Major security incident: $86M drained from Ledger hardware wallets sold through a compromised reseller. Ledger has ordered the reseller to halt all sales and shipments immediately.

If you purchased a Ledger device recently, especially from third-party sellers, do not use it yet. The attack vector appears to be tampered devices distributed through unauthorized channels — classic supply chain compromise.

This is a reminder that hardware wallet security isn't just about the device itself, but the entire distribution chain. Always buy directly from manufacturers or verified official retailers. Check for tamper-evident packaging, verify firmware signatures, and never trust a device that arrives pre-initialized or with seed phrases included.

The $86M loss shows how a single weak link in the supply chain can compromise what's supposed to be the most secure self-custody method. Not a Ledger firmware issue per se, but a distribution security failure that affects real users holding real money.