Nobody hacked the code. That is the part that should bother you. There was no phishing email, no malicious browser extension, no poisoned firmware update. The device did exactly what it was built to do: it drew your 24 recovery words onto its screen so you could write them down. Someone else was already watching that screen from inside the device.
Quick Summary
- On October 9, 2026, Ledger confirmed it is investigating losses tied to devices sold by CryptoBilis, an authorized reseller for Malaysia, Indonesia and the Philippines, and asked the shop to pause all sales and shipments.
- Ledger told buyers from the past 90 days not to set their wallets up, and told buyers who already had, to move their coins to a new signer with a brand new recovery phrase.
- On-chain researchers put the damage above $86 million. Blockchain data firm Bitquery traced $92.9 million taken from 311 wallets across TRON, Bitcoin, Ethereum, BNB Chain and Polygon.
- Ledger says its own infrastructure was not compromised and that it has received no reports involving devices bought directly from Ledger.
- Two independent teardowns describe an implant, not an exploit: a small board wired into the screen’s data lines that reads the seed words as they are displayed, plus a cellular connection that transmits them out.
- Corporate filings show CryptoBilis changed hands in 2026 – a shareholder registered in Heilongjiang, China took 100% equity effective August 3, under a non-disclosure agreement that ran until October 19.
What Actually Left the Wallets
The drain was not a smash and grab. According to Bitquery’s trace, the same operator emptied wallets on TRON, Ethereum, BNB Chain, Polygon and Bitcoin within 47 minutes, hitting five separate chains back to back. The clearest tell came from TRON: 25 separate wallets signed the exact same approval transaction inside a three-second window. You cannot coordinate that with phishing. You can only do that if one party is already holding every one of those wallets’ keys.
It also was not improvised. Starting September 25, two addresses ran a rehearsal loop – small test transfers with gas money, an approval, and a pull-back. The TRON address ran it 21 times, the Ethereum address 20 times. One practice run on October 2 moved three dollars into an address that later received $36 million on drain day. The attacker was mapping the payout wallet a full week before touching real money.
The victim profile points the same way. Bitquery’s wallet-age analysis found about six in ten victim wallets were first funded inside Ledger’s 90-day window, but more than eight in ten had been funded since June – meaning the exposure may reach back roughly four months, not three. One Bitcoin wallet took in 80 BTC on September 29 and lost the entire balance in a single block three days later. At least one drained TRON wallet had been moving 33.5 million USDT like a business treasury.
The Part Nobody Can Patch
Ledger has not confirmed the mechanism. But two separate accounts point at the same weak spot, and it is not the cryptography.
Mark Karpeles, the former Mt. Gox CEO, says he bought a Ledger through a Malaysian channel and found a hidden module with a SIM-style chip concealed in the screen padding, with the outer packaging showing no sign of tampering. Separately, 23pds, the chief information security officer at SlowMist, described the technical path: a small microcontroller tapped onto the screen’s data lines, recording the recovery phrase word by word as it renders during setup, then transmitting those words out over a built-in LTE or eSIM connection.
Here is why that works. The Secure Element chip inside a hardware wallet is genuinely hard to break – it is built to stop anyone reading the private keys out of it. But it does nothing to control what gets drawn on the screen during the one moment the 24 words are shown to a new owner. An implant on the display path never has to break the cryptography. It just has to watch. And because the actual Ledger chip is genuine, the device passes the genuine-check. It is not a counterfeit wallet. It is a real wallet with a passenger.
Two less exotic explanations are still on the table: a device pre-initialised before shipping and resealed, or a customer database stolen from the reseller and used for targeted phishing. Ledger has ruled out neither.
“Authorized Reseller” Is a Badge, Not a Guarantee
CryptoBilis was not a fly-by-night storefront. It was founded in Kuala Lumpur in 2020, sold Trezor, OneKey, Tangem and SafePal alongside Ledger, and it sat on Ledger’s own distributor listing as an authorized seller for three countries. For a buyer who checked the manufacturer’s site before spending money, that listing was the safety signal.
Then the filings: the company changed owners in 2026, the original founders say they lost operational control, and the buyer had the outgoing executives sign an NDA covering the sale – an NDA that ran until October 19. Which means that when the drain went public on October 9, the people who knew most about what changed inside that company were contractually barred from saying a word. No evidence has tied the ownership change to the theft. The timing is enough to keep asking.
This is the lesson hiding under the dollar figure: “authorized reseller” tells you who Ledger trusted to run a shop years ago. It tells you nothing about who runs it today. A badge is a moment in time, not a guarantee that survives a change of ownership, a change of staff, or a change of intent.
Why This Matters for Bitcoin
A hardware wallet exists to remove one thing: trust in a third party. It is the only consumer device whose entire pitch is that nobody – not an exchange, not a bank, not the manufacturer – can move your coins without you. The seed phrase is the whole security model. Whoever has those 24 words is you, as far as the network is concerned.
This incident attacks the one part of that model you cannot verify from your sofa. You can verify your own seed. You cannot verify that the box you sealed in 2026 was sealed by the people whose name is on it. The device was never broken. The chain of custody was.
