BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Lamborghini, NDA, Heilongjiang Boss… The Ledger Hack Is Full of Suspicious Details

Azuma
Odaily资深作者
@azuma_eth
This article is about 3356 words, reading the full article takes about 5 minutes
Cold wallets are no longer an absolutely safe option.
AI Summary
Expand
  • Key Takeaways: Ledger cold wallet users lost over $86 million in a suspected supply chain attack. The attacker may have implanted malicious modules into devices through distributor CryptoBilis to steal seed phrases, raising fundamental questions about the security of hardware wallet self-custody.
  • Key Elements:
    1. Over $86 million was stolen from hundreds of wallets across Ethereum, TRON, Bitcoin and other chains, involving distributor CryptoBilis.
    2. Former Mt. Gox CEO disclosed that counterfeit Ledger devices had a SIM card module hidden beneath the screen pad, capable of intercepting seed phrases and transmitting them via LTE.
    3. CryptoBilis changed ownership in March this year, and since August, an individual from Heilongjiang, China has held 100% of its shares. Former management cited confidentiality clauses as the reason for not disclosing this.
    4. One user deposited $7 million in USDT and had it all transferred out within approximately 10 hours; another user bought BTC with $5.2 million and suffered a total loss.
    5. The attacker has laundered 430 ETH through Tornado Cash. After Tether froze some USDT, the hacker quickly converted to USDD.
    6. Bitcoin losses currently stand at 213.42 BTC (approximately $17.7 million), with 92% held for less than 90 days, concentrated in 3 aggregation addresses.

Original | Odaily (@OdailyChina)

Author|Azuma (@azuma_eth)

The cold wallet, long regarded as the "safest way to hoard coins," is no longer safe either.

On the evening of October 9, on-chain detective Specter posted that multiple reports of Ledger user wallets being compromised had been observed on X and Reddit. After tracing the relevant addresses, Specter found that the addresses involved had received funds from hundreds of wallets across multiple mainstream blockchains including Ethereum, TRON, and Bitcoin, with cumulative losses exceeding $86 million.

From Supply Chain Anomalies to Suspected Hardware Implants: Where Did the Problem Originate?

After the theft incident, Ledger officially issued a statement pointing its investigation toward a distributor named CryptoBilis.

Ledger stated that the company is investigating an asset theft incident involving Southeast Asian users, who had previously purchased devices through the distributor CryptoBilis. Ledger has asked the distributor to suspend sales and shipments, and advised users who purchased devices through this channel within the past 90 days not to initialize them; users who have already completed setup should create a new Ledger signing device using a new mnemonic phrase and transfer assets to the new wallet.

More specific leads came from former Mt. Gox CEO Mark Karpelès. As early as October 8, Karpelès had warned that someone on the market was selling counterfeit or tampered Ledger devices with hidden SIM cards, which could transmit stolen mnemonic phrases.

After the incident, Karpelès further disclosed that a Ledger hardware wallet he purchased from Malaysia had intact packaging, but a suspicious module with a SIM card chip was hidden beneath the screen padding.

SlowMist Chief Information Security Officer 23pds speculated that attackers may have intercepted data displayed on the device screen through malicious modules, recording the recovery phrase when users initialized their wallets and viewed their mnemonic phrases, then transmitting the information out via LTE or eSIM.

The danger of such attacks lies in the fact that they may bypass users' conventional understanding of hardware wallet security. A hardware wallet's secure element can protect private keys from being directly read, but it may not necessarily prevent peripheral hardware from intercepting screen information. In other words, even if the core secure element has not been compromised, physical tampering with the device can still lead to mnemonic phrase leakage.

However, the above attack mechanism remains a technical speculation, and the specific cause of this security incident still awaits further verification. Another view holds that the reason attackers chose to act yesterday was precisely because Karpelès's warning was gradually spreading, and the attackers, fearing their operation had been exposed, began moving funds.

If this attack path is ultimately confirmed, then what this incident exposes is not just the security problem of a particular wallet, but a more fundamental risk: when users cannot confirm that the hardware in their hands remains trustworthy from factory to delivery, how secure can self-custody really be?

Lamborghinis, Confidentiality Restrictions, Equity Transfer... CryptoBilis Is Full of Suspicious Points

As the investigation deepened, the background of the distributor involved, CryptoBilis, gradually came to light.

CryptoBilis is a Web3 e-commerce and self-custody tool vendor located in Petaling Jaya, Malaysia, with a business that includes products such as hardware wallets. According to public information, the company was co-founded by Arravind Prabu and Vimal Selvamany, with the former serving as CEO and the latter as CTO.

But after the incident drew attention, Arravind Prabu quickly clarified on X that claims he was still operating CryptoBilis were inaccurate. The company had been acquired as early as March this year, and the original management team had exited all operational, managerial, and system permissions. For the current incident, he suggested that the public contact a current person in charge, Nicholas Chang (nicholas@cryptobilis.com).

