Ledger has confirmed that a device belonging to one of the users affected by the CryptoBilis incident contained an “unauthorized hardware implant,” advancing an investigation into reported cryptocurrency losses among buyers in Southeast Asia.
In a situation update posted on October 10, the hardware-wallet maker said it had confirmed the implant in one affected user’s device. The statement strengthens the physical-tampering theory that emerged after former Mt. Gox chief Mark Karpelès shared images of a suspicious chip found inside a Ledger device.
However, confirmation of an implant in one device does not establish that it caused all the reported losses. The full scope of the incident, the number of affected devices and the relationship between the implant and the wallet drains remain under investigation.
What affected Ledger users should do now
Ledger’s guidance distinguishes between users who have not yet activated their devices and those who have already set them up. Customers who purchased a Ledger device through CryptoBilis within the 90 days preceding the warning and have not yet set it up should not initiate setup. Users who have already set up such a device should consider moving their assets to a new Ledger signer with a newly generated recovery seed, following Ledger’s instructions.
The company has also reiterated its anti-scam guidance. Users should follow official Ledger channels for updates and contact support through Ledger’s official support website. Ledger says it will never ask users to disclose their 24-word recovery phrase.
Users should not share their recovery phrase with anyone claiming to provide emergency assistance, investigate the incident or help recover stolen funds.
CryptoBilis suspends sales as investigation continues
Ledger said CryptoBilis had confirmed that it suspended sales of its hardware-wallet inventory until the investigation concludes. The company also said it remained in active communication with the reseller about next steps.
The sales suspension follows Ledger’s initial request for CryptoBilis to pause sales and shipments while it investigated reports of missing funds. CryptoBilis has operated as a Ledger reseller in Southeast Asia, including Indonesia, Malaysia and the Philippines. Ledger also said it was working with the appropriate authorities and thanked the crypto security-response collective SEAL 911 for its support with the investigation.
Those efforts indicate that the incident remains under active investigation. They do not, by themselves, establish that the perpetrators have been identified or that the reported funds will be recovered.
Ledger also said it had no indication that its security infrastructure, systems or services had been compromised. That is the company’s stated assessment; it should not be read as proof that every aspect of the incident has been resolved. The evidence of an implant points to physical tampering in at least one device, but the investigation has not publicly established the full method used to compromise the affected wallets or whether all reported losses share the same cause.
Ledger also said it was continuing to develop additional anti-tampering measures. The company has not publicly confirmed that its broader device supply chain was compromised beyond the incident under investigation.
How the CryptoBilis incident unfolded
Ledger was investigating CryptoBilis after reports of more than $86 million in crypto losses among users in Southeast Asia. On-chain investigators subsequently published estimates of the suspected losses. Bitquery estimated approximately $92.9 million across 311 wallets on five blockchains, while other tracking placed the figure above $86 million. These remain third-party estimates, not a loss total confirmed by Ledger. The number of affected wallets and the precise relationship between the tracked transactions remain subject to verification.
The physical-tampering theory gained attention after Changpeng Zhao warned Ledger users and Mark Karpelès reported a hidden chip in a device. Karpelès shared images of a Ledger device that he said had been purchased in Malaysia, with a small component concealed beneath the screen area.
Zhao described the available information as suggesting a supply-chain attack involving one vendor. Ledger’s confirmation that one affected user’s device contained an implant provides additional evidence of physical tampering. It does not independently verify every detail of Karpelès’s separate device report or establish that the implant explains all the reported wallet losses.
Why the confirmation matters
Hardware wallets are designed to keep users’ private keys under their control, but the security of a device can also depend on the integrity of the hardware before it reaches the customer. Evidence that an affected device contained an unauthorized implant highlights the potential risks posed by physical tampering in a distribution chain.
For customers who bought through CryptoBilis during the period identified by Ledger, the company’s advice is the immediate priority: do not set up an unused device, and consider migrating assets from an already configured device to a new signer with a new recovery seed, following official instructions.
The incident does not establish that all Ledger devices are compromised, nor does the confirmed implant by itself settle the cause of every reported loss. Ledger’s investigation and the on-chain tracing efforts will be important to determining how the affected devices were altered, how the wallet drains occurred and how much cryptocurrency was lost.
The Crypto Times will continue to update this report as further verified information becomes available.
Also Read: Hoskinson Pushes Back on Buterin’s Lattice Cryptography Concerns
