📰 On October 9, more than $93 million in assets was reported stolen from Ledger hardware wallets. Chillingly, many victims said they had always stored their recovery phrases by hand and had barely ever connected their devices to external devices—yet the assets in their wallets were still drained, with some even seeing authorization signatures they had never approved.
🔥 According to on-chain tracking, attackers transferred about $93.4 million from 471 addresses across seven blockchains. The Tron network lost about 69.98 million USDT, while the Bitcoin network lost about $17.59 million. The attackers also sent more than $3 million worth of ETH to Tornado Cash. Tether has frozen about $10 million USDT, but another $14.6 million USDD could not be frozen.
👀 This doesn’t look like an opportunistic attack. The wallets involved began receiving funds as early as September 24, then tested multichain transfers, approvals, and consolidation processes, while also setting up an automated transfer mechanism in advance. Honestly, the attackers may have spent more than a day preparing.
💡 More troublingly, the clues also point to third-party reseller CryptoBilis. It was previously an authorized Ledger reseller in Malaysia, Indonesia, and the Philippines, but reports emerged this year that the company had changed hands. Someone also found what appeared to be a spy module containing LTE, eSIM, and a microcontroller. However, there is currently no conclusive evidence linking it directly to this large-scale crypto theft.
🤔 The most unsettling takeaway is that a hardware wallet doesn’t necessarily mean absolute security. The supply chain, resellers, and every step before and after device delivery could be compromised. Would you keep using a hardware wallet, or move your assets to a freshly initialized device first?
#Ledger #硬件钱包 #加密安全 #OnchainSecurity
🔥 According to on-chain tracking, attackers transferred about $93.4 million from 471 addresses across seven blockchains. The Tron network lost about 69.98 million USDT, while the Bitcoin network lost about $17.59 million. The attackers also sent more than $3 million worth of ETH to Tornado Cash. Tether has frozen about $10 million USDT, but another $14.6 million USDD could not be frozen.
👀 This doesn’t look like an opportunistic attack. The wallets involved began receiving funds as early as September 24, then tested multichain transfers, approvals, and consolidation processes, while also setting up an automated transfer mechanism in advance. Honestly, the attackers may have spent more than a day preparing.
💡 More troublingly, the clues also point to third-party reseller CryptoBilis. It was previously an authorized Ledger reseller in Malaysia, Indonesia, and the Philippines, but reports emerged this year that the company had changed hands. Someone also found what appeared to be a spy module containing LTE, eSIM, and a microcontroller. However, there is currently no conclusive evidence linking it directly to this large-scale crypto theft.
🤔 The most unsettling takeaway is that a hardware wallet doesn’t necessarily mean absolute security. The supply chain, resellers, and every step before and after device delivery could be compromised. Would you keep using a hardware wallet, or move your assets to a freshly initialized device first?
#Ledger #硬件钱包 #加密安全 #OnchainSecurity