A hardware wallet is supposed to be the safest place to keep crypto. This week's Ledger investigation is a reminder that the safety starts with where the device comes from, per CoinDesk and CryptoSlate.
š The news
Ledger is investigating reports that wallets bought through CryptoBilis, a Southeast Asian reseller, were drained. A pseudonymous investigator claims more than $86 million was taken from hundreds of wallets, and CryptoSlate puts the estimate near $90 million. Ledger has asked the reseller to halt all sales and shipments.
š Why it matters
⢠Suspected theft addresses span Bitcoin, Ethereum and TRON
⢠Tether has moved to freeze stolen $USDT linked to the case, per CryptoSlate
⢠There is no confirmed evidence that Ledger's own systems or wallet technology were compromised
š The numbers
⢠Over $86 million claimed stolen, not yet independently confirmed
⢠Ledger says it has sold more than 7 million devices since 2014
⢠Per DefiLlama data cited by CoinDesk, 2026 has already seen several nine-figure losses, including about $350 million at Bitget last month
āļø What Ledger told users
⢠If you bought from this reseller in the past 90 days, do not set up the device
⢠If you already activated one, consider moving funds to a new Ledger with a freshly generated recovery phrase
š What to watch next
⢠Whether Ledger confirms a supply-chain attack, meaning devices were tampered with before delivery
⢠How much of the stolen stablecoin Tether manages to freeze
āāāāāāāāāāāā
š” My take: In my view the real lesson is about the recovery phrase. A device that arrives with a phrase already filled in, or from a seller you cannot verify, should be treated as compromised, no matter what brand is printed on the box.
š¬ Where did you buy your hardware wallet, and did you check it on arrival?
#Ledger #SelfCustody #Security