· via The Verge
Suspected hardware implant in resold Ledger wallets tied to $86M crypto theft
Over $86 million in crypto has been drained from hundreds of Ledger wallets containing what the company says was an unauthorized hardware implant, sold via reseller CryptoBillis, The Verge reports.

Suspected implant in resold Ledger wallets tied to $86M theft
More than $86 million in cryptocurrency has been taken from hundreds of Ledger wallet users in what appears to be a supply chain attack, according to The Verge. The tampered devices trace back to CryptoBillis, a reseller of Ledger hardware, and Ledger has asked the company to suspend all wallet sales while it investigates. Ledger has confirmed that a device belonging to one of the affected users contained an unauthorized hardware implant.
How the implant reportedly works
Photographs and videos circulating on X and Threads appear to show a small extra circuit board tucked underneath the wallet's screen. As The Verge describes it, the implant reads everything the display shows, including the seed passphrase presented during initial setup, and uses a built-in SIM card to transmit that information to whoever installed it. Armed with the seed phrase, the attacker can take control of the wallet and drain the funds from the account.
The seed phrase is the foundation of hardware wallet security: it is a full backup of the wallet's keys, and the entire premise of the device is that this phrase never exists in a form a remote attacker can reach. A physical implant that watches the screen during first-time setup breaks that premise from the moment the device boots.
Scope of the incident and Ledger's response
The Verge reports that the victims are concentrated in Southeast Asia and that the tampered units came through the CryptoBillis reseller channel. So far, there is no indication that Ledger's own systems were compromised, or that wallets purchased directly from the manufacturer were affected. Ledger has published guidance on how to check whether a device has been tampered with.
Why it matters
Hardware wallets occupy a specific niche in security: they are meant to be a sealed, physical boundary between a user's keys and the outside world. Their pitch is not that software cannot be compromised, but that the secret never travels through anything an attacker can touch. A supply chain attack inverts that logic. The compromise happens before the customer ever opens the box, and nothing about the wallet's behavior gives it away. The screen works, setup proceeds normally, and the implant quietly observes until the attacker decides to act.
The incident also sharpens an old lesson about where security hardware comes from. A reseller is an implicit trust assumption, and in this case that assumption appears to have failed. For buyers, the practical mitigations are narrow: purchase directly from the manufacturer, inspect any device against the vendor's tamper-checking instructions before loading funds onto it, and treat an already-opened or repackaged unit as suspect. For the industry, the harder question is whether packaging and software checks are enough when the attacking hardware can sit beneath the screen and communicate over its own cellular connection, entirely outside the wallet's normal attack surface.
- #ledger
- #crypto
- #hardware-wallets
- #supply-chain-attack
- #security