On October 9, 2026, Ledger opened an investigation into the theft of at least $86 million in cryptocurrency from users who purchased hardware wallets through CryptoBilis, an authorized reseller operating in Malaysia, Indonesia, and the Philippines. On-chain analysis firm Bitquery subsequently tra...
"No reports had been made regarding products purchased directly from Ledger or about its infrastructure, systems and services." — Ledger Spokesperson, October 9, 2026
On October 9, 2026, Ledger opened an investigation into the theft of at least $86 million in cryptocurrency from users who purchased hardware wallets through CryptoBilis, an authorized reseller operating in Malaysia, Indonesia, and the Philippines. On-chain analysis firm Bitquery subsequently traced $92.9 million drained from 311 wallets across five blockchains in a coordinated 47-minute attack. On October 10, Ledger confirmed that one affected device contained an unauthorized hardware implant — a microcontroller with LTE, eSIM, and antenna components concealed behind the screen — capable of intercepting seed phrases during device setup.
The incident is the largest known hardware wallet supply chain attack in the industry's history. It follows a separate Trezor data breach via logistics partner ShipMonk in August 2026, which exposed the personal information of up to 81,000 customers. Together, these events expose a structural vulnerability in the $431–$914 million hardware wallet market: the reseller and logistics layer sits outside manufacturers' security perimeters, and neither Ledger nor Trezor has implemented tamper-detection mechanisms sufficient to catch physical modifications before devices reach end users.
According to Bitquery's on-chain analysis, the coordinated drain occurred on October 9, 2026, and lasted 47 minutes. Independent researchers tanuki42 and Specter first flagged abnormal outflows; Bitquery subsequently confirmed the totals.
Breakdown by chain:
| Chain | Wallets Drained | Loss | |-------|----------------|------| | TRON | 131 | $70.5M | | Bitcoin | 122 | $16.8M | | Ethereum | 33 | $3.7M | | BNB Chain | 27 | $1.45M | | Polygon | 13 | $0.58M | | Total | 311 | $92.9M |
TRON accounted for 75.9% of the total loss, consistent with the network's dominance in USDT transfers across Southeast Asia. Bitcoin wallets comprised the second-largest tranche at $16.8 million.
The attack followed a two-week rehearsal period (September 25 through October 7) during which the attacker executed test transactions, including final practice runs 23 seconds apart on October 7. Within two hours of the main drain, funds began moving through Tornado Cash, and stablecoins were swapped to evade further freezes. Tether froze approximately $10 million in USDT linked to the stolen funds.
On October 10, Ledger confirmed that one impacted user's device contained "an unauthorized hardware implant." Former Mt. Gox CEO Mark Karpelès posted photographs of the implant the previous day, identifying LTE components, an antenna, an eSIM, and a microcontroller concealed in the buffer pad behind the screen of a Ledger Nano X.
According to 23pds, chief information security officer at SlowMist, the suspected mechanism involved "a small microcontroller wired into the device's screen data lines, recording the recovery phrase character by character as it displays during setup, then transmitting the captured words out over a built-in LTE or eSIM connection."
The implant's placement on the SPI bus — the data line between the secure element chip and the display — represents a sophisticated interception point. The secure element itself was not compromised; instead, the implant captured seed phrase words at the moment they were rendered on the screen during initial device setup. This distinction matters: Ledger's core cryptographic architecture remained intact, but the physical layer between the chip and the display was exploited.
Earlier in 2026, reports of similar implants emerged from Thailand, suggesting a pattern concentrated in Southeast Asian resale channels. Ledger stated that no reports had been filed regarding products purchased directly from the company.
CryptoBilis was founded in Kuala Lumpur in 2020 and operated as an authorized Ledger reseller for Malaysia, Indonesia, and the Philippines. The company also sold Trezor, OneKey, Tangem, and SafePal devices.
Corporate records show a share transfer was initiated in March 2026, with 100% equity acquired by a shareholder identified as "Jiaming," whose registered address is in Heilongjiang Province, China. The transfer was completed on August 3, 2026 — 67 days before the coordinated drain.
According to reporting by BitPinas, the original co-founders confirmed that previous shareholders "fully withdrew from all operational, managerial, and administrative roles." The buyer required former executives to sign a non-disclosure agreement with an expiration date of October 19, 2026. When the hack became public on October 9, the individuals most knowledgeable about the ownership transition were contractually prohibited from speaking.
The NDA window is notable: it expires 10 days after the attack went public, effectively ensuring that the former leadership could not publicly comment during the critical first days of the investigation. Whether this timing was coincidental or deliberate remains undetermined. The investigation is ongoing.
Ledger asked CryptoBilis to suspend all sales and shipments on October 9. The company advised users who purchased devices from the reseller within the past 90 days to refrain from initializing any unused devices and to consider transferring assets to a new Ledger signer with a freshly generated seed phrase.
Seven weeks before the Ledger-CryptoBilis incident, Trezor disclosed a data breach at ShipMonk, its third-party logistics and fulfillment partner. On August 10, 2026, Trezor reported that attackers exploited CVE-2026-72898 — a critical SQL injection vulnerability rated 10.0 on the CVSS scale — in Metabase, an analytics platform used by ShipMonk.
