry that has been installed; therefore, it should be considered only one line of defense.
  3. Generate Your Own Mnemonic Phrase: Genuine hardware wallets do not come with a pre-printed mnemonic phrase. If you find a pre-printed mnemonic phrase card inside the packaging, or if someone asks you to use a specific mnemonic phrase, stop using the device immediately.

Long-term storage

  1. Keep Large Amounts of Assets Separate: Don’t store all your assets on a single, newly purchased device; instead, distribute them across different wallets.
  2. Start with a small amount: After setting up a new device, deposit a small amount of money first and monitor it for a while before gradually transferring larger amounts.
  3. Rely only on official information: The most common secondary scams during this event involve fake customer service representatives and fake websites. All updates should be verified through the brand’s official accounts and website.

If you want to review the basic differences between cold wallets and hot wallets, you can refer to The Complete Guide to Cryptocurrency Wallets。

Who is CryptoBilis? An Overview of the Company's Background

CryptoBilis is an authorized reseller of Ledger in Indonesia, Malaysia, and the Philippines. Headquartered in Kuala Lumpur, it had been listed on Ledger’s official list of authorized resellers prior to the incident.

According to the company’s equity change records, CryptoBilis was acquired in March 2026, at which time the original shareholders had stepped down from all operational, managerial, and administrative roles; As of August 3, an individual with a registered address in Heilongjiang Province, China, holds 100% shares in the company. A former co-founder has also publicly confirmed that the company was acquired in March.

However, there is currently no direct evidence linking the change in ownership to the implant incident. It remains unclear at this stage whether the implants were added by the company, individual insiders, or somewhere along the upstream supply chain; therefore, CryptoBilis should not be directly regarded as the mastermind behind the incident.

On October 10, CryptoBilis confirmed that it has suspended sales of all remaining hardware wallets until the investigation is complete.

Things We Still Don't Know

As of October 11, 2026, the following questions remain to be addressed by the official investigation:

  • Who installs the implants: distributors, internal staff, or other links in the supply chain?
  • Number of affected devices: How many devices have been modified?
  • Officially Confirmed Losses: Ledger has not yet confirmed the total amount of losses or the number of people affected.
  • Funds Recovered: Tether has frozen approximately $10 million in USDT; it remains unclear whether the remaining funds can be recovered.

Ledger stated that it is cooperating with relevant law enforcement agencies and thanked the security organization SEAL 911 for assisting with the investigation. MB will continue to monitor official updates.

Frequently Asked Questions

I bought my Ledger from the official website. Do I need to replace it?

According to Ledger’s current statement, the incident only involves devices purchased from CryptoBilis; there have been no reports so far regarding devices purchased directly from Ledger’s official website. If your device was purchased from the official website and your mnemonic phrase has been properly stored offline, there is no need to replace your device at this time due to this incident, but you should stay tuned for further updates from Ledger.

I didn't buy it on CryptoBilis, but on an online shopping platform or through a proxy buyer. What should I do?

Ledger’s official recommendation applies only to CryptoBilis, but this incident highlights the risk of tampering in the supply chain. If your device was purchased from a secondhand marketplace, a reseller, or an online store offering it at a price significantly below the official price—and it contains a large amount of assets—you may want to consider purchasing a new device through official channels and transferring your assets using a brand-new seed phrase.

If the packaging film is intact and the product has passed the official authenticity check, does that mean the device is in good working order?

Not necessarily. In the case that was recently made public, the protective film on the device was intact, and the implant was hidden in a hard-to-detect location. An official authenticity check is a necessary step, but it cannot guarantee the detection of all additional hardware, so the purchase channel is the most important first line of defense.

Are Ledger's past data breaches related to this one?

In 2020, Ledger experienced a customer data breach involving approximately 1 million email addresses; in January 2026, its payment partner Global-e was also hacked, resulting in the leak of some order data. There is currently no public information indicating that these incidents are related to the CryptoBilis implant incident. However, data breaches can lead to an increase in fake customer service representatives and phishing emails, so you should immediately ignore anyone claiming to be from Ledger who asks you for your mnemonic phrase.

Which cold wallet brand is currently the most secure?

Based on a comparison of publicly available security records from 2020 through October 2026, Keystone currently ranks first, followed by OneKey and BitBox02; none of the three have any publicly documented instances of user fund losses. The rankings reflect records as of October 11, 2026, and do not guarantee that incidents will not occur in the future; purchasing channels and custody practices are equally important.

Can the stolen funds be recovered?

There is some chance. Tether has frozen approximately $10 million in USDT, but the majority of the funds remain in addresses controlled by the attackers or have already been transferred via coin-mixing services. Whether the funds can be recovered depends on the progress of the law enforcement investigation; it is unclear at this stage.

Next Step: Protect Your Assets the Right Way

Cold wallets haven’t become obsolete because of this incident; what really needs to change are your purchasing and setup habits. If you’re planning to buy your first cold wallet or want to move your existing assets to a safer place, you can start by joining the MB community to exchange practical tips with other users and receive the latest updates on the situation as soon as they become available.

Disclaimer

The content of this article is for reference only, investors should exercise independent judgment, invest with caution and at their own risk, this article does not provide or attempt to persuade viewers to trade or invest on the basis of the content of this article is for sharing purposes only, and should not be regarded as investment advice, and does not represent the Monsterblockhk viewpoints and positions, all information and views of the specific date of the judgment of the time-limited nature. In addition, if any content in this website involves virtual asset trading platforms that have not yet obtained a license to operate virtual asset trading platforms in Hong Kong, including but not limited to text introductions, pictures, promotions, events, etc., they are only available to users outside of the Hong Kong Special Administrative Region.

According to the Hong Kong Anti-Money Laundering and Counter-Terrorist Financing (Amendment) Ordinance 2022, after June 1, 2023, all centralized virtual asset trading platforms operating in Hong Kong or actively promoting their services to Hong Kong investors will be licensed and regulated by the SFC, and any related unlicensed activities will be a criminal offence. For more information and details of the legislation, users may refer to the SFC website.