Hackers Steal Up to $93 Million via Tampered Ledger Wallets Sold by Reseller
Attackers compromised hardware wallets sold by authorized Southeast Asian distributor CryptoBilis, placing cellular hardware implants behind device screens to steal cryptocurrency recovery phrases. The spy chips quietly broadcast secret 24-word phrases over cellular networks, enabling bad actors to recreate wallets and drain funds remotely. Estimated losses range between $72 million and $93 million, affecting hundreds of crypto wallets across multiple blockchains including Bitcoin, Ethereum, and Tether USDT.
Ledger confirmed the presence of an unauthorized implant on October 10, 2026, and instructed CryptoBilis to halt all product sales and shipments in Malaysia, Indonesia, and the Philippines. The incident highlights supply chain vulnerabilities for hardware security devices. Ledger maintained that its direct sales channels and core infrastructure remain uncompromised. Meanwhile, Tether froze roughly $10 million in stolen USDT, though some stolen assets were funneled through mixing services.
Investors and security experts are monitoring further investigations into how many physical units were altered and whether asset issuers can freeze additional stolen funds. Observers are also watching for verification of claims that attackers directly acquired the reseller to execute the breach, as well as whether affected users will migrate funds to newly generated seed phrases on verified devices.
Key points
- Unauthorized hardware implants were discovered inside Ledger wallets sold by distributor CryptoBilis.
- Attackers stole between $72 million and $93 million by transmitting wallet recovery phrases over cellular networks.
- Ledger halted CryptoBilis sales and stated that its direct sales and core systems were not impacted.
- Tether froze approximately $10 million in USDT connected to the stolen funds.
Written by our AI from expert market sources across the web. It can contain mistakes: check the facts before acting on them. Write-ups powered by the free AI API at FreeTheAI.org
How we writeDisclaimerQuestions and answers
How did hackers steal funds from Ledger wallets?
Attackers planted cellular circuit boards behind screens on devices sold through distributor CryptoBilis. These spy chips captured users 24-word recovery phrases and sent them over cellular networks, allowing hackers to access wallets remotely.
Were devices bought directly from Ledger affected by the hack?
Ledger stated that its core systems and products sold directly through its official store were not affected. The security breach was confined strictly to the inventory sold through reseller CryptoBilis.
How much money was stolen in the Ledger reseller compromise?
Total estimated losses range between $72 million and $93 million, affecting hundreds of wallets. Tether has frozen roughly $10 million in linked stablecoin funds.
