Ledger is investigating reports that tampered hardware wallets sold through reseller CryptoBillis were used to steal more than $86 million in cryptocurrency from hundreds of users. The company has asked CryptoBillis to pause all wallet sales while it looks into the matter, and it says there is no indication that Ledger's own systems or devices bought directly from the company were affected.
Ledger confirmed that one impacted user's device contained an unauthorized hardware implant. Photos and videos posted online show a small circuit board tucked under the screen, which allegedly intercepts whatever is displayed—including the seed passphrase shown during setup—and sends that data back to the attacker using an embedded SIM card.
The incident appears to be a supply-chain attack concentrated on customers in Southeast Asia who purchased through CryptoBillis. Ledger has published guidance on how to check wallets for signs of tampering, but the company has not yet disclosed the full scope of the investigation.