OneKey founder Yishi suggests a supply chain attack involving malicious components may have caused a recent theft targeting Ledger users, potentially through interception of unencrypted recovery phrase data. Ledger is investigating a theft linked to devices sold via Southeast Asian retailer CryptoBilis, with estimated losses around $90 million. OneKey plans security improvements including encrypted recovery phrase backup and stronger vendor oversight.