Subscribe Now
Trending News

Blog Post

BITCOIN HARDWARE WALLETS JUST GOT HIT: LEDGER TOLD 90 DAYS OF BUYERS NOT TO TURN THEM ON – INVESTIGATORS SAY $86 MILLION IS GONE
News

BITCOIN HARDWARE WALLETS JUST GOT HIT: LEDGER TOLD 90 DAYS OF BUYERS NOT TO TURN THEM ON – INVESTIGATORS SAY $86 MILLION IS GONE 

You did everything right. You bought a hardware wallet. You moved your coins off the exchange. You told your friends to do the same. And then a shop in Malaysia handed you a device that may have already known your recovery phrase.

On Friday, Ledger told buyers who purchased its devices from a reseller called CryptoBilis in the last 90 days to not set their wallets up. For the ones who already did, the advice was worse: move your assets to a new device with a brand new seed. Right now.

On-chain investigator Specter says the damage is already north of $86 million. Ledger has not confirmed that number. Ledger has not explained how the funds left. Ledger has not said the devices were tampered with. Read that list again, because that is the part you should be angry about.

What We Actually Know

Ledger’s support team named the reseller on Friday: CryptoBilis, a Malaysian shop founded in 2020 that sells crypto gear and Ledger devices, and also operates in Indonesia and the Philippines.

Ledger said it asked CryptoBilis to pause all sales and shipments of its devices as a precaution while it investigates. Customers who bought in the past 90 days were told to hold off on setup. Customers who had already set up were told to consider moving their funds to a new Ledger signer with a new seed phrase.

That is the entire official answer. No root cause. No confirmed total. No explanation of how coins left wallets that were supposedly protected by a device that requires physical confirmation.

The numbers come from the chain, not the company. Specter traced suspected losses of $86.96 million across 98 addresses on Ethereum, TRON and Bitcoin, after users posted on X and Reddit about drained wallets. Security researcher tanuki42 had put losses above $72 million before that, and said the figure was still climbing. Mempool data showed three of the Bitcoin addresses Specter listed holding about 211 BTC combined, unmoved as of 13:44 UTC on Friday.

One caveat that does not make anyone feel better: 98 addresses is not 98 confirmed victims, and Ledger has not endorsed the $86 million figure. But someone is holding that Bitcoin, and it is not the people who bought the wallets.

This Is Not a Coincidence. This Is a Pattern.

In April, a researcher found fake Ledger units on a Chinese marketplace that shipped with a PIN and a recovery phrase already set up, and quietly sent both to the attacker.

Last month, Trezor confirmed that close to 81,000 customers had their details leaked after its third-party fulfilment partner was breached.

This summer, a firmware bug in Coldcard’s seed generation drained tens of millions of dollars from Bitcoin holders, and researchers found that multiple attackers exploited it independently once the bug was understood.

And Ledger’s own payment processor, Global-e, was breached, which is why so many Ledger owners got phishing emails telling them to “verify” their recovery phrase.

Four different companies. Four different attack paths. One single point of failure: the part of self-custody that people hand over to somebody else.

Why This Is Your Problem, Not Ledger’s

Here is the uncomfortable truth about hardware wallets. The device is not the security. The seed is. Your 24 words rebuild every key in your wallet. Anyone who has them can drain you from a laptop on the other side of the planet without ever touching your device, without your PIN, and without your permission.

So a device that arrives with a recovery phrase already printed on a card inside the box is not a wallet. It is a honeypot with your name on the shipping label.

And if you bought a “sealed” wallet from a marketplace seller, a reseller, or a guy on a Telegram channel who offered it cheaper than the official store, you have no idea which of those two things you received. Neither does Ledger, apparently. That is exactly why they told 90 days of buyers to freeze.

Now the part nobody at the top of this industry will say out loud: nobody is going to refund you. Not Ledger, not the reseller, not your bank, not your government. Ledger’s statement does not contain a compensation line. It contains an instruction to move your own coins to a new seed, at your own cost, on your own time, while the coins are still being drained.

The system that told you “not your keys, not your coins” is correct. It just never told you that your keys are only yours if you generated them yourself, on a device you verified, from a seller you can trust with your life.

The Love Is Bitcoin Takeaway

Do these five things this week, in this order. Generate your own seed on the device itself, never accept a pre-printed recovery phrase from anyone for any reason. Factory-reset any wallet that arrived already set up. Buy hardware directly from the manufacturer, or from a seller who lets you verify the chain of custody. Never type your 24 words into a website, an app, a support chat, or a “wallet checker.” And if there is any doubt about where your seed came from, move everything to a new seed today, not tomorrow.

Self-custody is still the only answer. This is what happens when you outsource the boring half of it. The device is a tool. You are the custodian.

When you are ready to buy back in, do it somewhere that never holds your coins. Bull Bitcoin lets you buy Bitcoin and send it straight to a wallet you control, no custody, no IOUs, no account balances for someone else to freeze. Use coupon LOVEISBITCOIN at loveisbitcoin.com/bull.

So here is the question: if a hardware wallet can be compromised before you even open the box, what exactly are you trusting when you trust a brand? And when did you last verify that the seed on your device was actually generated by you?

This article is for education only and is not financial advice.

Previous

BITCOIN HARDWARE WALLETS JUST GOT HIT: LEDGER TOLD 90 DAYS OF BUYERS NOT TO TURN THEM ON - INVESTIGATORS SAY $86 MILLION IS GONE

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal