$86M+ stolen through the screen of a Ledger bought from an AUTHORIZED reseller.
On-chain estimates: 86 million USD+ from hundreds of wallets (Specter), 72 million+ (tanuki42). Ledger confirmed none of the totals. What it did confirm: one affected device had an unauthorized hardware implant inside it.
The reseller: CryptoBilis, an official Ledger reseller for Malaysia, Indonesia and the Philippines; sales now halted.
Teardown photos show a cellular implant behind the screen, reading whatever the display shows during setup. Your 24-word seed appears on screen exactly once, in readable form at first setup. That was the one moment this attack needed. The device still passes Ledger's Genuine Check.
Ledger's advice: bought from CryptoBilis in the last 90 days? Don't set it up. Already did? Move funds to a fresh signer with a new seed.
Everyone audits firmware. Nobody audits the supply chain. For years the safest advice in crypto was "buy from an authorized reseller." This week that advice was the attack vector.
If any of your $BTC or $ETH sits behind a reseller-bought device, move it first.
#Bitcoin #Crypto #Ledger
---
86 juta dolar+ dicuri lewat layar Ledger yang dibeli dari reseller RESMI.
Estimasi: 86 juta dolar+ dari ratusan wallet (Specter); 72 juta+ (tanuki42). Ledger belum konfirmasi total. Yang dikonfirmasi: satu perangkat korban terbukti punya hardware implant ilegal.
CryptoBilis, reseller resmi Ledger untuk Malaysia/Indonesia/Filipina, penjualannya dihentikan.
Foto teardown: implant seluler di balik layar yang membaca apapun yang tampil saat setup. Seed 24 kata cuma muncul di layar sekali, saat setup pertama. Perangkatnya tetap lolos Genuine Check.
Ledger: beli dari CryptoBilis 90 hari terakhir? Jangan setup. Sudah terlanjur? Pindah dana ke signer baru dengan seed baru.
Semua orang audit firmware. Tidak ada yang audit rantai pasok. Bertahun-tahun nasihat paling aman adalah "beli dari reseller resmi." Minggu ini nasihat itu jadi jalur serangannya.
On-chain estimates: 86 million USD+ from hundreds of wallets (Specter), 72 million+ (tanuki42). Ledger confirmed none of the totals. What it did confirm: one affected device had an unauthorized hardware implant inside it.
The reseller: CryptoBilis, an official Ledger reseller for Malaysia, Indonesia and the Philippines; sales now halted.
Teardown photos show a cellular implant behind the screen, reading whatever the display shows during setup. Your 24-word seed appears on screen exactly once, in readable form at first setup. That was the one moment this attack needed. The device still passes Ledger's Genuine Check.
Ledger's advice: bought from CryptoBilis in the last 90 days? Don't set it up. Already did? Move funds to a fresh signer with a new seed.
Everyone audits firmware. Nobody audits the supply chain. For years the safest advice in crypto was "buy from an authorized reseller." This week that advice was the attack vector.
If any of your $BTC or $ETH sits behind a reseller-bought device, move it first.
#Bitcoin #Crypto #Ledger
---
86 juta dolar+ dicuri lewat layar Ledger yang dibeli dari reseller RESMI.
Estimasi: 86 juta dolar+ dari ratusan wallet (Specter); 72 juta+ (tanuki42). Ledger belum konfirmasi total. Yang dikonfirmasi: satu perangkat korban terbukti punya hardware implant ilegal.
CryptoBilis, reseller resmi Ledger untuk Malaysia/Indonesia/Filipina, penjualannya dihentikan.
Foto teardown: implant seluler di balik layar yang membaca apapun yang tampil saat setup. Seed 24 kata cuma muncul di layar sekali, saat setup pertama. Perangkatnya tetap lolos Genuine Check.
Ledger: beli dari CryptoBilis 90 hari terakhir? Jangan setup. Sudah terlanjur? Pindah dana ke signer baru dengan seed baru.
Semua orang audit firmware. Tidak ada yang audit rantai pasok. Bertahun-tahun nasihat paling aman adalah "beli dari reseller resmi." Minggu ini nasihat itu jadi jalur serangannya.