A supply chain attack on an official Ledger reseller led to roughly $90 million in stolen crypto assets. Victims' seed phrases were all handwritten, and attackers implanted a hardware module to steal what was displayed on the screen, extending the cold storage security boundary from the chip to the logistics chain.

A person transferred 80 BTC into a newly purchased Ledger. The device was bought from an official authorized reseller, and the seed phrase was handwritten and locked in a safe. The coins only arrived on September 29, with a purchase cost of about $5.2 million and an unrealized profit of $1.38 million at one point. On October 9 at 05:54 (UTC), all 80 BTC were moved out in a single transaction.

He did everything the textbook requires.

That same morning, a flood of similar reports began appearing on X and Reddit: one user's Ledger Stax had nearly 100,000 USDT moved out, with the seed phrase likewise handwritten and locked in a safe. The one thing these users had in common was— the devices were all purchased from the Southeast Asian reseller CryptoBilis.

On October 9 at 13:32 (UTC), Ledger confirmed it was investigating and asked CryptoBilis to suspend all sales and shipments of Ledger devices; users who had purchased devices from this channel within 90 days and had not yet initialized them should not initialize them, and those who had already initialized them should immediately move their assets to a new device generated with a new seed phrase.

How big the losses actually are can only be estimated on-chain for now.

On-chain investigator Specter was the first to publish ten consolidation addresses at 12:24, covering Bitcoin, Ethereum and Tron, estimating losses exceeding $86 million ; another investigator, tanuki42, listed eight of those addresses, giving over $72 million ; MistTrack under SlowMist said the figure was "approaching $90 million"; Bitquery covered 311 wallets, estimating about $92.9 million , of which roughly $42 million was Ethereum, $17.6 million Bitcoin, and $16.5 million USDT. Arkham has labeled these addresses as "Ledger Theft," and as of Friday afternoon, about $71.5 million remained in the labeled addresses, with the largest positions including roughly $29.4 million in ETH, $17.5 million in BTC, $13.6 million in USDD and $10.8 million in USDT.

More telling than the total is the victim profile. Lookonchain monitored that one address deposited 7 million USDT three weeks after purchasing a device, and it was all moved out about ten hours before the report—possibly the largest single loss in this incident; three other labeled Bitcoin addresses held about 211 BTC in total at 13:44 (UTC), with no outflows at that time. According to Chain INK statistics, this incident involved about 98 wallets, averaging about $890,000 each.

This is not retail users losing a few hundred dollars. These are the kind of wallets where people put their life savings.

Compare it with another incident this year, and the difference in distribution says more than the total. In July, Coldcard's firmware random number flaw made seed phrases guessable, causing losses of about $111 million, but spread across more than 5,200 wallets, averaging about $21,000 each; the CryptoBilis incident ranked second (about $87 million) in less than a day, yet involved only about 98 wallets, averaging close to $890,000.

The Coldcard case was casting a wide net; this one was precision harvesting. This distribution itself supports the "implanted module" inference: the attacker holds the seed phrases generated on every tampered device, so they can wait—wait for money to come in before acting, and specifically pick the ones worth acting on. The 80 BTC that Lookonchain monitored was moved out in one go after lying quietly in the device for ten days.

Ledger has not yet explained the attack mechanism, but someone has already opened a device up.

The most specific description comes from former Mt.Gox CEO Mark Karpelès. He said a device he received came from Malaysia—listed on Amazon at half price and shipped from Malaysia rather than the Japan he ordered from, and that shipping origin was itself the first warning sign. After opening it, he found a hidden module where the screen padding should have been: a single-strand antenna wire, space freed up by a shortened battery or removed screen padding, an LTE module with an eSIM, and a microcontroller connected to the device's SPI bus.

His assessment: this microcontroller can recognize the font Ledger uses on its 128×64 screen, lock onto the seed phrase setup interface, and send the seed phrase—displayed character by character as the user copies it down—as text via LTE.

SlowMist Chief Information Security Officer 23pds gave the corresponding technical path: the attacker installs a microcontroller inside the device and taps into the screen's SPI data line; the seed phrase is generated inside the secure element and then displayed on the screen for the user to copy, while the malicious module simultaneously records every character output to the screen and transmits it via built-in LTE or eSIM. He emphasized that the secure element's role is to prevent the private key from being directly read or exported, but it cannot control what is being displayed on the screen—the few seconds when the seed phrase appears on the screen are the attack window.

This explains the most counterintuitive point of the whole incident: these devices can pass Ledger's authenticity verification. Because the secure element is genuine—it correctly generates the seed phrase and correctly signs—it is simply being "watched." The firmware likewise cannot detect it, because the implanted module only listens when the screen refreshes. In other words, the only way to detect it is—to open the device up.

Two other possibilities also exist: one is a pre-set seed phrase—the attacker powers on the device in advance, sets it up, copies the phrase, and reseals it, so the user thinks they are "setting up a new device" but is actually using a phrase the attacker already holds; the other is phishing. Developer 0xQuit believes some victims may have fallen to phishing, saying it is irresponsible to directly claim "Ledger was hacked."

CryptoBilis is not some fly-by-night stall.

Founded in Kuala Lumpur in 2020, it is an official authorized reseller listed in black and white on Ledger's reseller page, covering Malaysia, Indonesia and the Philippines, and besides Ledger it also sells Trezor, OneKey, Tangem and SafePal.

The problem lies precisely here. Users follow the security rules the industry has taught them: if you can't buy directly from the official site, find an "official authorized reseller." But the authorization vouches for the company's reseller qualification, not the integrity of every device in its warehouse, nor every employee who handles sorting. A device leaves the factory, goes through logistics, warehouses, sorting, the reseller, and finally to your door—any link in this chain can be intercepted, opened, and restored—the shrink wrap on Karpelès's device was intact.

Once a device leaves Ledger's custody, the word "authorized" no longer provides any physical guarantee.

More subtle is the timeline. Newly disclosed company records show that CryptoBilis was acquired in March of this year, and a person named "Jiaming" with a registered address in Heilongjiang Province, China, has held 100% of the company's equity since August 3. A former co-founder confirmed the March acquisition, saying the original shareholders withdrew from all operational, management and administrative roles afterward, and that after the handover they could no longer understand the company's actual operations, urging the current management to handle the matter transparently. According to a report by Shenchao TechFlow, a non-disclosure agreement signed between the acquirer and former executives restricts them from disclosing transaction details, valid until October 19— when the incident erupted on October 9, the former executives were still legally unable to freely disclose the acquisition details.

There is currently no conclusive evidence linking the equity change to the device theft , and Ledger has only halted sales without making any accusation.

On October 10, CryptoBilis announced the suspension