Prices: CoinGecko (opens in a new tab)

Security

The Ledger reseller drains: what we know about the tampered-device reports, and how to buy a hardware wallet safely

Ledger is investigating wallet drains tied to devices sold by reseller CryptoBilis and confirmed one hidden implant. What we know and how to buy safely.

Beginner7 min readPublished October 10, 20269 sources
On this page
  1. What happened
  2. What Ledger says, and does not say
  3. How a hidden implant could steal a seed phrase
  4. If you bought a device from CryptoBilis
  5. How to buy a hardware wallet safely
  6. The bigger picture

Key takeaways

  • Ledger is investigating drained wallets among Southeast Asian customers who bought devices through CryptoBilis, a reseller Ledger listed as authorized, and on October 10 confirmed that one affected user's device contained an unauthorized hardware implant.
  • Ledger says it has no indication its own systems were compromised and, as of October 2026, had no reports involving devices bought directly from Ledger. Loss estimates of $72 million to more than $90 million come from on-chain researchers and are unconfirmed.
  • The lowest-risk way to buy any hardware wallet is from the manufacturer's own store, then to inspect the packaging, run the genuine check, reject any pre-written recovery phrase and create a brand-new seed yourself.

On October 9, 2026, people in Southeast Asia began reporting that their Ledger hardware wallets had been emptied. The common thread so far is a single reseller, and the next day Ledger confirmed it had found a hidden implant inside one affected device. Here is what is confirmed, what is still a theory, and what it means for how you buy a hardware wallet.

What happened

On-chain researchers raised the alarm first. Researcher tanuki42 traced more than $72 million to wallets suspected of receiving stolen funds, and another researcher, Specter, put the total above $86 million across Bitcoin, Ethereum and Tron, according to The Block. Later tallies from Yfarmx and Bitquery, reported by Bitcoin.com News, went above $90 million. Ledger has not confirmed any of these figures, and the researchers' totals may overlap rather than add up.

The same day, Ledger's support account said it was investigating reports of lost funds from Southeast Asian customers who had bought devices from a reseller called CryptoBilis. Ledger said it had asked CryptoBilis to pause all sales and shipments of Ledger devices while it looked into the reports. Both The Block and Gizmodo report that Ledger's official reseller directory showed CryptoBilis as an authorized seller covering Indonesia, Malaysia and the Philippines.

On October 10, Ledger posted an update: one impacted user's device "contained an unauthorized hardware implant." Bitcoin.com News reported that the update also said CryptoBilis had stopped selling all of its hardware wallet inventory until the investigation ends, that Ledger was working with authorities and the volunteer security group SEAL 911, and that it was developing further anti-tampering measures.

What Ledger says, and does not say

Ledger told customers it believes the drained funds are limited to devices sold through CryptoBilis, and that it has "no indication" its own security infrastructure, systems or services were compromised. The company also told TheStreet it had no reports involving products bought directly from Ledger.

Several important points remain open as of October 10, 2026:

  • Where the tampering happened. Ledger has not said who altered the device it examined or at what point in the supply chain. Gizmodo notes that Ledger has made no accusation of tampering against CryptoBilis, and that a third party could have altered units at some point along that sales route.
  • How many devices were affected. One implant is confirmed. Whether it explains every reported loss is not.
  • The final loss figure. The dollar totals so far are estimates from blockchain analysts, not numbers from Ledger.

How a hidden implant could steal a seed phrase

The most detailed public description came from Mark Karpelès, the former head of the Mt. Gox exchange, who had already been studying altered Ledger devices. He shared photos of a unit that, by his account, arrived from Malaysia in perfect shrink wrap. Behind the display, in the space normally filled by a foam pad, sat a second circuit board, with an antenna and a cellular (LTE) module, Gizmodo reported. Karpelès later said on X that he bought that unit cheaply from a seller on Amazon Japan that Ledger had not authorized, not from CryptoBilis. He also said photos shared by CryptoBilis buyers showed the same kind of implant, a comparison Ledger has not confirmed.

According to Karpelès, the add-on board watches what the screen displays. When a new owner sets up the wallet, the device shows the seed phrase so you can write it down, and the implant can read those words and send them out over the mobile network. Anyone holding those words can rebuild the wallet elsewhere and move the funds.

The worrying part is that this kind of attack would leave the device's secure element untouched. Ledger explains that its secure chip checks the device's other processor at startup and warns you if that code has been changed. An extra board that only listens to the screen would not trigger that check, which is why Karpelès argues firmware cannot detect it. Ledger's own integrity guide goes further, stating that the genuine check cannot catch implants of this kind if the original secure chip is intact. The guide shows official photos of the internal layout for comparison, but warns that any damage caused while opening a device voids the warranty, and it strongly discourages owners from taking apart a Ledger Stax themselves.

