Hackers Steal $93 Million via Compromised Ledger Reseller
UpGateNegativeSecurity & hacks

Hackers Steal $93 Million via Compromised Ledger Reseller

Reading time: 3 min

Hardware Wallet Security Compromised in Southeast Asia Reseller Breach

The fundamental promise of a hardware wallet – to provide a secure, self-custodial vault for digital assets – has been severely undermined by a sophisticated attack targeting Ledger devices sold through an authorized reseller in Southeast Asia. Attackers are reported to have infiltrated Ledger wallets by planting hidden hardware, leading to estimated losses ranging from $72 million to over $93 million across hundreds of compromised devices.

Unauthorized Hardware Implants Discovered

Ledger confirmed on October 10, 2026, that at least one affected device contained an unauthorized hardware implant. In response, the company has instructed its Southeast Asian reseller, CryptoBilis, to immediately halt all sales and shipments of its products.

The implants are described as miniature circuit boards equipped with cellular capabilities, discreetly concealed behind the device screens. Their function was to intercept a user’s 24-word recovery phrase and transmit it wirelessly over cellular networks. This recovery phrase serves as the ultimate key to a cryptocurrency wallet, allowing anyone possessing it to reconstruct the wallet on a different device and access the funds without requiring physical access to the original hardware.

Allegations of Reseller Acquisition

Further complicating the situation, a post on X (formerly Twitter) alleged that the attackers’ operation extended beyond simple inventory tampering. According to this unconfirmed account, the hackers allegedly acquired the reseller outright, compelled it to sign a non-disclosure agreement, and subsequently infiltrated wallets with spy chips, siphoning over $80 million. Ledger has not corroborated the claims regarding the reseller’s acquisition or the non-disclosure agreement.

Widespread Fund Draining and Tracing Efforts

The unusual draining of funds reportedly began around October 9, 2026. Security researchers observed substantial inflows into addresses associated with theft across multiple blockchain networks, including Bitcoin, Ethereum, and Tether’s USDT stablecoin. The majority of the losses occurred between October 9 and October 10. Some of the stolen cryptocurrency was allegedly laundered through privacy mixers like Tornado Cash. In response, Tether has reportedly frozen approximately $10 million in USDT linked to the theft addresses.

Researcher Details Implant Technology

Researcher Mark Karpelès has provided documentation detailing the compromised hardware. His findings suggest the presence of multiple generations of these implants in devices purchased in Southeast Asia. Karpelès’ analysis indicates that the implants were designed to covertly monitor and extract sensitive user data without triggering Ledger’s internal security protocols.

CryptoBilis serves customers in Malaysia, Indonesia, and the Philippines. Ledger maintains that the security breach is confined to this specific reseller channel and has found no evidence of compromise to its core systems or products sold directly to consumers.

Implications for Users and Next Steps

Customers who purchased Ledger devices through CryptoBilis now face a critical dilemma. If an implant successfully captured their recovery phrase, the compromised device and any wallet derived from that phrase are no longer trustworthy. The recommended course of action for affected users is to migrate their funds to a newly generated wallet on a verified device using a fresh recovery phrase.

Looking ahead, three key developments will be closely watched: First, confirmation from Ledger or independent researchers regarding the exact number of devices containing implants. Second, the success of efforts to freeze or trace the stolen funds as they attempt to exit privacy mixers. Third, the verification of the claim that the attackers acquired the reseller, which would elevate the incident from a case of tampered inventory to a more serious breach involving the hostile takeover of a trusted sales channel.

Tags:UpGateNegativeSecurity & hacks
Copied