Key Notes
- Ledger has confirmed an unauthorized hardware implant in one affected user’s device, but has not disclosed its model or established the full scope of tampering.
- CryptoBilis has halted all hardware-wallet sales, while Ledger advises its customers to defer setup or consider a new signer with a new seed.
- The company reports no indication that its own systems or services were compromised, and has not confirmed the analysts’ aggregate loss estimates.
Ledger has confirmed that one device belonging to a user affected by the ongoing wallet-theft investigation contained an unauthorized hardware implant. The October 10 update establishes physical tampering in an affected user’s device, as investigators examine reports involving reseller CryptoBilis.
CryptoBilis has stopped selling its entire hardware-wallet inventory until the investigation concludes, Ledger said. The manufacturer is contacting affected users, coordinating with the reseller and working with authorities, with investigative support from security response group SEAL 911.
The finding is narrower than confirmation of a breach across Ledger’s product range. The company has not disclosed the implanted device’s model, explained its technical operation or established how many units were modified. It says it has no indication that its own security infrastructure, systems or services have been compromised.
Ledger confirms an unauthorized hardware implant in one affected user’s device and updates its guidance for CryptoBilis customers.
— Ledger Support (@Ledger_Support) October 10, 2026
What Ledger Has Confirmed
The central development is the discovery of additional, unauthorized hardware inside an affected customer’s device. Earlier reports had raised the possibility that wallets were altered before reaching buyers. Ledger has now confirmed a physical implant in one examined unit, while its investigation into the broader incident continues.
That confirmation does not identify who installed the component, where the modification occurred or whether every reported theft used the same method. The announcement does not attribute wrongdoing to CryptoBilis or say that all devices sold by the reseller were compromised.
The sales suspension has also widened. Ledger’s October 9 warning asked CryptoBilis to pause Ledger sales and shipments; the latest update says the reseller has ceased sales of all hardware-wallet inventory as a precaution. Ledger says it remains in active communication with CryptoBilis about next steps.
Ledger’s Advice for CryptoBilis Customers
The updated notice addresses users who bought a Ledger device from CryptoBilis. Unlike the earlier warning, which specified purchases within the previous 90 days, the October 10 statement does not repeat that time limit.
- If the device has not been set up: Ledger recommends not beginning setup. Its instruction concerns initialization, when a wallet is created or restored; the update does not announce a universal recall of every Ledger device.
- If setup is already complete: Ledger advises customers to consider moving their assets to a new Ledger signer with a new seed. Both parts of that recommendation matter: replacement hardware and a newly generated recovery phrase.
- For assistance: use Ledger’s official support channels. The company warns that scammers may exploit the incident and says it will never ask for a customer’s 24-word recovery phrase.
Ledger’s existing security guidance explains the distinction between replacing a device and replacing a wallet. A recovery phrase restores the same keys on compatible hardware. Importing an exposed phrase into a new device therefore leaves anyone who already knows it able to access the corresponding assets.
A fresh phrase generated on trusted hardware controls a different wallet. Moving assets to its accounts is different from restoring the old backup. Recovery words should never be submitted to a website, pasted into a support chat or disclosed to somebody offering to investigate a theft.
How the Investigation Developed
The public investigation began with onchain reports of unexplained outflows. CoinScreamer’s initial report covered analyst Specter’s preliminary assessment of more than $86 million in suspected thefts across Bitcoin, Ethereum and TRON. That estimate was based on tracing associated addresses and reviewing user complaints.
Specter subsequently clarified that the number of affected wallets had not been established. An address cluster can include collection wallets and later transfers, so neither its address count nor its displayed balance automatically establishes unique victims or total losses.
Our reseller warning followed Ledger’s October 9 sales-pause request and analyst Darkfost’s concern that losses could be larger than first reported. At that stage, a compromise involving hardware supplied through CryptoBilis remained an investigative hypothesis.
The October 10 confirmation materially advances that record. However, Ledger has not provided a verified aggregate loss figure, reconciled the analysts’ estimates or tied every reported outflow to the implant. The earlier dollar totals remain attributed assessments rather than a company-confirmed accounting.
What Separate Implant Research Shows
CoinScreamer also examined Tibane’s findings on modified Nano X devices acquired through Japanese marketplaces. The lab’s technical report describes implants that intercept screen data, reconstruct recovery words and transmit them through separate cellular hardware.
In those specimens, the original secure element remains intact. Tibane says the modified devices can pass Ledger’s Genuine Check because the authentic chip is still present. The reported attack captures information sent to the display rather than demonstrating a break of the chip’s cryptography.
Those findings provide technical context, but Ledger has not said its newly confirmed implant uses that design. Tibane states that neither of its specimens was purchased from CryptoBilis and that it has no evidence linking them to the reseller. The two investigations should not be treated as a proven common operation.
What Remains Unresolved
The remaining questions include the number of modified devices, their distribution, the point at which tampering occurred and which reported thefts can be connected to affected hardware. Ledger’s statement does not identify an attacker or announce a compensation process.
The company says it is adding security mitigations and developing enhanced anti-tampering solutions. It has not specified a release date or said that a software update can neutralize the confirmed implant. For affected buyers, the current response remains the reseller-specific setup warning, consideration of a new signer and seed, and assistance through official channels.
Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.