Community users then continued to press further: since the company had already changed hands, why was there no public announcement earlier, and why was the account's most recent post even still showing off a Lamborghini... Arravind Prabu responded that the post was published by the new management team, and that due to confidentiality clauses in the contract, the original team had to wait until October 19 to publicly announce the transaction, and currently no longer has access to the company's accounts, backend, or operating systems.

That the original management has exited operations is the former CEO's public statement; as for what exactly happened inside the company after the handover, independently verifiable information is still lacking.

Another lead that has drawn more attention comes from the company's equity. After the incident, Bitcoin News disclosed that relevant equity transfer records show that an individual named JIAMING, with a registered address in Heilongjiang Province, China, has held 100% of CryptoBilis's shares since August 3.

This means that, at least from public information, CryptoBilis did indeed change hands on paper several months before the suspected supply chain attack occurred. However, the specific transaction arrangements for the equity change, the actual operations of the new management, and whether the new shareholder is connected to the devices involved all currently lack conclusive evidence for confirmation. One cannot directly link the new shareholder to the theft incident based merely on the registered address or the timing of the acquisition.

In response to the investigation, CryptoBilis has publicly announced through its official X account that it is suspending hardware wallet sales and shipments across all stores and online channels in Malaysia, the Philippines, and Indonesia, with physical stores temporarily closed. The company said this move is intended to cooperate with the Ledger security incident investigation and to accept review of its internal processes by independent experts; orders not yet delivered will be handled through proactive contact by customer service, and further updates are expected within three business days.

As of publication, the most critical questions in this incident remain unresolved—at which point the devices were tampered with, whether the original supply chain was exploited, and whether the current management team can provide records sufficient to reconstruct the delivery process—all of which require subsequent investigation and disclosure to answer.

Individual Loss Cases: One Whale Had Just Bought a Wallet a Week Ago...

Based on current on-chain tracking, the losses in this incident are not only staggering in scale, but the fund flows also exhibit different characteristics.

Galaxy research head Alex Thorn analyzed that Bitcoin losses related to this Ledger and CryptoBilis supply chain incident currently amount to 213.42 BTC, worth about $17.7 million at the time. Of that, about 92% of the Bitcoin had been held for less than 90 days when it was consolidated. The related BTC traced so far remains unspent, concentrated in 3 consolidation addresses.

The losses suffered by individual victims are even more shocking. Lookonchain monitoring showed that a user with an address labeled TY24Ya purchased the relevant Ledger device three weeks ago and subsequently deposited 7 million USDT into the wallet, but the funds were all transferred out within about 10 hours; another user bought 80 BTC for about $5.2 million four months ago, at one point enjoying unrealized gains of about $1.38 million, but after purchasing a Ledger device from CryptoBilis a week ago, transferred all BTC to that device and ultimately suffered a total loss.

Can the Funds Still Be Recovered?

Shortly after the incident, the attackers quickly began the money laundering and mixing process.

On-chain analytics firm Onchain Lens tracked that the suspected attackers had deposited 430.2 ETH, worth about $1.07 million, into Tornado Cash through 4 wallets, in an attempt to sever the tracing chain on Ethereum.

At the same time, the industry also began to "encircle" the attackers' stolen funds. Tether has currently frozen some USDT related to this incident, but the hackers' response was equally cunning and professional. After Tether took action, they quickly used the SUN.io and USDD PSM mechanisms in the TRON ecosystem to instantly swap the unfrozen USDT into the more censorship-resistant decentralized stablecoin USDD, and some transfers also involved Binance hot wallets (which may become a clue for later identifying the hackers).

At present, the key to recovering the funds lies in whether funds still held on centralized platforms or in freezable stablecoin addresses can be identified and intercepted in time. For assets that have already entered mixing protocols, cross-chain transfers, or other complex paths, the difficulty of tracking and recovery may rise further.

As of now, Ledger has not published a complete fund recovery plan, nor has it disclosed victim compensation arrangements. As the investigation progresses, whether the assets can be recovered and who bears responsibility still remain to be further confirmed.

Cold Wallets Are No Longer an Absolutely Safe Answer

For a long time, cold wallets have been regarded as one of the most reliable solutions for self-custody of crypto assets, and Ledger is the most representative brand in this market. Compared with exchange custody, users holding their own private keys was originally intended to reduce dependence on third parties. But this incident raises an unsettling question—if the device a user purchases is physically tampered with before delivery, then even if the packaging is intact and the core secure element is not compromised, the assets may still be at risk.

Of course, the specific attack path of the incident has not yet been definitively confirmed, and it cannot be used to deny the overall security of hardware wallets. But it at least reminds users that security depends not only on the device itself, but also on the purchase channel, the initialization process, and how the mnemonic phrase is safeguarded.

When risk may begin at the very source of the supply chain, even the seemingly safest self-custody solution can fail. This time, it truly was impossible to guard against.

wallet
Safety
BTC
stable currency
USDT
Welcome to Join Odaily Official Community