Ledger has admitted that unauthorized chips were implanted in hardware wallets sold by Southeast Asian distributor CryptoBilis. The losses may exceed $86 million; researchers estimate the range at $72 million to $86 million. The stolen assets are spread across Bitcoin, Ethereum, and Tron addresses. Ledger says this happened only at this one distributor and was limited to the Southeast Asian market.
That’s the problem. The entire selling point of a hardware wallet is its root of trust—the private key never leaves the chip. But the chip passed through the distributor’s hands, and the moment users open the box, they have no way to verify whether the one inside is genuine. You’re not trusting Ledger; you’re trusting the supply chain from the factory to your hands, and you never know how many people are in that chain.
I’m focused on another number: Coldcard was also looking into how a phishing link appeared on its X account on the very same day. One hardware wallet maker had its supply chain tampered with, another had its social media account compromised. What, exactly, can the device in users’ hands still prove? $BTC $ETH
That’s the problem. The entire selling point of a hardware wallet is its root of trust—the private key never leaves the chip. But the chip passed through the distributor’s hands, and the moment users open the box, they have no way to verify whether the one inside is genuine. You’re not trusting Ledger; you’re trusting the supply chain from the factory to your hands, and you never know how many people are in that chain.
I’m focused on another number: Coldcard was also looking into how a phishing link appeared on its X account on the very same day. One hardware wallet maker had its supply chain tampered with, another had its social media account compromised. What, exactly, can the device in users’ hands still prove? $BTC $ETH