There is a shop in Malaysia called Cryptobilis that sells hardware wallets. Ledger has listed it as an official authorized reseller since at least 2022 for Malaysia, Indonesia, and the Philippines. It was a legitimate shop selling real devices to normal customers for years.

This spring, the founders sold the company. The deal came with an NDA: they were not allowed to tell anyone about the sale until October 19. By August, the company registry showed one owner with 100% ownership — a man from Heilongjiang, China. The shop kept operating as if nothing had happened. The website, the name, and the “Authorized by Ledger” badge all stayed up.

On October 8, @MagicalTux posted photos of a Ledger he had cracked open. Hidden under the screen was a small extra board with an LTE modem and an eSIM. It simply watches the display. When you set up the wallet and the 24 words appear on the screen, they get sent out over mobile data. Ledger’s genuine check doesn’t catch it because the actual Ledger chip is real. His device came from Malaysia.

Only about 22 hours later, everything was swept. 203 BTC moved to two addresses in a single block. Around $58 million in USDT moved on Tron in the same hour. Adding up all the related wallets comes to roughly $91 million.

About 7 hours after that, Ledger said it was “investigating” and asked Cryptobilis to pause sales. At the time of writing, Cryptobilis was still listed as an authorized reseller on Ledger’s website.

To be fair, no one has officially tied the new owner to the bugged devices yet, and Ledger has not confirmed exactly how it happened. But read it as a business plan:

  • Get authorized, sell real products for years

  • Quietly sell the company under an NDA

  • Keep the authorized badge

  • Start shipping devices that phone home

  • Drain everything the moment someone notices

Was Ledger even told that the shop had been sold? Nobody has said so.

“Authorized reseller” only means Ledger trusted whoever ran the shop back in 2022. It says nothing about who runs it today.

Advice from CZ (Changpeng Zhao):

If you buy a new device (especially from a third party), “quarantine” it for a couple of weeks to a month before moving any significant amount of funds onto it. Follow community news during that time. If a batch of devices has been tampered with, the first thefts will surface and people can raise the alarm.

On the technical side: the hidden board uses an eSIM + LTE, so it needs mobile data to send the seed. Prepaid eSIMs usually have a limited validity period (a few weeks to a few months depending on the plan). The small board may have its own battery or draw power from the Ledger’s battery when the device is on. If it only activates during setup (when the seed is displayed), it doesn’t need to run continuously and may not cause noticeable battery drain during normal use. This is only technical speculation — there is no official analysis from Ledger or independent experts yet.

Deeper thoughts on this supply chain attack:

  1. Physical active tamper protection is important. Automated device security checks are insufficient if the device can be opened without triggering a tamper event.

  2. Trustable manufacturing is important. Domestic manufacturing is preferred. Many people do not want a hardware wallet manufactured by Foxconn or other factories in Asia.

  3. Transparent enclosures are not a panacea. Implants can be made smaller and can blend in completely with original components.

  4. DIY hardware is not a panacea. How soon until Amazon sellers start modifying Raspberry Pis and other dev boards, hoping someone uses them for Bitcoin or crypto storage?

  5. It was surprising to learn that no company currently makes an encrypted display driver chip. That would have prevented this kind of attack, where the data signals going to the display were intercepted.

  6. There are many different ways to do a supply chain attack. We’ve seen simple ones like Amazon sellers including a seed card already filled out, and some percentage of uneducated users entering those exact seed words. This was the most complex and well-executed attack we’ve seen so far.


LEDGER HACK: DON’T PANIC!

If you own a Ledger hardware wallet but DID NOT buy it from CryptoBilis, there is currently no evidence that your device is affected.

What happened?

Reports claim that more than $86 million in crypto was stolen from Ledger users in Southeast Asia. The incidents have been linked to devices purchased through CryptoBilis, a hardware-wallet reseller operating in Malaysia, Indonesia, and the Philippines.

Was Ledger hacked?

Not necessarily. There is currently no confirmation that Ledger’s encryption, secure elements, or recovery system were broken. Investigators are looking into a possible supply chain attack — and that’s a completely different problem.

How does that work?

Imagine buying a brand-new hardware wallet. It arrives sealed. Everything looks legitimate. But what if someone tampered with the device before you received it? If attackers somehow obtained your recovery phrase during setup, they could steal your Bitcoin without ever touching your wallet again. The exact attack method has not been confirmed.

Who is CryptoBilis?

CryptoBilis is a cryptocurrency hardware-wallet reseller operating in Southeast Asia. It sells products from Ledger and other hardware-wallet manufacturers. Ledger reportedly asked CryptoBilis to suspend Ledger sales and shipments while the investigation continues.

Is your Bitcoin safe?

  • If you bought directly from Ledger or another trusted retailer → there is currently no confirmed connection to this incident.

  • If you purchased from CryptoBilis (especially within the last 90 days) → take the warnings seriously.

Remember:

  • NEVER enter your recovery phrase on a website.

  • NEVER share it with “support.”

What should you do if your device might be affected?

  1. Stop using the suspected wallet.

  2. Set up a NEW wallet on a trusted device.

  3. Generate a completely NEW recovery phrase.

  4. Transfer your funds to the new wallet.

  5. Do NOT simply reset a potentially compromised device and assume it’s safe.


The Most Important Solution: The 25th Word (Passphrase)

This is the last line of defense and the best solution in this situation.

Even if the 24-word seed is completely exposed (as in the case of the screen-reading implant), as long as you have set a 25th word (also known as a BIP39 Passphrase), the attacker still cannot access your funds.

The 25th word works as an additional layer of protection:

  • It turns the same 24-word seed into a completely different wallet.

  • Without the 25th word → the real wallet cannot be opened.

  • You can create multiple “hidden wallets” from the same 24 words by using different 25th-word passphrases.

Strong recommendation:

From now on, for every hardware wallet (no matter where you buy it), always enable and use a 25th-word passphrase. This is the final protective layer that gives you much greater peace of mind against sophisticated supply-chain attacks like this one.

The Bigger Lesson:

Not your keys, not your coins.

But self-custody also means taking responsibility for how you generate and protect those keys. A hardware wallet is only as trustworthy as its security and its supply chain.

Stay informed. Don’t panic. Verify everything.