Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
Ledger Says a CryptoBilis-Sold Device Carried a Hardware Implant. Researchers Estimate $72M to $93M Drained

Since reports of emptied Ledger wallets surfaced in early October and the Oct. 9 drain was disclosed, the question has been how a hardware wallet could leak keys. Ledger now has an answer, at least in part: physical tampering.
The company said at least one device sold through CryptoBilis contained an unauthorized hardware implant that gave attackers access to users' recovery phrases. In a 72-hour update posted on X, Ledger said all confirmed cases tied to the Oct. 9 draining incident involve devices sold by that reseller. It says its own systems and direct sales channels are unaffected.
The numbers
On-chain investigators, including Specter and MistTrack, traced funds from hundreds of victim addresses. Their estimates run from the low $70 millions to just under $93 million, across 311 to 315 wallets. These are researcher estimates, not figures Ledger has confirmed.
Roughly $70 million of the total was USDT on the Tron blockchain. Losses were also recorded on Bitcoin, Ethereum, BNB Chain, Polygon and Solana, which fits an attacker sweeping whatever the stolen seed phrases unlocked.
Tether froze approximately $10 million tied to the incident. That is a fraction of the total, and stolen Bitcoin has no issuer that can freeze it.
Ledger describes the volume of affected devices as limited. The buyers are concentrated in Indonesia, Malaysia and the Philippines, and the affected units were bought from CryptoBilis within the last three months.
Who sold the devices
CryptoBilis, based in Kuala Lumpur, was listed in Ledger's own reseller directory for those three markets and marketed itself as an authorized seller of sealed, genuine devices. It has stopped selling hardware wallets. Ledger said it asked the reseller to pause all sales and shipments pending the investigation.
Company records cited by Crowdfund Insider indicate CryptoBilis changed hands earlier this year. By early August, full ownership had passed to an individual with a registered address in China's Heilongjiang province. A former co-founder confirmed a March sale and said the original team stepped away from operations and management, adding that confidentiality restrictions limited what he could say.
No public evidence ties the ownership change to the compromised devices. The timeline of when tampered units entered CryptoBilis's stock is what investigators will need to establish.
What Ledger is telling users
Buyers from CryptoBilis should not initialize any device they have not yet set up. Those who already have should move funds to a new seed phrase generated on a device from Ledger.
Swapping the hardware alone does not fix it. The original keys stay the same and may already be compromised.
Ledger also told authorized resellers and distributors to source stock only through authorized channels and never to restock returned products. It urged users not to buy from unauthorized sellers, where it says the risk of counterfeit or modified devices is high. Ledger notes it will never call, message or ask for a 24-word recovery phrase, and it warned that scammers often exploit incidents like this one.
Ledger says it is cooperating with authorities and has asked affected users to contact Ledger Support and file complaints with local law enforcement. It thanked the SEAL 911 security group for help. It has not said which authorities are involved.
The supply chain problem
A hardware wallet's pitch is that the keys never touch anything you do not control. That holds only if the device is clean when it leaves the box.
Ledger's own statement concedes the point. The company said the incident "underscores why we continuously review and strengthen our distribution and anti-tamper processes," and that it is reviewing authorized reseller controls and advancing hardware protections. It called on other vendors and researchers to work on industry chain-of-custody and anti-tamper practices.
The case also differs from another 2026 wallet failure. Coinkite's Coldcard devices had a seed-generation flaw dating to 2021 firmware, in which some units fell back on weak software randomness. Attackers began draining Bitcoin from it in late July, taking well over $100 million. That was a software defect. This one involves a physical implant in a reseller-sold unit.
CryptoBilis was an authorized seller in Ledger's directory, yet Ledger's advice for buyers is to avoid unauthorized resellers. The company has not said whether it plans to change how it vets or monitors authorized partners.
What remains unanswered: when and where the implants were installed, whether the ownership change played any role, and how many devices beyond the confirmed cases are still in buyers' hands unopened. Ledger says its investigation is ongoing.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.