Ledger wallet thefts approach $90 million as Tether freezes USDT, reseller investigated

Crypto hardware wallet maker suspects supply chain attack through authorized Southeast Asian distributor CryptoBilis

By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
Ledger is investigating reports that customers lost funds totalling nearly $90 million after purchasing devices from CryptoBilis, an authorised reseller in Southeast Asia, as Tether moves to freeze USDT stablecoin linked to the incident.

In an Oct. 9 statement, the crypto hardware wallet maker said it was probing claims that customers suffered losses after buying devices from the distributor, which appears in Ledger's official reseller directory for Malaysia, Indonesia and the Philippines. Ledger asked CryptoBilis to immediately pause sales and shipments while the investigation continues.

The company advised anyone who purchased a device from CryptoBilis in the past 90 days not to initialise it if setup is incomplete, and urged customers who have already configured their wallets to consider transferring cryptocurrency to a new Ledger device created with a fresh recovery phrase.

Binance founder Changpeng Zhao warned users to be cautious. "Based on information so far, it seems to be localized to a supply chain attack with one vendor," he wrote on X, while calling for industry-wide cooperation to trace and recover stolen assets. "I expect and know all BNB ecosystem players (and all industry) to help trace and recover the funds."

Former Mt. Gox CEO Mark Karpelès has asked CryptoBilis to open some of its unsold Ledger wallets so their circuit boards can be inspected for possible spying implants or other unauthorised modifications. His concern highlights a recognised gap in Ledger's security: the company's own documentation notes that its Genuine Check system verifies a device's Secure Element but cannot necessarily identify physical modifications elsewhere in the hardware if the original security chip remains intact.

§

Analysis

Why This Matters

  • The incident threatens confidence in hardware wallets, which rely on physical security to protect private keys; a supply chain compromise could erode trust in the entire ecosystem.
  • Cryptocurrency users in Southeast Asia may be directly affected if they bought from CryptoBilis, and the scale of losses approaching $90 million underscores the risk even with authorised resellers.
  • The response from Tether's freeze and industry calls for fund recovery signals potential escalation if attackers are identified, which could lead to legal or enforcement actions.

Background

Ledger is one of the most widely used hardware wallet manufacturers, providing offline storage for cryptocurrency private keys. Supply chain attacks against hardware wallets have been a theoretical risk for years; this case involves an authorised distributor, meaning devices went through official channels. The incident draws parallels to earlier tampering scares and highlights the difficulty of verifying hardware integrity beyond the Secure Element.

Key Perspectives

Ledger: The company has acted quickly to pause sales from the suspect reseller and is investigating, advising affected customers to move funds to a fresh device. It has not confirmed the exact cause but describes the situation as a suspected supply chain attack. Changpeng Zhao (Binance): He emphasises the incident appears localised to one vendor and calls for industry cooperation to trace and recover funds, positioning his ecosystem as a willing partner. Mark Karpelès and security researchers: They are pushing for physical inspection of unsold devices to determine whether malicious hardware components were inserted, pointing out that Ledger's genuineness checks may miss after-market modifications.

What to Watch

  • Whether inspections of unsold CryptoBilis units reveal hardware tampering and identify the point of compromise.
  • Ledger's next public update on the investigation and any changes to its reseller verification process or hardware authentication.
  • Any legal action or charges brought against individuals if fund tracing leads to the attackers.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe