Ledger said one affected user's device from reseller CryptoBilis contained an unauthorized hardware implant. Onchain analysts estimate losses between $72 million and $93 million, though Ledger has confirmed none of those figures.
Ledger said on Oct. 10 that one affected user's device contained an "unauthorized hardware implant," as it investigates fund losses among Southeast Asian customers of reseller CryptoBilis. The update did not identify the device model or explain how the implant worked, so its role in the losses remains unresolved.
Ledger also said CryptoBilis confirmed it stopped selling all hardware wallet inventory until the investigation concludes. That goes beyond Ledger's Oct. 9 request, which covered Ledger devices only.
What buyers are told to do
Customers who bought a Ledger device from CryptoBilis should not begin setup if they have not already done so, Ledger said. Those who have set up their devices should consider moving assets to a new Ledger device with a new seed phrase.
CryptoBilis is an authorized reseller operating in Indonesia, Malaysia, and the Philippines. Ledger says its own systems and the devices it sells directly have not been compromised.
Alleged spy board and estimated losses
The tampering theory began on social media. Photos and videos on X and Threads appear to show a small circuit board under the device's screen, reportedly with an embedded SIM card that relays captured data to an attacker.
The dollar figures come from onchain analysts, not Ledger. Specter and tanuki42 put losses between $72 million and $93 million, while Arkham Intelligence tracked around $87 million at one point. Tether froze approximately $10 million in USDT linked to some of the alleged theft addresses.
As of October 10, 2026, no definitive link had been confirmed between the alleged tampering and CryptoBilis. Ledger warned that scammers may try to exploit the incident, adding: "Ledger will never ask for your 24-word recovery phrase," it said.
Sources: The Defiant, Crypto Briefing
Trading involves risk.