Can hardware wallets be “compromised at the source”? Ledger is investigating thefts affecting users who bought devices from Southeast Asian reseller CryptoBilis. On-chain analysts estimate losses of more than $86 million, but the company has yet to confirm the amount or cause.
In a nutshell: A cold wallet is secure only if the device and recovery phrase belong exclusively to you.
Three reminders:
1. If you bought from this reseller in the past 90 days, the company recommends not activating the device for now. If you’re already using one, consider switching to a new device, generating a new recovery phrase, and then transferring your assets.
2. Buy only through official channels. Treat any device that comes with a pre-filled recovery phrase card as a scam.
3. Your recovery phrase must be generated by the device itself. No one else should know it in advance.
$BTC Where did you buy your cold wallet?