$86 million drained from Ledger: your recovery phrase was read as you wrote it down 🔐

On-chain analyst Specter traced 10 suspicious addresses that collected over $86 million from hundreds of victims’ wallets across BTC, ETH, and TRON. Ledger has yet to confirm the total losses. So far, all clues point to the same source: Malaysian reseller CryptoBilis.

📍 The attack path disclosed so far (SlowMist 23pds’ analysis)
1️⃣ Modified devices were sold through normal channels, with the outer shrink-wrap intact
2️⃣ A board was hidden where the screen’s cushioning pad sits: a microcontroller + LTE module + eSIM + antenna
3️⃣ You initialize the device, and your recovery phrase appears on the screen. The module reads it from the screen’s SPI circuitry
4️⃣ After setup, it’s sent back to the attackers over 4G

The secure chip can prevent private keys from being directly extracted, but it can’t control what’s being displayed on the screen. SlowMist also noted that this attack path and the alleged hardware implant still need independent verification.

🧩 Two takeaways
1. The chain of trust for a cold wallet extends beyond a single chip. Based on the attack path disclosed so far, the point of compromise was somewhere between the factory and your hands—in the reseller stage.
2. What the attackers took was the recovery phrase itself. Buying a new device and importing your old recovery phrase changes nothing.

👛 If you own a Ledger, here’s how to check:
· Bought from CryptoBilis in the past 90 days and haven’t activated it yet? Don’t set it up.
· Already using it? Follow the official guidance and move your assets to a new device with a newly generated recovery phrase.
· If the package came with a pre-printed or pre-written recovery phrase card, treat it as unsafe.
· Anyone DMing you, claiming they can help recover your funds, is most likely running a second-wave scam.
· In future, buy hardware wallets only from the official website or authorized channels.

Hardware wallets are built on the promise that no one has tampered with them between the factory and your hands. This time, the vulnerability was in the reseller stage. Whether Ledger can identify the root cause and affected batches will directly affect trust in the entire cold-wallet sector.

Where did you buy your cold wallet? Do you inspect it after it arrives?

The above is solely my personal opinion and does not constitute investment advice. DYOR.

#Ledger #硬件钱包 #资产安全 #ColdWallet