1 min read
Add as a preferred source on Google

Ledger Confirms Unauthorized Hardware Implant in Customer Device

One customer device contained an unauthorized implant, while suspected losses range from $93.2 million to about $94 million.

Mentioned assets
Disassembled hardware wallet showing concealed circuitry on a workbench / TokenPost.ai
Disassembled hardware wallet showing concealed circuitry on a workbench / TokenPost.ai

Ledger confirmed Oct. 10 that one customer’s hardware wallet contained an unauthorized implant, escalating a cryptocurrency theft investigation involving reseller CryptoBilis and suspected losses nearing $94 million.

Ledger said it is contacting affected users and has found no indication that its security infrastructure, systems or services were compromised. The company’s reseller directory lists CryptoBilis in Indonesia, Malaysia and the Philippines.

Suspected losses range from $93.2 million to about $94 million, while Ledger has not confirmed the total, the number of affected devices or a direct link between the implant and every reported theft. One tally covered 315 wallets across six networks through 3 a.m. ET (07:00 UTC) Oct. 10, while a later estimate counted 474 addresses through 11:10 a.m. ET (15:10 UTC).

The stolen assets included Bitcoin (BTC), Ether (ETH) and stablecoins. A modified Ledger Nano X contained concealed circuitry and cellular equipment, but it has not been established that every affected device used the same components.

Ledger advised customers who bought from CryptoBilis within the previous 90 days not to set up unused devices. Customers who already activated them were advised to consider moving assets to a new device with a new recovery phrase.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…