Ledger hack explained: spy implant, CryptoBilis, what to do

/ Ledger confirmed a hidden hardware implant in a wallet bought from reseller CryptoBilis after about $93M was drained. Who is at risk, how it works, what to do.
by Hozefa Khety
· 8 min read
Ledger, the French maker of crypto hardware wallets, has confirmed that a device belonging to one of the victims of a large wave of crypto thefts "contained an unauthorized hardware implant": a tiny extra circuit board hidden inside. The thefts hit people in Indonesia, Malaysia and the Philippines who bought Ledger wallets from a reseller called CryptoBilis, and on-chain investigators put the losses at roughly $86 million to $93 million. Ledger says its own systems were not breached. Here is what happened, how an implant like this steals your coins, who is at risk and exactly what to do if you own a Ledger. (Sources checked October 11, 2026 at 13:20 UTC / 18:50 IST.)
What Ledger has confirmed so far
On Friday, October 9, 2026 at 13:32 UTC (19:02 IST), Ledger's support account posted on X that it was "investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis" (Ledger spelled the name both ways). It asked CryptoBilis "to pause all sales and shipments of Ledger devices." Cointelegraph reports that CryptoBilis was listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines.
On Saturday, October 10 at 17:09 UTC (22:39 IST), Ledger posted a "Situation Update": "Ledger can confirm that one of the impacted users' devices contained an unauthorized hardware implant." It said it is reaching out to impacted users, is "working with the appropriate authorities to bring the bad actors to justice," and thanked the volunteer security group SEAL 911 for its help. CryptoBilis, Ledger said, "has ceased sales of all hardware wallet inventory until the investigation is concluded."
Ledger's position on its own security has not changed: "We have no indication that Ledger's security infrastructure, systems or services have been compromised." In replies on X it added that, based on what it knows so far, "the funds drained are limited to devices sold through a reseller named CryptoBilis in South East Asia," and it told Cointelegraph it had received no reports involving devices bought directly from Ledger.
What Ledger has not said: how many devices were tampered with, which models, how much was lost, or whether victims will be compensated. Its statements so far do not mention refunds, although many replies to its posts ask for them, as Bitcoin.com News noted.
How much was stolen
The figures come from independent blockchain researchers, not from Ledger, which has not confirmed any of them. Researcher tanuki42 first tied more than $72 million to eight addresses, and investigator Specter put the losses above $86 million across Bitcoin, Ethereum and Tron (Cointelegraph). Bitcoin.com News cites an estimate from Yfarmx of $93.4 million across 471 addresses.
The most detailed count so far is from blockchain data firm Bitquery, which traced $93.2 million taken from 315 wallets on six networks: Tron, Bitcoin, Ethereum, Solana, BNB Chain and Polygon. About $70.5 million of it was taken on Tron, almost all in the USDT digital dollar, plus about 204 bitcoin. According to Bitquery, the thief ran about two weeks of small test transactions first, then emptied wallets on all six networks within 47 minutes starting around 05:00 UTC on October 9, which points to one person or group already holding every wallet's keys.
Some money is stuck. Bitquery says Tether, which issues USDT, froze $10.0 million in 20 wallets, while the thief pushed 2,990 ether through the Tornado Cash mixer (a service that hides where coins go) over two days. By the morning of October 11, Bitquery said about $81 million could still be found on the blockchain. Being traceable is not the same as being returned to victims.

How a hidden implant steals your recovery phrase
A hardware wallet keeps the master key to your crypto inside a hardened chip called a secure element. That key is your 24-word recovery phrase, and anyone who has those words can rebuild your wallet on another device and spend everything, without ever touching your Ledger. The device shows you the words once, on its own small screen, when you set it up.
That moment is what the implant targets. Researchers at Tibane Labs, who have examined implanted Ledger Nano X units, describe a second tiny computer soldered onto a genuine Nano X and wired to the line that carries pictures to the screen. When the wallet displays the 24 words, the implant reads them pixel by pixel, recognizes the letters and sends them to the attacker over the mobile network, using its own cellular modem, SIM and antenna. The secure chip is never attacked, so the wallet works normally.
That is also why Ledger's "Genuine Check" in its app may not help here: it confirms the secure chip is authentic, and in a tampered device it still is. BeInCrypto notes that the check cannot detect every physical change around that chip, and Tibane Labs says the genuine-device check "passes, because the secure element really is genuine."
