Security
111 Ledger Wallets Emptied in One Bitcoin Block, and the Reseller Had Changed Hands in March
Ledger said on October 10 that one affected user's device carried "an unauthorized hardware implant." Bitquery counts $93.2 million drained from 315 wallets on six chains on October 9, including 111 Bitcoin wallets emptied in a single block after two weeks of test transactions. Corporate filings show the reseller, CryptoBilis, was sold in March under a non-disclosure agreement. Ledger's own buying guide says its Genuine Check cannot detect physical modifications to the hardware.
Ledger Support's first post, on the morning of Friday, October 9, said the company "is investigating reports of loss of funds from users in South East Asia" and that it had "asked CryptoBilis to pause all sales and shipments of Ledger devices," per BitPinas. The advice that followed was unusually specific for a company that had not yet named a cause: "We recommend Ledger users who purchased from this reseller in the last 90 days to not initiate set up," and, for anyone who already had, to "consider moving assets to a new Ledger signer (with new seed)," as Gizmodo quoted it.
The second post came on Saturday. In what The Crypto Times describes as a situation update, Ledger said that a device belonging to one affected user contained "an unauthorized hardware implant." It repeated that it had "no indication that Ledger's security infrastructure, systems or services have been compromised," said it was working with authorities and with the volunteer response group SEAL 911, and said it was developing further anti-tampering measures. That is the whole of what Ledger has confirmed: one implant, in one device. It has not published a loss figure, a count of affected devices, a description of the implant, or a statement about how many of the reported losses it believes share a cause.
What the chain shows
The figures everyone else is using come from on-chain investigators, and they have grown each day. The pseudonymous analyst Specter, whose post CoinDesk cited on Friday, said more than $86 million "may have been stolen from hundreds of wallets" on Bitcoin, Ethereum and Tron, and said there had been no independent confirmation of the amount. MistTrack put reported losses at "approaching $90 million," per Crypto Briefing. Arkham's unverified "ledger-drainer" entity showed about $71.5 million on Friday afternoon, per Gizmodo.
The most detailed accounting this desk has read is Bitquery's, verified against the chain on October 11. It counts $93.2 million leaving 315 victim wallets on six chains, and it describes a drain that was rehearsed. Test loops began on September 25, 21 of them on Tron and 20 on Ethereum. The main drain started at about 05:00 UTC on October 9. At 04:59:57 UTC, 30 Tron wallets had a new key added, which locked their owners out; they were emptied at 10:26 UTC for $5.8 million. Twenty-five Tron wallets signed the same approval within three seconds of one another, and about $29 million left them within six seconds. At 05:54 UTC, 111 Bitcoin wallets were emptied in a single block. "Within 47 minutes the same thief had emptied wallets on Ethereum, BNB Chain, Polygon, Solana and Bitcoin," the report says, and its conclusion is the one the implant theory needs: "One actor held the keys to every drained wallet."
What left the wallets, by chain
Tether moved faster than anyone. Bitquery says it began blocking addresses about ten minutes after the first public post at 12:09 UTC on Friday, blocked 37 addresses over roughly two hours, 20 of which held $10.0 million in USDT, and at 15:30 UTC lifted the block on four wallets that behaved like over-the-counter desks serving other clients. The thief's response was to swap about $15 million into USDD, a Tron stablecoin Tether cannot freeze, and to push 2,990 ETH through Tornado Cash across October 9 and 10. As of about 06:00 UTC on October 11, Bitquery says, roughly $81 million could still be found on-chain. The 203.8 BTC had not moved.
The chip under the screen
The implant Ledger confirmed has not been described by Ledger. The one that has been described publicly belongs to Mark Karpelès, the former Mt. Gox chief executive, who on October 9 posted photographs of a Ledger he says he bought in Malaysia. The shrink wrap was intact. Where the screen's padding should have been, there was a second circuit board. "Even opening it, at first you don't see the implant which is cleverly hidden where the screen's padding is supposed to be," he wrote, per Gizmodo. He described an LTE module with a data eSIM, an antenna on a single wire, and a microcontroller wired to the device's SPI bus, the internal channel the chips use to talk to the display, per Crypto Briefing. His account of how it works: the microcontroller reads the Ledger font on the 128-by-64 display, recognises the setup screen, and sends the recovery phrase as text over the cellular network. Because it only listens, he argued, firmware cannot see it.
