When secure hardware is no longer Ledger's largest source of revenue, $100 million was stolen.

Bitsfull2026/10/10 13:007972

概要:

The supply chain attack that was discovered long ago was not taken seriously by Ledger.

The 80 bitcoins were received on September 29.


Four months earlier, its owner bought these 80 bitcoins at around $65,000, spending $5.2 million. By the end of September, the unrealized gain was $1.38 million. He didn't sell. He made over $1 million in 4 months.


A week ago, he bought a Ledger hardware wallet: a small plastic thing designed to hold money, shaped like a USB drive, and transferred all 80 bitcoins into it. On-chain data shows this was the last incoming transaction for his address.


On the afternoon of October 9, these 80 bitcoins were swept from a block.


He wasn't the only one swept at the same time. At 13:00 on October 9, the first funds were drained on the TRON network; about 1 second later, wallets on BNB Chain and Polygon began bleeding; 11 seconds later, a wallet on Ethereum signed the same authorization; within 6 seconds after the first authorization landed, $29 million in USDT was drained. By 13:54, 111 sweeps on the Bitcoin network landed in the same block, with the two batches totaling 122 transactions and 203.8 bitcoins.


Humans don't operate like this.


By 00:37 the next morning, the last batch of funds was drained. Third-party statistics put the numbers at: 311 wallets, 5 chains, at least $92.9 million. $70.5 million on TRON, $16.8 million on Bitcoin, $3.7 million on Ethereum, $1.45 million on BNB Chain, $580,000 on Polygon. Ledger has still not confirmed the total amount.


The owners of these funds are distributed across Indonesia, Malaysia, and the Philippines. This is not an accident. In Chainalysis's 2026 Global Crypto Adoption Index, Indonesia ranks 14th, and the Philippines ranks 19th. In these places, USDT is a daily tool for remittances and payments.


They all have one thing in common: their wallets were bought from the same store.


Southeast Asia's Top Distributor


That store is called CryptoBilis, with a booth on the sixth floor of Berjaya Times Square, one of the busiest malls in Kuala Lumpur.


The footer of the Malaysia site reads "A brand of CB International," followed by a company registration number 201901004478. This number was still registered under another name, Fetch Malaysia Sdn Bhd, in 2021, and was only changed to CB International in March 2022. The business is relatively simple: it just sells hardware wallets, and they sell hardware wallets from over twenty brands including Ledger, Trezor, SafePal, Tangem, CoolWallet, Ellipal, and more.



Its product page says this:


And on Ledger's own official website, CryptoBilis is indeed listed — not one, but three: one each for Malaysia and Indonesia, and one for the Philippines, all using its own domain names. All three are marked as having an "online store."


This is not a small brand. This store's standing in Southeast Asia carries more weight than the words "authorized reseller." In October 2025, its CEO Arravind Prabu and regional project manager Zean Wong received personal invitations from Ledger, flew to Paris to attend the Ledger Op3n event and the global launch of the Nano Gen5, and also toured Ledger's new headquarters security lab, "Donjon."


In Southeast Asian crypto forums, this is how people recommend it:




It is this very reseller that locals trust so much that turned out to have a problem inside its devices.


Teardown Reveals Something Amiss


At 9 PM on the 9th, Ledger's official account posted a statement. It said Ledger is investigating reports of fund losses from Southeast Asian users who purchased products from a reseller called CryptoBillis. As a precautionary measure, and pending the investigation results, CryptoBilis is suspending all sales and shipments of Ledger devices.


At that point no one knew what was going on, until a Frenchman named Mark Karpelès picked up a screwdriver in his workshop.


Two hours later, he posted a tweet. He is the former CEO of Mt. Gox. Mt. Gox was once the world's largest Bitcoin exchange, lost approximately 850,000 bitcoins in 2014, and ended in bankruptcy. When it comes to losing money, he probably has some trauma.

He said, "This Ledger of mine with a spy device implanted came from Malaysia, the shrink wrap was flawless. Even when you open it, at first you can't see the implant: it was cleverly hidden in the spot where the screen buffer pad was supposed to be."



This is a component that measures only 2 millimeters by 2 millimeters. Not much bigger than a grain of rice.



A Brazilian cryptocurrency blogger created an annotated version of Karpelès's teardown photos.




This is the shape of the entire answer.


Attack Path


The security firm SlowMist provided a possible attack path.


The process is: after the seed is generated, the mnemonic words are displayed for you to copy down, thus appearing on the screen. A malicious module connected to the screen data line (such as SPI) records the displayed words, and once all are captured, sends them out via LTE/eSIM. The attacker obtains the mnemonic words and transfers the assets away.


The secure element only protects against "the private key being read or leaked outward" — it cannot stop someone from filming your screen.


The core of a hardware wallet like Ledger is a "secure chip." When you first set up the wallet, this chip generates 24 English words: the mnemonic phrase. These 24 words are your money itself: whoever obtains them can reconstruct your wallet on any device and transfer the funds away, without ever needing to touch your Ledger.


So the device's entire job is to ensure that no one other than you ever sees these 24 words. It displays the words on that tiny OLED screen for you to write down on paper.


Between the screen and the chip, communication relies on a bus called SPI. The mnemonic is rendered by the secure element and pushed to the screen through this line.


What the malicious implant does is attach an ear to this line. It doesn't modify the firmware, doesn't touch the private keys, doesn't change any behavior of the device. It just listens.


It has nothing to do with the computer you use. Your computer can be offline, can be a freshly formatted machine, can have never had any software installed. It will still send out.


Since the official statement has named this well-known distributor in Malaysia, it's easy to associate whether something went wrong internally. Crypobilis responded immediately, but the truth is even more shocking — this distributor had long been transferred.