And it is not an isolated story. A 2020 Ledger data breach handed attackers names, emails and home addresses. In 2023, Ledger’s Connect Kit library was compromised and used to trick users into signing malicious transactions for a few hours. Trezor’s third-party fulfilment partner leaked details for close to 81,000 customers, and the phishers promptly used Trezor’s own domain to hunt 347,000 wallets. Coldcard’s firmware bug drained holders earlier this year. Four different companies, four different attack paths, one recurring failure point: the part of self-custody that gets handed to somebody else – the reseller, the fulfilment partner, the courier, the packaging.
Self-custody is still correct. It is just not a product you buy. It is a chain of custody you have to personally close.
The Love Is Bitcoin Takeaway
Do these in this order:
- Never accept a pre-printed recovery phrase. Any wallet that arrives with 24 words already on a card is a gift to whoever printed them. Generate the seed yourself, on the device, in front of your own eyes.
- Factory-reset any device that was already initialised when you opened it. If it powered on into a ready wallet, it is not new.
- Buy direct from the manufacturer whenever you can. Where you cannot, buy from a seller who lets you verify the chain of custody, and treat a change of ownership at that seller as a reason to re-verify everything.
- Generate the words somewhere a camera or an implant cannot see. The screen is the leak. Set the wallet up offline, alone, away from windows, cameras and strangers.
- If your seed came from a device you did not buy direct, move to a new seed today. Not next week. Not after you finish reading. Fresh device, fresh words, then sweep your coins.
What Beginners Should Do Next
- Check where your device actually came from. If it arrived via a marketplace seller, a regional reseller or a discount listing, assume nothing and generate a new seed on hardware you trust.
- Learn the difference between a wallet brand and a wallet installation. The brand builds the chip. The installation is where the seed is born, and that is the step you must own.
- Write your seed on something that survives water, fire and time, and store it where nobody can photograph it.
- Split long-term holdings from spending. A device you carry is a device you expose.
- Start with education before chasing anything else. The strongest wallet in the world still ends at 24 words, and those words are the whole ballgame.
FAQ
Was Ledger itself hacked?
Nothing public so far points to a breach inside Ledger’s own systems. The losses are tied to devices bought through CryptoBilis, a third-party reseller. Ledger says it is investigating how the affected recovery words were obtained.
How much was actually stolen?
Bitquery’s on-chain trace puts it at $92.9 million from 311 wallets across five blockchains. Earlier estimates from individual researchers ranged from roughly $72 million to $87 million based on smaller sets of known addresses. Ledger has not confirmed a final figure.
How were the seed phrases obtained?
Not confirmed. Independent accounts describe a hidden board that reads the 24 words off the screen during setup and transmits them over a cellular connection. Pre-initialised devices and reseller database phishing remain possible and have not been ruled out.
Is my hardware wallet safe if I did not buy from a reseller?
Devices bought directly from the manufacturer are not implicated in this incident, and Ledger says it has received no reports involving direct sales. The safe default has not changed: buy direct, generate your own seed, verify everything you can.
What should I do if I did buy from a reseller?
If the device was never activated, do not activate it. If it was, treat the recovery phrase as compromised and move your coins to a new device with a freshly generated phrase. Given that the exposure may stretch back to June, do not assume the 90-day window protects you.
Can the stolen coins be recovered?
Tether froze roughly $10 million in USDT within two hours. The stolen Bitcoin, about 203.8 BTC, has not moved. But the attacker started feeding ETH into a mixer within hours, and funds that have already passed through it or been swapped into other stablecoins are very unlikely to come back.
Does this mean self-custody is broken?
No. It means the half of self-custody people outsource – buying, shipping, packaging, the shop – is the half that fails. You are the custodian. That was always the job.
Final Thoughts
The $92.9 million did not leave because someone cracked Ledger’s encryption. It left because the industry sold you a device and then let the trust live in a supply chain nobody audits, in a shop whose ownership quietly changed, under an NDA that expires ten days after the money left.
This was not a hack. It was a business plan that used a badge as camouflage. The fix is not a better chip. The fix is buying direct, generating your own words, and never letting a seller, a courier or a box decide who holds your keys.
When you are ready to buy back in, buy somewhere that never holds your coins. Bull Bitcoin lets you buy Bitcoin and send it straight to a wallet you control – no custody, no IOUs, no account balance for somebody else to freeze. Use coupon LOVEISBITCOIN at loveisbitcoin.com/bull.
So here is the question: if the box can be compromised before you ever open it, what exactly are you trusting when you trust a brand? And when did you last verify that the words on your device were generated by you?
This article is for education only and is not financial advice. Ledger has not confirmed the implant mechanism or a final loss total, and no evidence yet ties the CryptoBilis ownership change to the theft.
Source: the X thread by @exsiway_ that assembled the reseller-sale and teardown details (https://x.com/exsiway_/status/2108635197662986357), plus Bitquery’s on-chain trace and the teardown accounts from Mark Karpeles and SlowMist’s 23pds. Our first report on this story is here. For the basics on choosing hardware you control, start with Choosing a Bitcoin Wallet, and for how the same trust gets weaponised, read the Trezor domain-phishing case and what Ledger keeps asking self-custody users to do next.