Ledger theft has hit $91 million, spanning nearly 500 addresses, and raises questions about the future of crypto self-custody. The Tron network is the hardest hit, with 276 victim addresses drained of about $64.5 million. The Bitcoin [BTC] addresses are the second most affected (276 addresses), losing $17.7 million, while the Ethereum [ETH] ecosystem suffered $8.8 million across 55 addresses. Because the impact on BNB Chain, Base, Avalanche, and other chains hasn't been fully traced, Galaxy’s head of research, Alex Thorn, viewed the $91 million as a “floor” of total theft. Simply put, the figure could rise after Ledger completes a full audit in the coming days. Ledger attacker begins laundering funds As of the 9th of October, about $73 million of the stolen funds sits in attacker-controlled wallets across Bitcoin, Ethereum [ETH], and Tron [TRX]. $3 million has been moved into Tornado Cash and other relay accounts. Some stolen USDT has been converted to USDD ($13.65 million). Surprisingly, the attacker has also moved some funds to Binance as security analysts press the exchange to freeze them. Both Binance founder Changpeng Zhao (CZ) and the current CEO Richard Teng vowed to help whenever the need arises to recover the funds. In particular, Teng said, As investigations continue, the focus must be on supporting affected users, tracing funds, and assisting recovery efforts wherever possible. Security is a shared responsibility, and Binance stands ready to support the industry's collective efforts. It remains to be seen how much will be recovered from this pledged coordinated approach. The industry is still reeling from the $114 million Coldcard hardware exploit in Q3. So, how did the Ledger attack happen, and how was it missed? Did CryptoBillis compromise Ledger users? Preliminary reports point to a supply attack that affected Ledger Nano X and Ledger Nano S Plus hardware wallets from Southeast Asian reseller CryptoBilis. According to unverified reports, this was a localized hardware tampering operation. The two models above were allegedly compromised and had spyware components that could read and send seed phrases to a server. Seed phrases are like passwords to crypto wallets. This meant the attacker could drain the funds in these devices if they aren’t in a multi-sig setup. Following these allegations, users pressed Arravind Prabu, the CEO of CryptoBillis, for answers. Strangely, Prabu defended himself by saying that he is no longer part of CryptoBillis. When asked why he didn’t publicly disclose the sale of the reseller firm, he said that they signed an NDA (non-disclosure agreement) with the Chinese buyer. The NDA would conveniently expire on October 19th, right after the attack. Reacting to the saga, Ark Invest’s head of crypto research, Lorenzo Valente, noted, This is a pretty wild story if confirmed, and highlights two things: Never buy from a reseller, even if official. Self-custody will die very quickly if nothing is done Final Summary Ledger supply chain attack has hit $91 million in losses, affecting over 470 addresses. Experts warn the increasing hardware wallet exploits could kill crypto self-custody.