Author: Gu Yu, ChainCatcherA person transferred 80 bitcoins into a newly purchased Ledger. The device was bought from an officially authorized dealer, and the mnemonic phrase was handwritten and locked in a safe. This batch of coins was credited on September 29, with a purchase cost of about 5.2 million dollars, and at one point, the unrealized profit reached 1.38 million dollars. On October 9 at 05:54 (UTC), all 80 BTC were transferred in a single transaction.He did everything that the textbook required correctly.On the same morning, similar reports began to appear in large numbers on X and Reddit: a user’s Ledger Stax was transferred with nearly 100,000 USDT, with the mnemonic phrase also handwritten and locked in a safe. The common point among these users is only one—the devices were all purchased from the Southeast Asian dealer CryptoBilis.On October 9 at 13:32 (UTC), Ledger confirmed that it was investigating and requested CryptoBilis to suspend all sales and shipments of Ledger devices; users who purchased devices from this channel within the last 90 days should not initialize them if they have not been initialized yet, and those that have been initialized should immediately transfer their assets to a new device generated with a new mnemonic phrase.I. The scale of losses may exceed 90 million dollarsHow large the losses are, can only be estimated on-chain at present.On-chain investigator Specter first published ten aggregation addresses at 12:24, covering Bitcoin, Ethereum, and Tron, estimating losses exceeding 86 million dollars; another investigator, tanuki42, listed eight of those addresses, giving over 72 million dollars; SlowMist's MistTrack stated that the amount "is approaching 90 million dollars"; Bitquery covered 311 wallets, estimating about 92.9 million dollars, with approximately 42 million in Ethereum, about 17.6 million in Bitcoin, and around 16.5 million in USDT. Arkham has marked these addresses as "Ledger Theft," and as of Friday afternoon, about 71.5 million dollars remained in the marked addresses, with the largest positions including approximately 29.4 million dollars in ETH, 17.5 million dollars in BTC, 13.6 million dollars in USDD, and 10.8 million dollars in USDT.More noteworthy than the total amount is the profile of the victims. Lookonchain monitored that a certain address deposited 7 million USDT three weeks after purchasing the device, and all of it was transferred out about ten hours before the report, possibly the largest single transaction; three other marked Bitcoin addresses held a total of about 211 BTC at 13:44 (UTC), with no transfers out at that time. According to Chain INK statistics, this incident involved about 98 wallets, averaging about 890,000 dollars each.This is not just retail investors losing a few hundred dollars. This is the kind of wallet where someone put in their savings.Comparing this with another incident this year, the difference in distribution is more telling than the total amount. In July, Coldcard suffered a loss of about 111 million dollars due to a firmware random number defect that allowed the mnemonic phrase to be inferred, but it was spread across more than 5,200 wallets, averaging about 21,000 dollars each; whereas this incident with CryptoBilis, which reached second place in less than a day (about 87 million dollars), only involved about 98 wallets, averaging close to 890,000 dollars.Coldcard's incident was a wide net, while this one was precise harvesting. This distribution itself supports the inference of "implanted modules": the attacker has control over the mnemonic phrases generated on each modified device, allowing them to wait—wait until the money comes in before acting, and specifically targeting those worth attacking. The 80 BTC monitored by Lookonchain were transferred all at once after lying quietly in the device for ten days.II. After opening the device: the microcontroller on the screen ribbon cableLedger has not explained the attack mechanism, but someone has already opened the device.The most specific description comes from former Mt.Gox CEO Mark Karpelès. He stated that one device he received came from Malaysia—listed at half price on Amazon, shipped from Malaysia rather than Japan where he ordered it, which itself was the first warning sign. After opening it, he found a hidden module where the screen padding should have been: a single-strand wire of an antenna, space freed up by a shortened battery or removed screen padding, an LTE module with eSIM, and a microcontroller connected to the device's SPI bus.His judgment is that this microcontroller can recognize the font used by Ledger on the 128×64 screen, lock onto the mnemonic phrase settings interface, and display the mnemonic phrase character by character as the user writes it down, sending it out via LTE.SlowMist's Chief Information Security Officer 23pds provided the corresponding technical path: the attacker installed a microcontroller inside the device, connecting to the screen's SPI data line; after the mnemonic phrase is generated in the secure element, it is displayed on the screen for the user to write down, while the malicious module synchronously records every character output on the screen, then transmits it through the built-in LTE or eSIM. He emphasized that the role of the secure element is to prevent the private key from being directly read or exported, but it cannot control what is being displayed on the screen—the few seconds when the mnemonic phrase appears on the screen is the attack window.This explains the most counterintuitive aspect of the entire incident: these devices can pass Ledger's authenticity verification. Because the secure element is real, it does correctly generate the mnemonic phrase and does sign normally; it is just being "watched." The firmware also cannot detect it, as the implanted module only listens during screen refreshes. In other words, the only way to detect it is—by opening the device.Two other possibilities also exist: one is pre-set mnemonic phrases—attackers power on, set up, record, and repackage in advance, while users think they are "setting up a new device," but are actually using a set of words already mastered by the attacker; the other is phishing. Developer 0xQuit believes that some victims may have fallen victim to phishing, stating that it is irresponsible to simply say "Ledger was hacked."III. "Officially Authorized" endorses sales qualifications, not supply chain integrityCryptoBilis is not a street vendor.It was established in Kuala Lumpur in 2020 and is listed in black and white on Ledger's official dealer page as an officially authorized dealer, covering Malaysia, Indonesia, and the Philippines, selling not only Ledger but also Trezor, OneKey, Tangem, and SafePal.The problem lies precisely here. Users follow the security guidelines taught by the industry: if they cannot buy directly from the official website, they look for "officially authorized dealers." But the authorization endorses this company's sales qualifications, not the integrity of every device in its warehouse, nor the integrity of every employee handling and sorting them. Once a device leaves the factory, goes through logistics, passes through warehouses, is sorted, delivered to dealers, and then sent to the doorstep, any link in this chain could be intercepted, opened, and restored—the heat shrink film on Karpelès's device was intact.Once the device leaves Ledger's custody, the word "authorized" no longer provides any physical guarantee.Even more subtle is the timeline. Newly disclosed company records show that CryptoBilis was acquired in March of this year, and a person named "Jia Ming," registered in Heilongjiang Province, China, has held 100% of the company's shares since August 3. The former co-founder confirmed the acquisition in March, stating that the original shareholders subsequently withdrew from all operational, management, and administrative positions, and after the hand