A Distributor That Was Transferred


In March 2026, CryptoBilis was acquired. The original shareholders withdrew from all operational, managerial, and administrative roles.


The two founders said that earlier this year, CryptoBilis was acquired by new owners. As part of this handover, Vimal and I formally stepped down in March 2026 and completed the transfer of all operational, managerial, and administrative responsibilities.


"Vimal and I spent many years building CryptoBilis with absolute integrity. Seeing our names dragged into something we had no control over and no knowledge of is hard to bear."


The community quickly dug up the transfer contract.


Records show that an individual registered at an address in Heilongjiang Province, China, named Jiaming, became a director of this company on that day.



He served as director for 35 days. Took office on August 3, resigned on September 7. On October 9, 311 wallets were emptied.


More interestingly, the founding team mentioned the existence of a confidentiality clause that restricted public disclosure — before mid-October this year, this transfer could not be disclosed.



Currently, there is no public evidence directly proving a causal relationship between this ownership change and the tampering with the devices. But when the facts are laid out, it is hard for victims not to think in the direction of conspiracy theories.


Open up a Ledger Nano X, and you will find a rectangular recess in the casing above the screen. On a factory-original unit, this recess contains a piece of shock-absorbing foam. Its purpose is simple: when the casing is closed, it gently presses down on the screen to prevent it from shifting, dust ingress, and impact damage.


That piece of foam was gone.


In its place was a small circuit board.


This $100 million attack was not because of high technical sophistication. On the contrary: it was because it was too low-tech.


The attackers did not crack any cryptography. They did not forge firmware signatures, did not breach Ledger's servers, did not find any vulnerability on the blockchain, did not send phishing emails, did not use malware. What they did was open the box, pry out a piece of foam and throw it away, insert a circuit board, and seal the box back up.


From an engineering standpoint, this was a very clean operation. But from the perspective of "trust," it was devastating.


All the rhetoric in this industry points to the same place: don't trust exchanges, don't trust software, don't trust the network, don't trust anyone—hold your private keys in your own hands. And the physical form of "in your own hands" is a hardware wallet. It is the endpoint of this chain of trust. Crypto exchanges can go bankrupt (Mt. Gox, FTX), custodians can be hacked, hot wallets can be stolen, but as long as you have a hardware wallet and a piece of paper with your mnemonic written on it, your assets are safe.


It is the last line of defense. The reason the last line of defense is valuable is because there is nothing behind it.


But the last line of defense in 2026 is full of cracks.


In January, third-party logistics provider Global-e suffered a data breach. Ledger's order data was affected, with names, addresses, emails, and similar information leaked.


In April, fake Ledger Live apps appeared. A counterfeit Ledger Live app passed Apple App Store review and was listed, tricking users into entering their mnemonics. Within 6 days, more than 50 users lost approximately $9.5 million.


On July 30, a 5-year-old vulnerability in the well-known legacy Bitcoin wallet Coldcard was exposed. Within 41 minutes, 1,196 addresses were emptied, and 1,082.65 bitcoins were swept away. A total of $130 million was stolen.

Then came Ledger in October. No one can defend against an attack from this angle.


Ledger's Main Revenue Source


In fact, this attack method was warned about long ago. In an August 2025 Reddit post, someone warned that tampered Nano X devices were being sold. Hardware security researcher Joe Grand followed that lead, bought the device, completed reverse engineering, and publicly released all materials at the hardwear.io conference in May 2026.


Even Ledger itself said years ago that similar backdoored products were on the market.


But they just didn't take one more look at this supply chain.


Perhaps because hardware sales had long ceased to be Ledger's biggest revenue source.

In March of this year, Ledger itself stated that the upgraded wallet app (Ledger Wallet) contributed over 50% of revenue.


In other words: the hardware that sold millions of units is no longer the company's largest revenue source.


Their main revenue comes from the wallet app — that is, transactions.


In October 2025, Ledger changed the name "Ledger Live" to "Ledger Wallet." This wasn't just a name change. After the revamp, it transformed from a management tool into a trading app where users can buy, sell, swap, and spend crypto. Portfolio analysis and a redesigned "Earn" section were also added.


Every time the app facilitates a transaction, Ledger takes a cut. That is, transaction fees.


They also launched Ledger Multisig, priced at a flat $10 per transaction plus 0.05% of the transaction amount.


Hardware wallet sales bring in a few dozen dollars each, far less than the accumulation from countless daily transaction fees.


2025 was Ledger's best revenue year in history.

Ironically, the team attributed the high revenue to crypto security issues, because as industry theft incidents surged, demand for hardware wallets was directly correlated — the more chaotic the industry, the better Ledger sells, and the more people use Ledger to trade.


Their energy was most likely concentrated on the most profitable segment. A year later, the supply chain had a problem.


In August 2019, Ledger's own security lab wrote these words: a hardware implant hidden in a USB cable might be able to steal PIN codes and seed phrases; such a device "could be shrunk to fit inside the cavity of a malicious cable" and reach users through a supply chain attack.


Their conclusion at the time was: theoretically feasible, never demonstrated in practice, and "no evidence of any such hardware implant was found."


Seven years later, someone extracted a variant of it from a device that came from Malaysia. The same idea, only the cable was replaced with an SPI bus, and USB was replaced with 4G.


When a company that makes security hardware no longer derives its primary source of revenue from security, that is precisely when the alarm bells should ring loudest.


Welcome to join the official BlockBeats community:

Telegram Subscription Group: https://t.me/theblockbeats

Telegram Discussion Group: https://t.me/BlockBeats_App

Official Twitter Account: https://twitter.com/BlockBeatsAsia