Ledger has confirmed the discovery of an unauthorized hardware implant on an affected user’s device. This physical finding proves that the asset breach did not originate from standard malware, while updating earlier investigation reports that previously estimated losses between $86 million and $90 million.
Estimated losses continue to mount as on-chain tracking progresses. Security researcher Specter estimated losses exceeding $86 million across Bitcoin, Ethereum, and Tron networks. Analytics firm Bitquery released a higher estimate of over $92 million across 311 examined wallet addresses, while independent investigator tanuki42 recorded a figure topping $72 million.
What sets this incident apart from typical hacks is its attack vector: the perpetrators infiltrated via physical components before the units reached buyers’ hands.
Compromised Devices Traced to CryptoBilis
The illicitly implanted units circulated through CryptoBilis, a distributor serving Indonesia, Malaysia, and the Philippines. CryptoBilis previously operated as an official Ledger reseller for the Southeast Asian region. In response to these findings, CryptoBilis halted sales of all hardware wallet inventory until an audit is completed.
Ledger emphasized that its server infrastructure and service systems remain secure without any breaches. The French manufacturer confirmed that the physical tampering incident was isolated to units supplied by the local reseller, rather than an assembly defect from the main factory.
What Should Device Owners Do?
Ledger urged buyers from the reseller not to configure their new devices. Consumers who have already activated their units are advised to immediately transfer all funds to a new Ledger device with a newly generated 24-word recovery phrase (seed phrase). Anyone with additional information is directed to report to Ledger’s bounty program at bounty@ledger.fr.
Threats facing users are increasingly layered with the emergence of search engine scams. Security researcher Cyber Scrilla discovered a fake Ledger website ranking at the top of Google search results aimed at phishing victims’ recovery phrases. Such campaigns align with findings from Zscaler in September 2026, which noted that spoofed Google ads bypassed account verification and redirected victims to fraudulent pages.
Physical supply chain tampering demonstrates that cold wallet security does not rely solely on digital safeguards. Verifying device provenance and refusing to enter recovery phrases on any screen remain the strongest defense for crypto asset owners.
Reported by Cointelegraph.
Read also: Tron Activates Post-Quantum Defenses on Testnet - Justin Sun Says Mainnet Ready Anytime
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




