Original | Odaily Azuma ==================  What has always been regarded as the "safest coin storage solution," cold wallets, is no longer safe. On the evening of October 9, on-chain detective Specter reported that multiple Ledger user wa
Original | Odaily AzumaWhat has always been regarded as the "safest coin storage solution," cold wallets, is no longer safe.On the evening of October 9, on-chain detective Specter reported that multiple Ledger user wallet theft reports had surfaced on X and Reddit. After tracking the relevant addresses, Specter discovered that the addresses involved had received funds from hundreds of wallets across multiple mainstream blockchains, including Ethereum, TRON, and Bitcoin, with total losses exceeding $86 million.From supply chain anomalies to suspected hardware implants, where is the problem?After the theft incident occurred, Ledger officially released a statement pointing the investigation towards a distributor named CryptoBilis.Ledger stated that the company is investigating a theft incident involving assets of Southeast Asian users who had previously purchased devices through the distributor CryptoBilis. Ledger has requested that the distributor suspend sales and shipments and advised users who purchased devices through this channel in the past 90 days not to initialize them; users who have already set up their devices should create new Ledger signing devices using new mnemonic phrases and transfer their assets to new wallets.More specific clues came from former Mt. Gox CEO Mark Karpelès. As early as October 8, Karpelès warned that there were counterfeit or tampered Ledger devices for sale on the market that contained hidden SIM cards capable of transmitting stolen mnemonic phrases.After the incident, Karpelès further disclosed that a Ledger hardware wallet he purchased from Malaysia had intact packaging, but a suspicious module with a SIM card chip was hidden beneath the screen padding.Slow Mist's Chief Information Security Officer 23pds speculated that attackers might intercept data displayed on the device's screen through malicious modules, recording recovery phrases when users initialize wallets or view mnemonic phrases, and then transmit the information via LTE or eSIM.The danger of such attacks lies in the fact that they may bypass users' conventional understanding of hardware wallet security. The secure element of a hardware wallet can protect private keys from being directly read, but it may not necessarily prevent external hardware from intercepting screen information. In other words, even if the core secure element has not been compromised, physical tampering with the device can still lead to mnemonic phrase leakage.However, the aforementioned attack mechanism remains a technical speculation, and the specific cause of this security incident is yet to be further verified. Another viewpoint suggests that the attackers chose to act yesterday precisely because Karpelès's warning was gradually spreading, and the attackers, fearing their actions had been exposed, began to move funds.If this attack path is ultimately confirmed, then the issue exposed by this incident is not just a security problem with a particular wallet, but a more fundamental risk: how safe can self-custody be when users cannot confirm that the hardware in their hands has remained trustworthy from factory to delivery?Lamborghini, confidentiality restrictions, change of ownership... CryptoBilis is full of doubtsAs the investigation deepens, the background of the involved distributor CryptoBilis is gradually coming to light.CryptoBilis is a Web3 e-commerce and self-custody tool seller located in Petaling Jaya, Malaysia, with business including hardware wallets and other products. According to public information, the company was co-founded by Arravind Prabu and Vimal Selvamany, with the former serving as CEO and the latter as CTO.However, after the incident drew attention, Arravind Prabu quickly clarified on X that the claim that he was still operating CryptoBilis was inaccurate. The company had been acquired as early as March of this year, and the original management team had exited all operational, management, and system permissions. Regarding the current incident, he suggested that the public contact a current responsible person, Nicholas Chang (nicholas@cryptobilis.com).Community users immediately continued to question why, since the company had changed ownership, there had been no public announcement, and the account's most recent post even showcased a Lamborghini... Arravind Prabu responded that the post was made by the new management team, and the original team had to wait until October 19 to publicly announce the transaction due to confidentiality clauses in the contract, and they currently no longer have access to the company's account, backend, and operational systems.The original management team has exited operations, which is the former CEO's public statement; however, there is still a lack of independently verified information regarding what exactly happened within the company after the handover.Another more concerning clue comes from the company's equity. Bitcoin News reported after the incident that relevant equity transfer records show that an individual named JIAMING, registered at an address in Heilongjiang Province, China, has held 100% of CryptoBilis's shares since August 3.This means that at least from public information, CryptoBilis indeed changed ownership months before the suspected supply chain attack occurred. However, there is currently no conclusive evidence to confirm the specific transaction arrangements for the equity change, the actual operational situation of the new management team, or whether the new shareholder is related to the involved devices. One cannot directly link the new shareholder's registered address or acquisition time to the theft incident.In response to the investigation, CryptoBilis has publicly announced through its official X account the suspension of hardware wallet sales and shipments at all stores and online channels in Malaysia, the Philippines, and Indonesia, with physical stores temporarily closed. The company stated that this move aims to cooperate with the Ledger security incident investigation and accept independent experts' review of internal processes; unfulfilled orders will be actively handled by customer service, and further progress is expected to be announced within three working days.As of the publication of this article, the most critical questions of the incident remain unanswered------at which stage was the device tampered with, whether the original supply chain was exploited, and whether the current management team can provide records sufficient to reconstruct the delivery process------these questions await further investigation and disclosure for answers.Individual loss cases: A major user just bought a wallet a week ago...From the current on-chain tracking situation, the losses from this incident are not only staggering, but the flow of funds also shows different characteristics.Alex Thorn, head of research at Galaxy, analyzed that the Bitcoin losses related to this Ledger and CryptoBilis supply chain incident currently amount to 213.42 BTC, worth approximately $17.7 million at the time. Of this, about 92% of the Bitcoin was held for less than 90 days when it was aggregated. The related BTC currently tracked has not yet been spent and is concentrated in three aggregation addresses.The losses of individual victims are even more shocking. Lookonchain monitoring indicated that a user marked with the address TY24Ya purchased the relevant Ledger device three weeks ago and subsequently deposited 7 million USDT into the wallet, but this fund was entirely transferred away within about 10 hours; another user bought 80 BTC for approximately $5.2 million four months ago, at one point showing a profit of about $1.38 million, but after purchasing a Ledger device from CryptoBilis a week ago, transferred all BTC into that device, ultimately suffering a total loss.Can the funds be recovered?Shortly after the incident occurred, the attackers quickly began the money laundering and mixing process.On-chain analysis firm Onc