Two things about that account need saying plainly. Karpelès has not said his device came from CryptoBilis; he said his devices did not come from an authorised reseller, and that the Friday reports "could be exactly what I'm investigating." And Ledger's confirmation of an implant in one user's device does not say whether it matches his. The link between the photographs and the $93 million is, for now, timing.
What Ledger's own documentation says is less ambiguous. The company's Academy guide to buying a device safely describes the Genuine Check as "a cryptographic verification built into every Ledger signer" that "confirms that the device contains a genuine secure element." It then states the limit in the same voice: the check "cannot detect unauthorized physical modifications to the hardware," and it "cannot verify the device's physical supply chain history." A device with an untouched secure element and a second board watching the screen passes, by design. The guide's answer to that gap is the authorised reseller registry, and a warning that a legitimate device "never comes with a recovery phrase or PIN code pre-configured. Ever."
The reseller changed hands
CryptoBilis was on that registry for Malaysia, Indonesia and the Philippines until Friday. It was founded in Kuala Lumpur in 2020, has a walk-in location in Petaling Jaya, and sells Trezor, Tangem, SafePal and other brands alongside Ledger, per Gizmodo. On October 10, BitPinas reported that corporate filings circulating on X show "100% of CryptoBilis shares were transferred to an individual identified as Jiaming," with a registered address in Heilongjiang province, China. The acquisition closed in March; the share transfer was finalised in August, on August 3 by Journal du Coin's reading of the records. Former co-founder Arravind Prabu confirmed to BitPinas that the founders "surrendered all administrative, operational, and system access" to the incoming team after the March sale, and a co-founder told Journal du Coin: "We are no longer part of the company." A non-disclosure agreement barred them from announcing the sale; Journal du Coin says it expires on October 19.
Both outlets are careful about what that proves. "Investigators have not established direct evidence linking the change in corporate ownership" to the device modifications, BitPinas writes, and Journal du Coin's version is that nothing at this stage connects the buyout to the thefts. What is not in doubt is the sequence: a listed Ledger reseller was sold under an NDA in March, Ledger's registry still listed it in October, and Journal du Coin says it is unclear whether Ledger was told of the change of control. CryptoBilis has suspended sales and shipments of every hardware wallet brand it carries, online and in its stores, per BitPinas. It has made no statement about the devices.
The other hardware wallet this weekend
At about 02:00 UTC on October 11, Coldcard's official X account published a post warning of a critical flaw in recovery phrase generation on recent firmware and directing users to a "security migration" site, per Crypto Briefing. The post was fake and the link was phishing. Coldcard's statement, quoted by crypto.news: "We are investigating how a post containing a phishing link was published from this account." The company said its review found no login, session or access record matching the post, said the account has used offline two-factor authentication since 2017, and asked X to investigate whether the platform itself or an administrator's access was involved. That is a different attack on a different company, and it worked because of July: after a real firmware flaw cost Coldcard users more than 1,700 BTC, a fake one was believable. The CryptoBilis buyers were told the opposite, that the device was genuine, and it was.
The Take
Ledger has confirmed exactly one fact, and it is the right one to be careful with: an implant in one device. Bitquery's reconstruction is the thing to hold against it. One set of keys, 315 wallets, six chains, two weeks of test transactions, and a Bitcoin block that emptied 111 wallets at once. That pattern is what a stockpile of harvested seeds looks like when its owner decides the harvest is over, and it is hard to square with any explanation that involves a few tampered units. Ledger's buying guide already concedes the point that matters: the Genuine Check verifies the chip, not the box, and the company's defence against a modified box is a list of resellers it vouches for. The list vouched for a company that had been sold, quietly, seven months earlier. Whether Ledger's reseller program knew that, and what it checks when a listed partner changes hands, is the question the next statement should answer. The number of implants can wait for the lab. The number of resellers whose ownership Ledger has verified since March cannot.