Ledger: Allegedly Bugged Wallets Cost Users Millions
Trending Topics auf Google als bevorzugte Nachrichtenquelle festlegen.
The very device meant to keep crypto safe has become a trap: The French hardware wallet maker Ledger is investigating reports of crypto losses among customers in Southeast Asia. According to Ledger, the affected devices were sold through CryptoBilis, an authorized Ledger reseller for Indonesia, Malaysia and the Philippines. Ledger has asked CryptoBilis to halt all sales and shipments, the company said on X.
Up to $86 Million Gone
Ledger has not confirmed the size of the losses. The blockchain analytics platform Arkham most recently counted about $71.5 million (about €64 million) on addresses it has labeled “ledger-drainer,” including $29.4 million in ether and $17.5 million in bitcoin. The on-chain analysts Specter and tanuki42 estimate losses at between $72 million and more than $86 million (up to €77 million), spread across hundreds of affected wallets on the Bitcoin, Ethereum and Tron networks.
Ledger said it has “no indication that Ledger’s security infrastructure, systems or services have been compromised.” The incident appears to be limited to the one reseller and its market, and devices bought directly from Ledger are not affected, the company said. Customers who bought from CryptoBilis in the past 90 days should not set up their devices. Anyone who already has should move their assets to a new Ledger device with a new recovery phrase. CryptoBilis has not commented publicly, and Ledger has not accused the reseller of tampering.
A Cellular Modem Inside the Wallet
How attackers might have obtained the funds is suggested by an analysis from Mark Karpelès, the former head of the crypto exchange Mt. Gox. He says he took apart a shrink-wrapped Ledger device bought in Malaysia and found a hidden second circuit board with an antenna, a cellular module and a data eSIM. According to Mr. Karpelès, the chip recognizes the Ledger font on the display, captures the recovery phrase during setup and sends it out over the cellular network. Ledger’s firmware cannot detect this, he said, because the implant only reads the screen. His account has not been confirmed, and it is unclear whether his device came from CryptoBilis.
The problem could extend beyond Ledger. CryptoBilis also sells wallets from Trezor, Tangem, SafePal, OneKey and other makers. Rob Hamilton, chief executive of the crypto insurer AnchorWatch, advised anyone who bought from the reseller to move their funds immediately.
A Warning Against Panic
The security researcher Taylor Monahan, by contrast, warned against panic. It does not look like a zero-day, she said, meaning a previously unknown flaw in Ledger’s technology. The greater danger now comes from phishing links, fake Google ads and counterfeit apps targeting users as they hurriedly move their funds.
It is not Ledger’s first trouble this year: In January, a data leak at the payment provider Global-e exposed the names and contact details of Ledger buyers. The crypto industry remains a target in general. The exchange Bitget recently lost $352 million in a hack, and before that, bitcoin worth $320 million was stolen from the Liquid Network.

