Ledger said Saturday it has confirmed an "unauthorized hardware implant" inside a device belonging to one of the users affected by the CryptoBilis incident — the company's first physical corroboration of the tampering theory behind one of the year's largest suspected wallet drains.

The confirmation came in a situation update posted October 10, reported by The Crypto Times. Ledger reiterated that it has no indication its own security infrastructure, systems or services were compromised, said it is working with the appropriate authorities, and thanked the security-response collective SEAL 911 for its assistance. The reseller CryptoBilis, which operated in Indonesia, Malaysia and the Philippines, has suspended sales of its hardware-wallet inventory.

Important limits remain: one confirmed implant does not establish the cause of every reported loss, and Ledger has not said how many devices were altered or who altered them. A separate report of a hidden chip found in a Ledger device purchased in Malaysia, shared publicly by former Mt. Gox chief Mark Karpelès, remains an unverified individual account.

The On-Chain Picture Grows Darker

Blockchain analytics firm Bitquery has published the most detailed tracing of the incident to date, counting $93.2 million taken from 315 wallets across six chains — higher than the $86 million first estimated from ten public drain addresses, because the thief also emptied wallets on Solana, BNB Chain and Polygon. By chain: TRON $70.5M (131 wallets, mostly USDT), Bitcoin $16.8M (122 wallets, 203.8 BTC), Ethereum $3.7M, BNB Chain $1.45M, Polygon $0.58M and Solana $0.25M.

The timing evidence points to a single actor who already held the private keys, Bitquery says — presented as analytical inference, not a confirmed attribution:

  • 25 TRON wallets signed the same approval for the same address within three seconds, and $29 million was pulled out within six seconds of the first signature.
  • Eight minutes earlier, 30 other TRON wallets had their account controls changed to add the same new key, all within three seconds — something only a holder of each wallet's own key can do.
  • 111 Bitcoin wallets were emptied into two addresses in a single block.
  • The thief's control addresses ran 21 small test loops on TRON and 20 on Ethereum over two weeks before the October 9 drain.

Bitquery also found that roughly six in ten victim wallets were first funded inside Ledger's 90-day advisory window, but more than eight in ten were funded from June onward — suggesting buyers from as far back as four months should treat the re-seed guidance as applying to them too.

Laundering and Freezes

Tether blocked 37 addresses linked to the theft within hours, freezing $10.0 million in USDT, though the thief also converted 14.9 million USDT into USDD, a stablecoin Tether cannot freeze, which still sits in seven TRON wallets. About 1,254 ETH was run through Tornado Cash and then swapped into Zcash in 41 lots — but the coins resurfaced in three new wallets holding 384 ETH and 2.1 million USDC, the latter freezable by Circle. The stolen Bitcoin has not moved. Bitquery estimates about $86 million remains traceable on-chain.

For customers who bought a Ledger through CryptoBilis, the guidance stands: do not set up an unused device, and move assets from any device already configured to a new signer with a newly generated recovery phrase. No one from Ledger or law enforcement will ever ask for the 24 words.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.