OneKey founder points to supply chain attack in Ledger theft case
Yishi, founder of hardware wallet maker OneKey, said a recent theft targeting Ledger users may have involved a supply chain attack in which malicious components were inserted into devices. In a post on X, Yishi said one likely cause was the interception of unencrypted data while a recovery phrase was being displayed on screen. Yishi stressed, however, that any link between that attack method and the latest incident has not been confirmed. Yishi added OneKey plans to soon introduce a backup feature that does not display recovery phrases on screen and instead uses encrypted communication to counter similar attacks. The company is also pursuing encryption for internal device communications, stronger tamper-evident packaging, and tighter oversight of vendors. Ledger previously said it was investigating a theft case tied to devices sold through Southeast Asian retailer CryptoBilis. On-chain analysts estimate the losses at around $90 million.