Former Mt. Gox boss Mark Karpelès posted photos on October 9 of what he called his "spy-implanted ledger," which he said came from Malaysia with "flawless shrink wrap," the implant "cleverly hidden where the screen's padding is supposed to be." BeInCrypto reports that Karpelès says his unit came from a different seller, not CryptoBilis. Ledger has not published details of the implant it found, so it is not yet known whether every drained wallet involved the same hardware.
This implant has been around for at least a year
The idea is not new. According to Tibane Labs, the first known implanted "Nano X" was flagged in a Reddit thread in August 2025. Hardware hacker Joe Grand of Grand Idea Studio took that unit apart and presented the full teardown at the hardwear.io USA 2026 conference, describing a hand-wired add-on board with a mobile modem that squeezed in by shrinking the battery.
Tibane Labs says it bought two newer implanted Nano X units in September 2026, one on Yahoo! Auctions in Japan and one on Amazon Japan from a China-based seller that shipped from Malaysia. Each version is harder to spot: the newest is painted to match the board, has its chip markings scraped off, leaves the battery alone and is cut to drop into place, which Tibane says points to mass installation. Neither was bought from CryptoBilis, and Tibane says it has not tested any device sold by CryptoBilis and has no evidence linking its Amazon Japan unit to the reseller.
Tibane also published a statement from CryptoBilis's former co-founders, Arravind Prabu and Vimalatheethan, saying the company was acquired by new owners earlier in 2026 and that they handed over all operations in March 2026 and have had no access since. The Threshold has not independently verified the ownership change, and Tibane stresses that a change of ownership is not in itself evidence of wrongdoing.
Who is at risk
Highest risk: anyone who bought a Ledger from CryptoBilis, in person or online, in Indonesia, Malaysia or the Philippines. Ledger's original advice covered purchases in the last 90 days, but its October 10 update repeats the advice for anyone who "purchased a Ledger device from this reseller," without mentioning the 90-day limit. Bitquery found that more than 8 in 10 of the drained wallets it checked first received money from June 2026 onward, and about 6 in 10 inside the 90-day window, so earlier buyers should not assume they are safe.
Some risk: anyone who bought a Ledger second-hand or from an unofficial marketplace seller, anywhere. The specimens Tibane examined were bought on auction and marketplace sites in Japan, not from CryptoBilis.
Lowest risk: people who bought directly from Ledger. Ledger says it has had no reports involving those devices, and nothing published so far suggests its factory or its own store was involved.
What to do now
If you bought from CryptoBilis and have not set the device up: don't. Ledger's advice is to "not initiate set up if they have not yet done so." The implant can only capture your words when the screen shows them, so an unused device has nothing to leak yet. Contact Ledger support through its official site, support.ledger.com.
If you bought from CryptoBilis and already use it: treat your recovery phrase as stolen. Ledger says to "consider moving assets to a new Ledger signer (with a new seed)." In plain terms, get a new hardware wallet from a trusted source, set it up so it creates a brand-new 24-word phrase, and send all your coins to the new wallet's addresses. Restoring your old 24 words onto a new device does not help, because the thief has those words too.
If your wallet was already drained: Bitquery warns that the thief still holds the keys, so any money sent to that old wallet later can be taken again. Tell anyone who pays into it to stop. Ledger asks people with information to contact its bounty program at bounty@ledger.fr.
If you hold USDT on Tron: Bitquery found that the thief quietly added its own key to 30 Tron wallets before emptying them. Check your wallet's permissions in a Tron block explorer, and if you see a key you don't recognize, move your funds to a new wallet.
Watch for scams. Ledger warns that "scammers often try to take advantage of incidents like this" and that "Ledger will never ask for your 24-word recovery phrase." Nobody legitimate will ever ask you to type it into a website, app, chat or form.
Buy direct or from a listed official reseller, and inspect what arrives. Never use a device that comes with recovery words already printed or filled in, a PIN already set, or opened packaging, and keep in mind that shrink wrap alone proves nothing.
What a replacement Ledger costs
If you need a new device to move your coins to, these are the prices on Ledger's official US store (shop.ledger.com, checked October 11, 2026, 13:22 UTC). Prices vary by country.
