Ledger confirmed that one of the impacted users' devices contained an unauthorized hardware implant, saying in a situation update on X that it is reaching out to impacted users as part of the ongoing investigation. Anyone with information on the investigation was asked to contact Ledger's bounty program at bounty@ledger.fr. As a precaution, CryptoBilis confirmed it has ceased sales of all hardware wallet inventory until the investigation concludes, and Ledger said it is in active communication with CryptoBilis on next steps. Ledger said it is working with the appropriate authorities to bring the bad actors to justice and thanked SEAL_911 for its collaborative support on the investigation, adding that it has no indication its security infrastructure, systems or services have been compromised. As a reminder, Ledger recommends users who purchased a device from this reseller not initiate setup if they have not yet done so; those who have already set up their device should consider moving assets to a new Ledger signer with a new seed. The company said security is a constantly evolving landscape, that it is continuously adding security mitigations and working on further, enhanced anti-tampering solutions. It also warned that scammers often try to take advantage of incidents like this, urging users to rely only on official Ledger channels for updates, restating that Ledger will never ask for a 24-word recovery phrase, and directing assistance requests to support.ledger.com.