If you bought a device from CryptoBilis

Ledger's advice, as of October 10, 2026, is simple:

  1. Not set up yet? Do not set it up. Ledger asks buyers from the last 90 days to leave unused devices uninitialized.
  2. Already using it? Ledger suggests moving your assets to a new Ledger device with a new seed phrase. Generate that phrase on the new device; never reuse the old one.
  3. Get help only through official channels. Ledger says it will never ask for your 24-word recovery phrase. Expect fake "Ledger support" messages and fake refund offers to follow a story like this.

How to buy a hardware wallet safely

A hardware wallet can only protect you if nobody has interfered with it before it reaches your hands. These habits cut that risk sharply.

  • Buy from the manufacturer's own store first. Type the maker's web address yourself rather than clicking an ad or search result. Ledger's own guidance recommends its official shop or its authorized retail network and says buying from unlisted sellers is strongly discouraged.
  • If you use a reseller, check the maker's own list. Confirm the seller appears on the reseller page of the manufacturer's official website, not just on the seller's own site. This incident shows the list is a minimum standard, not a guarantee, so buying direct is the safer choice when it is available to you.
  • Skip marketplaces and secondhand devices. Avoid auction sites, classifieds, social media sellers and any listing priced well below the official store. A used or discounted device may have been opened, swapped or pre-configured.
  • Inspect the packaging. Check the seals and packaging against the maker's description, and contact official support if anything looks opened, glued or reworked. Remember that good shrink wrap alone does not prove a device is clean.
  • Run the genuine check. Use the maker's official app to confirm the device is authentic, and update its firmware only through that app. Treat a pass as one check among several.
  • Reject any pre-written seed. A genuine device never arrives with recovery words already printed or filled in, and never asks you to use a phrase that came in the box. If yours does, stop and contact the maker.
  • Create a new seed yourself. Set up the device as a new wallet, write the words by hand in private, and confirm the backup. Our seed phrase guide walks through it.

The bigger picture

Hardware wallets remain one of the strongest ways to hold your own keys, and nothing reported so far shows a flaw in how Ledger devices work when they are untouched. What this case highlights is trust in the delivery path. An "authorized" label describes a business relationship, not the condition of a specific box, and the fewer hands a device passes through, the fewer chances someone has to alter it.

Compare models and their buying options in our hardware wallet comparisons, and if you are new to self-custody, start with crypto wallets explained. We will update this post as Ledger publishes findings. Details are as of October 10, 2026.

Frequently asked questions

Was Ledger itself hacked?

Based on what Ledger has said as of October 10, 2026, no. The company says it has no indication that its security infrastructure, systems or services were compromised, and the reported losses are tied to devices sold through one reseller in Southeast Asia.

I bought my Ledger from CryptoBilis. What should I do?

Ledger advises anyone who bought from that reseller in the last 90 days not to set the device up. If you already did, it suggests moving your assets to a new Ledger device with a new recovery phrase. Contact Ledger only through its official support site.

Is buying from an authorized reseller still safe?

Authorized resellers are generally far safer than marketplaces or secondhand sellers, but this case shows the list is not a guarantee. Buying straight from the manufacturer's own store removes one link in the chain, which is why we treat it as the first choice.

Would the genuine check have caught an implant?

Not if the implant left the secure chip alone. Ledger's genuine check proves the device's secure chip is authentic, but Ledger states the check cannot spot physical tampering, such as a spying implant, as long as the original secure chip is still in place. Researcher Mark Karpelès says the board in the device he examined reads what the screen displays without touching that chip. Ledger's own support page suggests opening the device to look for extra chips if you have doubts.

Sources

  1. Ledger Support statement on reported loss of funds from CryptoBilis buyers (October 9, 2026) (opens in a new tab) — Ledger Support on X
  2. Ledger Support situation update confirming an unauthorized hardware implant (October 10, 2026) (opens in a new tab) — Ledger Support on X
  3. Check hardware integrity (opens in a new tab) — Ledger Support
  4. Ledger investigates wallet drains involving CryptoBilis buyers; estimate tops $86 million in losses (opens in a new tab) — The Block
  5. Ledger asks users to take urgent action amid $86M exploit report (opens in a new tab) — TheStreet (via Yahoo Finance)
  6. Ledger Confirms Hidden Hardware Implant in Affected User's Wallet (opens in a new tab) — Bitcoin.com News
  7. Ledger's Crypto Wallets Reportedly Backdoored, $71 Million in Crypto Already Moved (opens in a new tab) — Gizmodo
  8. Mark Karpelès on where he bought his implanted Ledger Nano X (October 10, 2026) (opens in a new tab) — Mark Karpelès on X
  9. Review and analysis of fake Trezor cryptowallet (opens in a new tab) — Kaspersky

Published October 10, 2026 by . Educational content, not financial, legal or tax advice. Spot an error? Request a correction.

About the author

Dave McNaught has worked in IT since 1999 and founded All Business Technologies (ABT) in 2003, a Boston-area firm providing Managed IT, Cybersecurity, Managed AI, Web Design and App Development. He publishes The Crypto Guide.