Blockchain

Ledger confirms hidden implant in CryptoBilis victim’s wallet as losses near $93 million

Legal & CrimeAshton Addison·October 10, 2026·6 min read

Ledger confirmed on Saturday that at least one wallet belonging to a victim of the CryptoBilis drain had an unauthorized hardware implant inside it. The finding backs up the photos former Mt. Gox CEO Mark Karpelès posted a day earlier, but Ledger still has not said the implant caused the losses, which on-chain trackers now put between $72 million and $93 million.

  • Ledger Support said on October 10 that one impacted user’s device contained an unauthorized hardware implant, the first company confirmation of physical tampering in the case.
  • CryptoBilis, an authorized Ledger reseller for Malaysia, Indonesia and the Philippines, has stopped selling all hardware wallet inventory, not only Ledger units, until the investigation ends.
  • Karpelès’s teardown shows a cellular implant hidden behind the screen that reads the recovery phrase off the display during setup, a design that can still pass Ledger’s Genuine Check.
  • $72M to $93.4M Range of suspected losses across independent on-chain estimates; Ledger has confirmed none of them
  • 471 addresses Suspected victim addresses counted by tracker Yfarmx in its $93.4 million estimate
  • 90 days Purchase window Ledger flagged for CryptoBilis buyers

Ledger confirms an implant, not yet a cause

Ledger’s situation update on Saturday moved the story from rumor to documented tampering. The company said one of the impacted users’ devices held an “unauthorized hardware implant,” that it is contacting affected customers, and that anyone with information should reach it through its bounty program. It thanked the volunteer security response group SEAL 911 for help and said it is working with authorities.

Ledger also said it has no sign that its own security infrastructure, systems or services were compromised, and that it is building stronger anti-tampering measures. What it has not said is just as important: how the implant got into the device, how many units carry one, and whether the implant explains every drained wallet. Bitcoin.com News and others noted that Ledger has not verified any of the loss totals.

The update came one day after Ledger first asked CryptoBilis to pause sales and shipments on October 9. CCS covered that first pause here. CryptoBilis has since widened the halt to its entire hardware wallet inventory, which matters because the reseller also lists other wallet brands.

What Mark Karpelès found inside the Nano X

Karpelès, who ran the Mt. Gox exchange before its 2014 collapse, posted photos on October 9 of a Ledger Nano X circuit board next to the implant he said was hidden inside it. He asked anyone affected to open their device and send him pictures so he could check for the same hardware.

According to Karpelès, the implant packs a microcontroller, an LTE cellular modem, an antenna and an eSIM into the foam pad that normally sits behind the screen. The microcontroller is wired to the SPI bus, the internal line the Nano X uses to send text to its display. That placement is the whole trick. A hardware wallet never lets the seed phrase leave its secure chip, except in one place: the screen, during first setup, when the owner writes the 24 words down. An implant that copies what the screen shows can capture the phrase at that moment and send it out over a mobile network, with no internet connection to the computer needed.

Because the genuine Ledger secure element is left untouched and still generates a real seed, the device can pass Ledger’s Genuine Check. Ledger’s own threat model documentation says that check verifies the secure element and cannot guarantee that the rest of the hardware is unmodified. Physical signs that a unit was opened include a stray antenna wire, a battery that looks smaller than normal, or a missing pad behind the screen.

Karpelès has since published a research page collecting his findings and said his next steps are to analyze each SIM card and extract the firmware from each microcontroller. He also asked CryptoBilis to open unsold units from its stock to see whether they carry the same part. On October 9 it was not yet established that the device he photographed came from CryptoBilis; Ledger’s Saturday confirmation is the first link between an implant and a CryptoBilis victim.

How big the losses are, and where the money went

The totals keep moving because each tracker counts a different set of addresses, and some may overlap:

  • Analyst Specter put losses above $86 million across Bitcoin, Ethereum and TRON.
  • Investigator tanuki42 traced more than $72 million to suspected theft addresses.
  • Arkham put the figure above $80 million; SlowMist’s MistTrack said it was approaching $90 million.
  • Yfarmx counted $93.4 million across 471 addresses, and Bitquery about $92.9 million across 311 unique addresses.

MistTrack reported that Tether froze a significant amount of USDT at addresses tied to the incident, which may limit how much of the stablecoin portion the attackers can move. Bitcoin and ETH have no equivalent freeze.

One case shows how the attack plays out. Lookonchain flagged a trader who bought a new Ledger from CryptoBilis and moved 80 BTC onto it on September 29. Public mempool records show all 80 coins, roughly $6.6 million, leaving in a single transfer at 05:54 UTC on October 9, ten days later. Another user, Edward Winz, said publicly that he lost about $1 million.

A known attack, now through an official channel

Hardware implants in Ledger devices are not new. Security researcher Joe Grand reverse engineered a Nano X implant found in a secondhand unit bought in Thailand, where the battery had been shrunk to make room for a small board that tapped the same display interface. Earlier cases involved USB drives soldered inside devices and fake units with swapped chips sold on marketplaces.

The difference this time is the sales channel. CryptoBilis was listed in Ledger’s official reseller directory, the place buyers are told to go precisely to avoid tampered stock. Binance co-founder Changpeng Zhao said early on that the evidence pointed to a supply chain attack localized to one vendor. Posts circulating on X allege that CryptoBilis changed ownership earlier this year; CCS has not been able to verify that claim, and neither Ledger nor CryptoBilis has addressed it.

Many replies to Ledger’s update asked whether victims will be compensated, arguing that an authorized reseller is Ledger’s responsibility. Ledger has not answered that question.

What CryptoBilis buyers should do now

  • Not set up yet? Do not initialize the device. Ledger’s guidance covers any unit bought from CryptoBilis in the last 90 days.
  • Already set up? Ledger advises moving funds to a new Ledger signer bought directly from the manufacturer, with a brand new seed. Do not reuse the old 24 words on the new device, because the old phrase may already be in someone else’s hands.
  • Bought from another reseller? There is no sign so far that other channels are affected, but checking for signs the case was opened costs nothing.
  • Watch for scams. Ledger will never ask for your recovery phrase. Expect fake “Ledger support” messages and refund offers to target victims.

The CCS read. This is a supply chain failure, not a broken Ledger chip, but that distinction offers little comfort to people who did everything right and bought from an authorized seller. The implant works because it attacks the one moment self-custody depends on a human reading a screen. Buying direct from the manufacturer just went from good advice to the only advice, and hardware makers will now be judged on how well they police their own reseller lists and whether they stand behind buyers when those lists fail.

Next to watch: whether Ledger confirms more implanted devices or ties the implant to the full loss figure, results of Karpelès’s SIM and firmware analysis, whether CryptoBilis explains how tampered units entered its stock, any recovery or freeze of the Bitcoin and ETH, and whether Ledger offers affected buyers compensation or replacement devices.

Get this in your inboxThe Crypto Coin Show newsletter covers the security, policy and market moves crypto investors need to know.
Subscribe