The cold wallet you think is safest may have been tampered with while it was still in a distributor’s hands 😨

Yesterday (October 9), Ledger acknowledged in an announcement that hardware wallets bought by some users through Southeast Asian distributor CryptoBilis may have been used to steal over $86 million in crypto assets, involving $BTC , $ETH , and multiple chains $TRX . The company has asked the distributor to suspend sales and shipments. The investigation is ongoing.

A checklist to go through, item by item:

◆ Where did you buy it? The distributor involved is CryptoBilis, an official distributor in Indonesia, Malaysia, and the Philippines—not a direct purchase from the official website.
◆ Ledger’s official recommendation: If you bought a device through them in the past 90 days and haven’t activated it yet, don’t activate it for now. If it’s already activated, consider transferring your coins to a new device with a completely new recovery phrase.
◆ The $86 million figure hasn’t been fully verified, and it’s not yet clear whether the devices were tampered with or if something else caused the incident—but the company has suspended the distributor, so it’s better to be cautious.
◆ The key point: This is an issue with the “purchase channel,” not a compromise of all Ledger products. Don’t panic-sell, but do check if you need to.

Put simply, hardware wallets protect you from hackers, but they can’t protect you if someone handled the device you bought before it left the factory. Order from the official website or an official direct-sales channel, check that the packaging is genuine before opening it, and always write down your recovery phrase by hand and keep it offline. These are the basics.

Where did you buy your cold wallet? Let’s compare notes in the comments 👇

#硬件钱包 #安全 #Bitcoin