환율 -
|
USDT(업비트) -
|
BTC.D -
|
총시총 -
|
접속 0

Ledger confirms unauthorized implant in one victim's device; reseller CryptoBilis halts sales

Ledger confirms unauthorized implant in one victim's device; reseller CryptoBilis halts sales

Ledger confirmed an unauthorized hardware implant in one affected user's device on Oct. 11 KST.

CryptoBilis halted sales of all hardware wallet inventory until the probe concludes.

Bitquery counts about $93.2 million drained from 315 wallets; Ledger has not confirmed the figure.

광고

Hardware wallet maker Ledger confirmed that a device sold through Southeast Asian reseller CryptoBilis contained an unauthorized component. In a situation update posted on X at about 2 a.m. KST on Oct. 11, Ledger's support account said "one of the impacted users' devices contained an unauthorized hardware implant." It is the first time in this case that Ledger has officially confirmed physical tampering with a device.

In the same update, Ledger said CryptoBilis had ceased sales of all hardware wallet inventory until the investigation is concluded. CryptoBilis is registered as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines. Ledger said it is reaching out to affected users and working with the appropriate authorities to bring those responsible to justice. It is collecting information through its bounty program at bounty@ledger.fr.

Two weeks of test transfers, half a day to drain

Combining Ledger's statements with an on-chain reconstruction by blockchain data firm Bitquery gives the following sequence.

  1. Addresses used by the attacker on Tron and Ethereum received their first funds. More than 40 test transfers followed on the two networks through Oct. 7.
  2. New permission keys were added to 30 Tron wallets, taking control away from their owners. Eight minutes later, about $29 million was pulled at once from other Tron wallets.
  3. 111 bitcoin wallets were emptied in a single block. About 203 BTC was taken.
  4. Ledger issued its first notice, saying it had asked CryptoBilis to stop sales and shipments.
  5. Former Mt. Gox CEO Mark Karpelès posted photos of a component hidden inside a device that came from Malaysia.
  6. Ledger said it had found an unauthorized component in one victim's device.

All times are KST. Ledger has not yet confirmed the number of affected customers or total losses, and has not said whether all of the thefts stem from tampered devices.

광고

The shrink wrap was intact

Photos of the component in this case surfaced a day before Ledger's confirmation. Karpelès, who once ran the Japanese bitcoin exchange Mt. Gox, wrote on X: "My spy-implanted ledger came from Malaysia, and had flawless shrink wrap." He said the implant is not visible at first even after opening the device, because it is cleverly hidden where the screen's padding is supposed to be.

A hardware wallet shows a 24-word recovery phrase, or seed, on its screen during initial setup. Summarizing Karpelès' account, French crypto outlet Cryptoast said the component contained a SIM card and a modem, allowing it to intercept the 24 words as they appear on screen and send them over the mobile network without going through the victim's computer or phone. Ledger has not disclosed how the component is built or how it works. "We have no indication that Ledger's security infrastructure, systems or services have been compromised," Ledger said, adding that it is working on further anti-tampering measures.

5.35 million USDC that Circle could freeze

Bitquery counted about $93.2 million drained from 315 wallets across six networks as of Oct. 11. Ledger has not confirmed that figure. The amount still traceable on-chain fell from $88 million to about $81 million in a day.

According to Bitquery, the attacker pushed another 1,736 ETH on Oct. 10 into Tornado Cash, a mixing service used to obscure fund flows. The money passed through Zcash (ZEC) and landed as 4.29 million USD Coin (USDC) in four new wallets. Including one untouched wallet from the Oct. 9 mixing, 5.35 million USDC sits in five wallets that have never sent a payment. USDC issuer Circle can freeze all of it.

On Tron, the attacker took a different route. Bitquery said Tether blocked 37 addresses linked to the theft on Oct. 9, freezing $10 million in USDT. The attacker converted $5.1 million of funds it had parked in USDD, a stablecoin Tether cannot freeze, back into USDT and sent it to five wallets that appear to be over-the-counter (OTC) desks. Those wallets then sent 5.2 million USDT to three Binance deposit addresses. Bitquery noted, however, that the OTC wallets handle funds for many clients. The remaining $10 million in USDD is still sitting in the attacker's wallets.

What CryptoBilis buyers should do

Ledger repeated that anyone who bought a device from this reseller and has not set it up should not initiate setup. Those already using one should consider moving assets to a new Ledger device with a new recovery phrase. Ledger said it will never ask for the 24-word recovery phrase and urged users to rely only on official support channels (support.ledger.com) to avoid scams exploiting the incident.

This article summarizes public announcements and documents. It is not investment advice; investment decisions and their consequences are your own.