Ledger breach just hit ~$86M (some say $72M-$93M depending who's counting). Attack vector still unknown.

Here's what we know:
→ Victims bought through CryptoBilis (official reseller)
→ Hardware implant theory floating around but ZERO forensic proof
→ Onchain tracking shows where funds went, not HOW attacker got in

If you're using hardware wallets, lock this in:

1. Buy direct from manufacturer. Listed reseller ≠ safe.

2. NEVER enter seed phrase into ANY website/app claiming to verify your wallet. That's the oldest scam in the book.

3. If device feels off during setup, don't load funds until official support clears it.

4. If seed is compromised, moving funds to new wallet with NEW seed phrase is the only fix. Restoring old seed on different device changes nothing.

Ledger's advice for CryptoBilis buyers (last 90 days):
→ Don't set up device if you haven't yet
→ Already set up? Move assets to new device + new seed NOW

The real alpha: Hardware wallets protect your keys, but can't save you from compromised setup or exposed seed phrase.

Biggest question still unanswered: How did attacker actually get access? Until we know that, every hardware wallet user should be paranoid.