Ledger Pauses Reseller Sales After Suspected Supply-Chain Tampering

Ledger has asked reseller CryptoBilis to pause device sales and shipments while it investigates suspected hardware tampering tied to drained customer wallets.
The request follows user reports of accounts being emptied after setup on devices sourced through CryptoBilis. Ledger has warned recent buyers who purchased from that reseller and published guidance on how to check whether a device has been tampered with, according to reporting by The Verge.
Reports put the losses at more than $86 million across hundreds of wallets. CoinDesk reported that figure on Oct. 9, 2026, and current reporting as of Oct. 10, 2026 continues to cite over $86 million. The number was described at the time as an analyst's claim based on onchain tracking, not a Ledger-confirmed total, as noted by Yahoo Finance. Bloomberg had earlier on Oct. 9 described the incident as an estimated $70 million attack. The later figure supersedes that early estimate.
The suspected cause is physical tampering in the supply chain. Photos and videos shared by researchers appear to show a small extra circuit board hidden under the wallet screen. That board allegedly records anything shown on the display, including the 24-word recovery phrase, the human-readable backup code shown during setup. The captured data is then sent out over a built-in cellular connection to the attacker, who can rebuild the backup code and steal the funds.
Ledger describes the case as a supply-chain attack focused in Southeast Asia and centered on the CryptoBilis distribution path, The Verge reported. There is no indication that Ledger's own systems were compromised. There is also no indication that devices bought directly from Ledger were affected. The pause request to CryptoBilis, detailed by The Defiant, covers both sales and shipments pending the outcome of the investigation.
The key technical detail is where the tap sits. The attack does not need to break the secure element, the locked-down chip that holds keys, or defeat firmware checks. It sits on the display path. Hardware wallets use separate hardware to create backup codes and verify transactions, so a hacked computer or phone cannot see what the user approves. An implant that watches the screen cable gets around that protection without touching the cryptography. It grabs the secret at the one moment it has to be readable for backup.
The broader context here is why a separate cellular radio makes detection harder. A normal add-on that uses USB or Bluetooth would leave traces on the user's computer or phone, in logs or radio activity tied to use. A board with its own cell connection does not. It can send the stolen recovery phrase at once, quietly, from anywhere with coverage. The theft can then happen days or weeks later, after the device looked fine and the user thought setup was clean. That delay breaks the link users depend on to find the cause.
For buyers, the practical lesson is an old rule with new urgency. Buy direct, check tamper-evident packaging, and treat any third-party seller as untrusted until proven otherwise. Companion-app checks help, but they only verify firmware and chip state. They cannot see a passive listener attached to the screen cable. Physical inspection still matters, including checks for display problems, added thickness, strange seams, or cellular activity that model should not have. Ledger's inspection guidance is the correct first reference for owners of potentially affected units.
In my view, worth noting is how fixable this type of failure is. Supply-chain tampering is not new, and we have seen this pattern before with PCs and networking gear. Tighter controls on authorized sellers, tracked serial numbers, sealed cases that show clear damage if opened, and clear advice never to set up large holdings on hardware of unknown origin all lower the risk. None of that needs new cryptography. It needs careful handling across distribution. The long arc still favors self-custody hardware, as long as buyers treat where they bought it as part of security.


