Ledger has confirmed finding an unauthorized hardware implant inside one customer’s cryptocurrency wallet during its October 10 investigation into reported thefts involving Southeast Asian reseller CryptoBilis, as blockchain researchers estimate suspected losses exceeding $86 million.
Summary
- Ledger confirmed an unauthorized hardware implant inside one affected customer’s device during its CryptoBilis investigation.
- CryptoBilis suspended sales of all hardware wallets while Ledger investigates reported losses involving Asian customers.
- Ledger advised customers with CryptoBilis devices against setup and recommended fresh recovery phrases for others.
- Researcher Mark Karpelès reported finding suspicious electronics behind a Ledger Nano X screen in Malaysia.
- Bitquery estimated $92.9 million in cryptocurrency losses across 311 wallets, figures unconfirmed independently by Ledger.
Ledger Support confirmed the discovery in an official statement, saying the modified device belonged to a user affected by the ongoing investigation. The company said CryptoBilis had stopped selling all hardware wallets as a precaution and that Ledger was contacting affected customers while working with authorities. It has not established whether the implant caused the reported cryptocurrency losses.
The discovery provides direct confirmation of physical tampering in at least one device, following earlier warnings about suspicious wallets distributed through the reseller.
Ledger confirms unauthorized implant in customer’s wallet
During its investigation, Ledger identified an additional electronic component inside a wallet belonging to an affected customer.
The company described the component as an “unauthorized hardware implant” but did not disclose the exact device model, how the component was installed or whether it had transmitted any information.
Reports of unauthorized transactions emerged on October 9 among customers who purchased Ledger products through CryptoBilis, a reseller operating in Indonesia, Malaysia and the Philippines. Following the complaints, Ledger opened an investigation into the reported losses and asked the distributor to suspend sales and shipments of its devices.
A subsequent report from The Block said on-chain investigators had initially identified suspected thefts exceeding $72 million, while another estimate placed the losses above $86 million.
Ledger has not confirmed either amount. The company emphasized in its latest statement that it has found no evidence suggesting its internal security infrastructure, systems or services were compromised.
“We have no indication that Ledger’s security infrastructure, systems or services have been compromised,” the company stated.
The manufacturer is developing additional protections against physical device tampering while investigators work to determine how the unauthorized component entered the affected wallet.
CryptoBilis halts all hardware wallet sales during investigation
Following Ledger’s discovery, CryptoBilis confirmed that it had suspended sales of its entire hardware wallet inventory.
The temporary halt covers all hardware wallet products sold by the distributor, extending beyond the earlier request to pause Ledger sales and shipments.
According to an October 10 report from TokenPost, CryptoBilis will maintain the suspension until the investigation concludes.
Ledger said it remained in active communication with the reseller regarding the investigation and appropriate next steps. Customers who purchased a device through CryptoBilis have been instructed not to begin setting it up if they have not already done so.
For customers who have used the devices, Ledger recommends considering a transfer of their cryptocurrency to a new hardware wallet initialized with a completely new recovery phrase. Moving an existing recovery phrase onto a replacement device would not address possible exposure of that phrase through the original hardware.
The company’s statement did not identify any suspects, announce arrests or provide a timetable for completing the investigation. Separately, former CryptoBilis executives Arravind Prabu and Vimalatheethan stated that they had transferred operational control of the business following an ownership change earlier in 2026.
In a statement shared with researcher Mark Karpelès and published by Tibane Labs, the former executives said they completed their management handover in March and no longer controlled company systems or customer databases.
Their statement does not establish who modified the affected device or whether the ownership change had any connection to the incident.
Security researcher reports hidden electronics behind Ledger screen
Before Ledger publicly confirmed the hardware implant, former Mt. Gox CEO Mark Karpelès reported examining a suspicious Ledger Nano X device obtained from Malaysia. On October 9, Karpelès described finding an additional electronic component hidden behind the device’s display, inside material normally used to protect the screen.
