Ledger Finds Hardware Implant in CryptoBilis Wallet

Ledger confirmed an unauthorized hardware implant in one wallet sold by CryptoBilis and urged buyers not to set up unused devices or reuse recovery phrases.

Ledger confirmed Oct. 10 that one hardware wallet sold through CryptoBilis contained an unauthorized hardware implant. The finding is linked to an investigation into wallet-draining incidents in Southeast Asia that began Oct. 9.

CryptoBilis is a reseller listed by Ledger for Indonesia, Malaysia and the Philippines. The reseller has stopped selling all hardware-wallet inventory while the review continues. Ledger is contacting affected customers, working with authorities and receiving assistance from the security group SEAL 911.

Ledger reported no evidence that its security infrastructure, systems or services were compromised. The company has confirmed one device with the implant but has not identified its model or disclosed how many other devices may be affected. It has not confirmed that the implant caused the reported losses.

Blockchain researchers estimate that more than $86 million has been taken from users of Bitcoin, Ethereum and TRON. Other estimates put the losses at about $92.9 million across 311 wallets and $93.4 million across 471 addresses. Ledger has not verified those figures.

Mark Karpelès, the former chief executive of Mt. Gox, provided a technical description of a modified Ledger Nano X. The device reportedly contained a concealed circuit board, an LTE module, an eSIM and a microcontroller connected to the display’s SPI bus.

The reported design could record a 24-word recovery phrase while it appeared on the screen during setup and send it over a cellular connection. It would not need to access the secure element that stores private keys. Since the secure chip and firmware could remain unchanged, a tampered device might still pass Ledger’s genuine-device check. Ledger has not published its own technical findings or confirmed that this method was used.

Ledger advises customers who bought from CryptoBilis within the past 90 days not to initialize an unused device. Customers who already initialized a device should treat it as untrusted and transfer their assets to a new wallet created with a new recovery phrase. Reusing the original phrase would leave the same keys exposed. Customers should contact Ledger through support.ledger.com.

Ledger also warned that it will never request a 24-word recovery phrase. Buyers should ignore messages asking for the phrase and use the company’s official support channel.

The confirmed case involves devices sold through CryptoBilis. Ledger has reported no indication that devices bought directly from the company are affected and is developing additional measures to detect physical tampering.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author