Crypto Briefing • October 11th 2026, 9:32 PM
Hackers Bypass Ledger's Trust with Hidden Hardware
Key Summary
Hackers reportedly compromised a Ledger reseller, CryptoBilis, and inserted hidden hardware into wallets, draining up to $93 million from affected users. The attack involved capturing users' recovery phrases and sending them over cellular networks. Ledger has confirmed the issue and stopped sales through CryptoBilis.
Please see our real time news feed on our Home Page
Background
CryptoBilis serves customers in Malaysia, Indonesia, and the Philippines. Ledger's position is that the problem is confined to the reseller channel. The company says there is no evidence that its core systems or products sold directly were affected.How the Attack Allegedly Worked
The implants are described as small circuit boards with cellular capabilities, tucked behind the device screens. Their job was to capture a user's 24-word recovery phrase and send it out over cellular networks.The Money Trail
The unusual draining began around October 9, 2026. Researchers spotted significant inflows to theft addresses across several blockchains, including Bitcoin, Ethereum, and Tether's USDT stablecoin.Implications and Next Steps
Anyone who bought a Ledger through CryptoBilis faces an uncomfortable question. If an implant captured the recovery phrase, the device itself cannot be trusted, and neither can any wallet created from that phrase. Moving funds to a wallet generated on a verified device with a fresh phrase is the logical response for anyone exposed.#Bitcoin#US#Crypto#SEC#Malaysia#Indonesia#Philippines