He reported that the wallet had arrived in packaging that appeared intact, raising questions about whether customers could identify a modified device through a routine visual inspection. In photographs shared publicly, the component appeared to contain electronic circuitry separate from the wallet’s original hardware.
Karpelès subsequently reported examining the modification further and inspecting images provided by other affected users.
A technical account published by Tibane Labs described an arrangement involving a microcontroller, cellular communication hardware and connections to the screen’s internal data lines. The analysis suggested that a component positioned along the screen connection could potentially capture information displayed during wallet setup.
A recovery phrase typically consists of 24 words that allow a wallet owner to restore access to cryptocurrency holdings. If an attacker obtains those words, the attacker may be able to recreate the wallet and authorize transfers without possessing the original hardware device.
Researchers have suggested that an implant capable of reading information sent to the display could potentially capture recovery words when a wallet is initialized.
However, Ledger has not independently confirmed that the discovered implant performed that function or that it was responsible for the reported thefts.
The company’s official announcement confirms physical tampering in one affected device without establishing the technical method used to access customer funds. Ledger’s historical security research has previously examined situations involving unauthorized modifications to wallet hardware.
In a 2018 security response, the manufacturer discussed how attackers with physical access could modify a wallet and use additional electronics to interfere with its operation. The earlier research concerned different attack scenarios and did not establish a connection to the CryptoBilis investigation.
On-chain researchers estimate millions in suspected thefts
As investigators examine the affected hardware, blockchain analytics researchers have attempted to calculate the value of cryptocurrency moved from suspected victim wallets.
In an October 9 investigation, Bitquery estimated that approximately $92.9 million had been removed from 311 wallets across Bitcoin, Ethereum, TRON, BNB Chain and Polygon.
The estimate exceeded earlier reports of suspected losses ranging from $72 million to more than $86 million. Bitquery attributed the difference to additional wallets and blockchain networks included in its analysis. Its researchers reported that the largest portion of the suspected losses involved USDT transactions on TRON, followed by Bitcoin and Ethereum transfers.
The report identified approximately $70.5 million in assets transferred from TRON wallets and $16.8 million in Bitcoin. Using transaction timing and address relationships, Bitquery argued that the activity was consistent with an attacker already possessing control over multiple wallets.
The research company identified closely timed transactions across several networks and examined where the transferred assets subsequently moved. Bitquery reported that approximately $10 million in USDT had been frozen in addresses linked to the suspected thefts.
It further identified transactions involving cryptocurrency swaps and transfers to Tornado Cash, a service used to obscure the transaction history of digital assets. The analysis remains an independent assessment. Ledger has not confirmed Bitquery’s estimated losses, number of victims or conclusions about the attacker.
More recent on-chain reporting from PublicAML described additional movements involving suspected stolen Ether on October 10, including transfers to Tornado Cash. The analysis estimated that 900 ETH reached Tornado Cash during another series of transfers, although the researchers’ wallet attribution and loss calculations remain separate from Ledger’s confirmed findings.
Ledger urges users to protect recovery phrases
Ledger’s investigation has prompted warnings about the possibility of criminals exploiting public concern surrounding the reseller incident. The company cautioned customers to rely on official communication channels for information about affected devices, investigations and potential security measures. Its public statement reminded customers that Ledger support personnel will never request their 24-word recovery phrase.
Earlier research into fraudulent Ledger websites documented phishing pages that attempted to obtain recovery phrases through fake wallet verification requests.
The report, published October 11, discussed malicious Google advertisements that directed users toward imitation Ledger websites and applications. The phishing campaign has not been linked to the CryptoBilis hardware investigation. In its latest notice, Ledger said it was preparing additional measures intended to make unauthorized physical modifications harder to carry out.
The company did not announce a release date for those protections or provide details of any hardware redesign. For customers seeking guidance, Ledger directed inquiries to its official support website at support.ledger.com.
Its security team said affected users would continue receiving direct communication as the investigation proceeds, while information about the incident can be submitted through its bounty program.






