Ledger Hardware Implant Confirmed as CryptoBilis Halts All Sales
Ledger has confirmed that a device belonging to one victim of the CryptoBilis wallet drains contained an unauthorized hardware implant, the clearest evidence yet that the losses stem from tampered hardware rather than a breach of Ledger itself.

The Ledger hardware implant that investigators had suspected is now confirmed. On Saturday, October 10, 2026, the wallet maker said that "one of the impacted users' devices contained an unauthorized hardware implant," according to Bitcoin.com News, turning a week of speculation about a supply chain attack linked to Southeast Asian reseller CryptoBilis into a documented case of physical tampering.
What happened
The statement, posted by Ledger's support account on X, was the first time the company confirmed that an affected customer's wallet had been physically modified. Ledger also said CryptoBilis "has ceased sales of all hardware wallet inventory until the investigation is concluded." The Defiant noted that this widens an earlier pause request that covered only Ledger devices.
The Verge described photos and videos circulating on X and Threads that appear to show a small circuit board tucked under a wallet's screen. The implant allegedly reads whatever the display shows, including the recovery phrase presented during initial setup, and uses an embedded SIM card to send that information to the attacker, who can then empty the wallet. Bitcoin.com News said the confirmation lends weight to findings published by former Mt Gox chief executive Mark Karpelès, who documented a modified Ledger Nano X with a hidden circuit board and cellular equipment.
The scale of the losses is still disputed. Earlier reports put thefts above $86 million across hundreds of wallets, The Verge said. Bitcoin.com News cited newer independent estimates of $93.4 million across 471 addresses from Yfarmx and roughly $92.9 million across 311 unique addresses from Bitquery, and stressed that Ledger has not verified either figure.
Why it matters
The Ledger hardware implant matters because of how it reportedly works. Rather than attacking the wallet's secure element, the add-on hardware is said to capture the recovery words on their way to the screen. Bitcoin.com News pointed out that this approach could let an otherwise authentic device pass ordinary verification checks while quietly leaking its owner's seed. A recovery phrase captured at setup can expose funds long after the compromised device is unplugged, which is why simply discarding the hardware is not enough.
Ledger has drawn a firm line between tampered devices and its own systems. "We have no indication that Ledger's security infrastructure, systems or services have been compromised," the company said. The Verge added that there is no sign that wallets bought directly from Ledger are affected, and that the problem appears concentrated among CryptoBilis customers in Southeast Asia. That distinction has not satisfied everyone. Replies under Ledger's post asked whether victims would be refunded and argued that the company bears responsibility for an authorized reseller, Bitcoin.com News reported.
The money trail is also moving. The Defiant reported that a wallet linked to the thefts routed 464 ETH to Tornado Cash through an intermediary and four deposit wallets, while the source address kept about 700 ETH. In a separate report, The Defiant said on-chain records show a 2 million USDT conversion through USDD's stability module, moving value beyond Tether's freeze controls, while Bitquery estimates Tether froze $10 million across the wider theft cluster. A separate account of the Ledger CryptoBilis losses covered the first reports, and our long read on crypto bunker mode looked at wallet security more broadly.
What's next
Ledger has repeated its advice. Buyers who obtained devices through CryptoBilis and have not set them up should "not initiate set up," and those who already have should "consider moving assets to a new Ledger signer (with a new seed)," the company said. It added that it is "working on further, enhanced anti-tampering solutions," thanked the SEAL 911 security group for its help and said it is cooperating with authorities. The Verge said Ledger has published guidance on checking a device for tampering. Ledger also reminded users that it will never ask for a 24-word recovery phrase.
The open questions are the important ones. One Ledger hardware implant has been confirmed, but investigators have not established how many other devices carry similar hardware, how directly they connect to the reported losses or who installed them. Until those answers arrive, the episode is a reminder that a hardware wallet's security depends on the chain of custody before it reaches the buyer. This article is for information only and is not security or investment advice.
This article is for information only and is not investment advice.