Ledger’s Southeast Asian sales channel has reported asset losses. The $86 million figure is only an on-chain estimate; the real concern is the supply-chain risk posed to hardware wallets.
Ledger is investigating user asset losses connected to its reseller CryptoBilis and has asked the channel to suspend sales and shipments. On-chain researchers estimate that suspected losses across networks including BTC, ETH, and TRON exceed $86 million, but the amount and exact cause have not yet been fully confirmed.
<Cite refs={["turn545983search0","turn545983search1"]}/>
This incident is a reminder to all crypto users: a hardware wallet being offline does not mean your assets are absolutely safe. If a device is tampered with before delivery, or its recovery phrase has been exposed, a cold wallet can still be compromised.
I think there are three things worth paying attention to in this incident:
First, the risk may come from the supply chain, and not necessarily from the wallet software itself. Ledger has not confirmed the root cause, so we cannot conclude that all devices are vulnerable.
Second, the responsibility for self-custody goes beyond managing private keys; it also includes choosing where to buy, initializing the device, and safeguarding the recovery phrase.
Third, if it is later confirmed that devices were tampered with, reseller vetting and supply-chain security across the hardware wallet industry will face greater scrutiny.
For users who bought devices through CryptoBilis in the past 90 days, Ledger recommends that those who have not yet initialized their devices hold off on using them. Users who have initialized their devices should consider moving their assets to a wallet created with a brand-new recovery phrase. Be sure to verify instructions through official channels, never disclose your recovery phrase to anyone, and do not click on purported emergency migration links.
<Cite refs={["turn545983search0","turn545983search3"]}/>
My view is this: real security isn’t about believing that a particular brand will never have a problem. It’s about making sure that even if one part of the process fails, your assets aren’t all exposed.
Do you think this incident will lead more people to turn to exchange custody, or instead push the hardware wallet industry to strengthen its security checks?
Ledger is investigating user asset losses connected to its reseller CryptoBilis and has asked the channel to suspend sales and shipments. On-chain researchers estimate that suspected losses across networks including BTC, ETH, and TRON exceed $86 million, but the amount and exact cause have not yet been fully confirmed.
<Cite refs={["turn545983search0","turn545983search1"]}/>
This incident is a reminder to all crypto users: a hardware wallet being offline does not mean your assets are absolutely safe. If a device is tampered with before delivery, or its recovery phrase has been exposed, a cold wallet can still be compromised.
I think there are three things worth paying attention to in this incident:
First, the risk may come from the supply chain, and not necessarily from the wallet software itself. Ledger has not confirmed the root cause, so we cannot conclude that all devices are vulnerable.
Second, the responsibility for self-custody goes beyond managing private keys; it also includes choosing where to buy, initializing the device, and safeguarding the recovery phrase.
Third, if it is later confirmed that devices were tampered with, reseller vetting and supply-chain security across the hardware wallet industry will face greater scrutiny.
For users who bought devices through CryptoBilis in the past 90 days, Ledger recommends that those who have not yet initialized their devices hold off on using them. Users who have initialized their devices should consider moving their assets to a wallet created with a brand-new recovery phrase. Be sure to verify instructions through official channels, never disclose your recovery phrase to anyone, and do not click on purported emergency migration links.
<Cite refs={["turn545983search0","turn545983search3"]}/>
My view is this: real security isn’t about believing that a particular brand will never have a problem. It’s about making sure that even if one part of the process fails, your assets aren’t all exposed.
Do you think this incident will lead more people to turn to exchange custody, or instead push the hardware wallet industry to strengthen its security checks?