Static

Ledger wallet tampering suspected after reports of crypto thefts

First reported by The Verge ·

The signal ●○○○ Compiled by AI from The Verge, the single source so far
Why you might care

If you bought a Ledger hardware wallet from a third-party reseller, you must verify it for tampering before use.

What happened

Multiple reports indicate significant cryptocurrency thefts from Ledger wallets, with suspicion falling on a supply chain attack involving reseller CryptoBillis. Users have shared images and videos on social media platforms like X and Threads, appearing to show a hardware implant concealed within the wallet's screen assembly. This alleged implant is believed to intercept sensitive information, such as seed passphrases displayed during initial setup. The compromised data is then reportedly transmitted via an embedded SIM card to attackers, who subsequently drain user accounts. Over $86 million in crypto has allegedly been stolen from hundreds of wallets. Ledger has requested CryptoBillis halt sales and is investigating the matter, while also providing customers with instructions on how to verify their devices for tampering. The company states its own systems have not been breached and that wallets bought directly from Ledger are not affected.

What it means

This incident highlights a critical vulnerability in the hardware wallet supply chain, suggesting that even devices designed for high security can be compromised before reaching the end-user. The alleged method of interception, involving a physical implant that captures screen data and transmits it wirelessly, represents a sophisticated attack vector previously less discussed in the context of hardware wallets. The scale of the alleged theft underscores the significant financial risks associated with such supply chain breaches in the digital asset space.

The focus on resellers like CryptoBillis, particularly in specific geographic regions, indicates a targeted approach that could be replicated. This situation compels users to exercise extreme caution, expanding their security considerations beyond the manufacturer's direct controls to include the entire distribution network. Future security measures will likely need to address more robust tamper-evident packaging and potentially direct-to-consumer verification protocols for sensitive hardware.

AI-written summary. May contain errors.

Crypto