The breach initially affected 13,689 customers whose orders shipped between May 10 and August 8, 2026. Of those, 11,742 had full exposure (name, email, phone, shipping address), while 1,947 had partial exposure. By September 2, Trezor disclosed that the breach was larger than first reported, encompassing 81,000 customers with order data dating back to November 2019.
Trezor's devices and firmware were not compromised. However, the breach created a curated list of confirmed hardware wallet owners with home addresses — precisely the information needed to target users with tampered replacement devices or phishing campaigns. The geographic footprint spanned the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal.
The two incidents are structurally different — physical implant versus data breach — but they share a common failure point: the distribution and logistics layer that connects manufacturer to end user.
The hardware wallet security model rests on a core assumption: that the device arriving in the user's hands is identical to the one that left the factory. The CryptoBilis incident demonstrates that this assumption breaks down at the reseller layer.
Historical supply chain incidents:
| Date | Company | Vector | Impact | |------|---------|--------|--------| | Jun 2020 | Ledger | E-commerce database breach | 1M+ emails, 272K full records exposed | | May 2023 | Trezor | Firmware tampering via resellers | Pre-generated seed phrases (Russia) | | Dec 2023 | Ledger | Connect Kit library compromise | Rogue WalletConnect drainer injected | | Aug 2026 | Trezor | ShipMonk logistics data breach | 81,000 customer records exposed | | Oct 2026 | Ledger | Physical hardware implant via reseller | $92.9M stolen from 311 wallets |
The pattern shows escalating sophistication. The 2023 Trezor firmware tampering in Russia involved pre-generating seed phrases — a relatively crude method that required the attacker to control both the seed and the device. The 2026 CryptoBilis implant intercepted the user's own seed phrase generation process, a method that is harder to detect and scales more effectively.
Ledger and Trezor together control more than 70% of the global hardware wallet market, according to market research data. Ledger has shipped over 8 million devices since 2014, and the company states it secures approximately 20% of global crypto user assets. Trezor has shipped over 2 million units. The market itself is valued at an estimated $431 million to $914 million in 2026, depending on the source, with projections of $1.9 billion by 2033.
The scale of the installed base means that even a narrow compromise in a single reseller channel can produce losses in the tens of millions.
The $92.9 million CryptoBilis loss fits within a broader pattern of crypto theft in 2026. According to industry tracking data, DeFi protocols alone lost $1.3 billion in the first eight months of the year, with compromised private keys overtaking smart contract bugs as the leading attack vector for the first time on record.
However, the CryptoBilis attack is distinct in its category. DeFi exploits target protocol code. Exchange hacks target institutional custody. The CryptoBilis incident targets the self-custody layer — the very mechanism that hardware wallets are designed to protect.
Self-custody adoption has been a consistent industry narrative: "not your keys, not your coins." Hardware wallets are marketed as the most secure method of key management available to retail users. A successful supply chain attack on this layer undermines the foundational security proposition of the product category.
Ledger's pricing for the Nano X is approximately $149. The average loss per affected wallet in the CryptoBilis incident was $298,700 — a ratio of roughly 2,000:1 between the value secured and the cost of the security device. This asymmetry creates a substantial economic incentive for supply chain attackers.
$92.9 million was stolen from 311 wallets across five blockchains in a 47-minute coordinated drain on October 9, 2026, targeting users who purchased Ledger devices through Southeast Asian reseller CryptoBilis.
Ledger confirmed a physical hardware implant in at least one affected device, containing LTE, eSIM, antenna, and microcontroller components that intercepted seed phrases during setup.
CryptoBilis changed ownership on August 3, 2026, with 100% equity transferred to a Heilongjiang-based shareholder, 67 days before the attack. An NDA prevents former leadership from commenting until October 19.
Trezor disclosed a separate supply chain breach via logistics partner ShipMonk in August 2026, exposing up to 81,000 customer records including home addresses — creating a target list for physical social engineering.
Neither manufacturer has deployed tamper-detection sufficient to catch physical device modifications occurring between factory and end user. The reseller layer remains a structural blind spot.
The hardware wallet market's 70%+ concentration in two vendors (Ledger and Trezor) means supply chain vulnerabilities at either company carry systemic risk for retail self-custody.
The CryptoBilis incident represents a new category of crypto theft: not a smart contract exploit, not a phishing campaign, not a key management failure by the user — but a compromise of the physical hardware device before it reaches the buyer. The secure element performed as designed; the attack bypassed it entirely by reading the screen output.
For an industry that has spent a decade building the narrative of self-sovereign custody, the implication is uncomfortable. Hardware wallets remain the strongest option for individual key management, but their security guarantee ends at the factory door. Everything between the assembly line and the user's hands — warehousing, logistics, reseller handling — is a potential interception point.
Ledger's investigation is ongoing. CryptoBilis sales remain suspended. The former leadership's NDA expires October 19. Until the full chain of custody is reconstructed, the 311 affected wallets represent both a financial loss and an open question about how many other modified devices may still be unactivated.