Ledger Nano S Plus: $69.
Ledger Nano X: $99.
Ledger Nano Gen5: $179.
Ledger Flex: $249.
Ledger Stax: $399.

Ledger says it is "working on further, enhanced anti-tampering solutions" but has not said what they are or which devices will get them.
Was Ledger hacked?
Not in the usual sense, based on everything published so far. There is no sign that Ledger's servers, software or own store were broken into, and the stolen keys did not come from cracking the wallet's secure chip. What failed was the supply chain: devices that passed through a seller's hands with extra hardware inside. That distinction matters little to people who lost money through an authorized reseller, and it is why the questions about Ledger's responsibility for its resellers will not go away. The Verge says the issue appears to be a supply chain attack, and Ledger's investigation is still ongoing.
The bottom line
A hardware wallet is only as trustworthy as the path it took to reach you. If you bought a Ledger from CryptoBilis, assume your recovery phrase is exposed and move your coins to a new wallet with a new phrase now. If you bought second-hand or from an unknown marketplace seller, it is worth doing the same. If you bought directly from Ledger, nothing reported so far puts you at risk, but never share your 24 words with anyone, and be wary of anyone who contacts you about this incident. We will update this story as Ledger releases more findings.
Sources
Ledger Support on X (October 9, 2026, 13:32 UTC, and October 10, 2026, 17:09 UTC) and Ledger replies on X (October 10, 2026); Cointelegraph (Nate Kostar, October 9, 2026; Michael Millard, October 11, 2026); The Verge (Terrence O'Brien, October 10, 2026); Bitcoin.com News (Jamie Redman, October 10, 2026); BeInCrypto (Lockridge Okoth, October 10, 2026), citing Mark Karpelès on X; Bitquery, "The Ledger CryptoBilis hack" (Gaurav Agarwal, updated October 11, 2026, 07:00 UTC); Tibane Labs, "Ledger Nano X: the spy implant" (October 2026); Grand Idea Studio, "Reverse Engineering a Ledger Nano X Hardware Implant" (Joe Grand, hardwear.io USA 2026); Ledger US store prices (shop.ledger.com, checked October 11, 2026, 13:22 UTC).
Frequently asked questions
Was Ledger hacked?
Ledger says it has no indication that its security infrastructure, systems or services were compromised. It has confirmed that one impacted user's device, bought through the Southeast Asian reseller CryptoBilis, contained an unauthorized hardware implant, which points to tampering in the supply chain rather than a break-in at Ledger.
What is CryptoBilis?
CryptoBilis (sometimes spelled CryptoBillis) is a crypto hardware shop that was listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines. Ledger asked it to pause all sales and shipments on October 9, 2026, and it has stopped selling all hardware wallets until the investigation ends.
How much crypto was stolen in the Ledger CryptoBilis incident?
Ledger has not confirmed a figure. Independent estimates range from more than $72 million (tanuki42) and more than $86 million (Specter) to $93.2 million from 315 wallets on six networks (Bitquery) and $93.4 million (Yfarmx).
How does the Ledger hardware implant work?
Researchers who examined implanted Ledger Nano X units say a tiny extra board is wired to the line that sends images to the wallet's screen. When the wallet shows the 24-word recovery phrase during setup, the implant reads the words and sends them to the attacker over the mobile network using its own modem, SIM and antenna.
Does Ledger's Genuine Check detect the implant?
Not reliably. Genuine Check confirms that the wallet's secure chip is authentic, and in a tampered device it still is. Researchers say an implanted device can pass the check while the extra hardware watches the screen.
I bought my Ledger from CryptoBilis. What should I do?
If you have not set it up, don't, and contact Ledger support via support.ledger.com. If you already use it, get a new hardware wallet from a trusted source, create a brand-new recovery phrase on it and move all your coins there. Do not restore your old 24 words onto the new device.
Is my Ledger safe if I bought it directly from Ledger?
Ledger says it has received no reports involving devices bought directly from the company, and nothing published so far suggests otherwise. Keep your 24 words private, and remember Ledger will never ask for them.
Will Ledger refund victims?
Ledger has not announced any compensation. Its statements so far cover the investigation, its advice to buyers and its work with authorities and SEAL 911.


