Ledger theft reports: Check where you bought it first—don’t rush to click “Emergency Repair”!
As of 10/9 at 10:56 p.m. Taiwan time, multiple sources citing Ledger Support say it is investigating reported asset losses among customers who purchased from Southeast Asian reseller CryptoBillis, and has asked the seller to suspend sales and shipments.
Keep these three things in mind:
1|A theft report does not mean that all Ledger devices have been compromised.
2|Supply-chain tampering is still one possible line of investigation; the cause has not been determined.
3|The large losses circulating online are unconfirmed estimates, not official statistics.
If you bought from CryptoBillis in the past 90 days:
• Not yet set up: Don’t activate the device or deposit assets into it.
• Already set up: In line with the notice, consider moving your assets to a trusted new device using a newly generated recovery phrase.
• Don’t just switch devices and import your old recovery phrase. If the old phrase has been exposed, the risk remains.
During the transfer, independently verify the receiving address and network on the new device’s screen. Don’t use a “safe address” provided by a stranger. If you’re unsure how to proceed, navigate directly to the official support page from Ledger’s website. Don’t contact anyone who messages you claiming to be support.
Other holders should first verify their purchase source and on-chain records. Don’t interpret “not currently covered by the reports” as a guarantee of safety. If you notice an unfamiliar outgoing transaction, keep the transaction records, order details, and packaging. Don’t rush to reset the device and destroy potential evidence.
Never enter your recovery phrase on a website, in a mobile app, or on a computer, and never share it with any support agent. Reject any signature request you don’t understand. If your recovery phrase has been leaked, revoking contract approvals won’t address the root problem.
The second wave of attacks that most often follows a security incident comes from fake support agents who exploit your panic and tell you to “verify your wallet.”
Original notice:
https://x.com/Ledger_Support/status/2108551100613714002
Anti-scam guide:
https://www.ledger.com/phishing-campaigns-status
#Ledger #加密安全 #冷錢包
$BTC
As of 10/9 at 10:56 p.m. Taiwan time, multiple sources citing Ledger Support say it is investigating reported asset losses among customers who purchased from Southeast Asian reseller CryptoBillis, and has asked the seller to suspend sales and shipments.
Keep these three things in mind:
1|A theft report does not mean that all Ledger devices have been compromised.
2|Supply-chain tampering is still one possible line of investigation; the cause has not been determined.
3|The large losses circulating online are unconfirmed estimates, not official statistics.
If you bought from CryptoBillis in the past 90 days:
• Not yet set up: Don’t activate the device or deposit assets into it.
• Already set up: In line with the notice, consider moving your assets to a trusted new device using a newly generated recovery phrase.
• Don’t just switch devices and import your old recovery phrase. If the old phrase has been exposed, the risk remains.
During the transfer, independently verify the receiving address and network on the new device’s screen. Don’t use a “safe address” provided by a stranger. If you’re unsure how to proceed, navigate directly to the official support page from Ledger’s website. Don’t contact anyone who messages you claiming to be support.
Other holders should first verify their purchase source and on-chain records. Don’t interpret “not currently covered by the reports” as a guarantee of safety. If you notice an unfamiliar outgoing transaction, keep the transaction records, order details, and packaging. Don’t rush to reset the device and destroy potential evidence.
Never enter your recovery phrase on a website, in a mobile app, or on a computer, and never share it with any support agent. Reject any signature request you don’t understand. If your recovery phrase has been leaked, revoking contract approvals won’t address the root problem.
The second wave of attacks that most often follows a security incident comes from fake support agents who exploit your panic and tell you to “verify your wallet.”
Original notice:
https://x.com/Ledger_Support/status/2108551100613714002
Anti-scam guide:
https://www.ledger.com/phishing-campaigns-status
#Ledger #加密安全 #冷錢包
$BTC