OneKey founder Yishi suggests a supply chain attack involving malicious components may have caused a recent theft targeting Ledger users, potentially through interception of unencrypted recovery phrase data. Ledger is investigating a theft linked to devices sold via Southeast Asian retailer CryptoBilis, with estimated losses around $90 million. OneKey plans security improvements including encrypted recovery phrase backup and stronger vendor oversight.
A Ledger hardware wallet reseller in Southeast Asia (CryptoBilis) was sold to an individual in China's Heilongjiang Province in March 2026 under a secrecy agreement. In October, compromised Ledger Nano X devices with spy-inserted components were discovered by former Mt. Gox CEO Mark Karpelès, leading to a coordinated $86–93 million theft across multiple blockchains affecting hundreds of users. Ledger confirmed the breach was limited to the CryptoBilis distribution channel and recommended affected customers move assets to new signers.
Malaysian hardware wallet distributor CryptoBilis changed ownership in March to a person named Jiaming from Heilongjiang, China, who now holds 100% equity. The company faces scrutiny over alleged involvement in a supply chain attack on Ledger devices with hidden theft modules, though no direct link to the ownership change has been established. CryptoBilis has suspended all sales and closed stores across Malaysia, the Philippines, and Indonesia pending investigation.
SlowMist security researcher 23pds analyzed a compromised Ledger device purchased by Mark Karpelès that contained a spy module with an embedded SIM card in the screen padding. The malicious module could intercept and transmit mnemonic phrases displayed on screen via LTE, bypassing the secure element's protection of private keys.