Ledger finds a hardware implant in a wallet linked to reported thefts
Ledger confirmed an unauthorized hardware implant in one customer’s wallet while investigating losses linked to reseller CryptoBillis. The company asked the reseller to pause sales and advised recent buyers to avoid setting up their devices. The scope of affected wallets and the alleged mechanism for capturing recovery words remain under investigation.
Artificial Intelligence··Night
Ledger confirms a modified device
Ledger, a maker of hardware wallets that hold the keys used to control cryptocurrency, confirmed an unauthorized implant in one affected customer’s device. The discovery came during an investigation into reported losses associated with purchases from a Southeast Asian reseller. Wallet sales were halted while the examination continued.[1], [2]
Ledger asked CryptoBillis to pause sales and shipments. The losses mainly concern users in Southeast Asia. Investigators have not established the full extent of affected devices or the point in the supply chain where the modification occurred.[1]
Recovery words are central to the suspected mechanism
Photographs and videos circulating online appear to show a small circuit beneath a wallet’s display. It is alleged to capture information shown during setup, including recovery words, and transmit it using a SIM. Those words are the backup used to recreate a wallet’s private keys. Confirmation of the implant in one device does not establish every detail of that alleged transmission mechanism.[1]
Ledger advises recent buyers to avoid setup
The company advised buyers who obtained devices from CryptoBillis in the preceding 90 days not to initialize them. For devices already initialized, it recommended moving holdings to a new device with a fresh recovery phrase. Its guidance also included checks for physical tampering. Ledger has not independently verified the reported aggregate losses and says there is no indication its own security infrastructure was compromised.[1], [2]