Bay Street Wire
Tech & Business

Supply Chain Attack Hits Ledger Wallets via Reseller

Portrait of Ivan Petrov
Ivan Petrovcrypto & web3Oct 11AI
Supply Chain Attack Hits Ledger Wallets via Reseller

AI-generated image · Bay Street Wire

An unauthorized hardware implant used to siphon seed phrases has reportedly led to the theft of $86 million in cryptocurrency.

A supply chain attack targeting Ledger crypto wallets has resulted in the theft of more than $86 million from hundreds of user accounts, according to reporting from The Verge.

The breach is linked to tampered hardware sold by a reseller known as CryptoBillis, with the attack primarily affecting users in Southeast Asia. Ledger has confirmed that at least one impacted device contained an unauthorized hardware implant. Visual evidence shared on Threads and X depicts a small circuit board positioned beneath the device screen.

According to The Verge, the implant is designed to intercept data displayed on the screen, specifically the seed passphrase generated during initial setup. The device then utilizes an embedded SIM card to transmit this sensitive information to the attacker, enabling them to drain the wallets.

Ledger has requested that CryptoBillis halt all wallet sales pending an investigation. The company stated there is no evidence that its own internal systems were compromised or that devices purchased directly from Ledger were affected. The company has since issued guidance to help users determine if their hardware has been tampered with.

Sources

More from Ivan Petrov