Reports have been mounting that users of the Ledger crypto wallet have seen their accounts drained, and it appears to be related to tampered hardware sold by CryptoBillis. Ledger has asked CryptoBillis to pause all sales of its wallets while it conducts an investigation. Ledger has confirmed that “one of the impacted users’ devices contained an unauthorized hardware implant.”
Photos and videos posted on X and Threads appear to show a small circuit board sandwiched under the screen. The implant allegedly intercepts anything displayed on the screen, including the seed passphrase shown during the initial setup. Using an embedded SIM card, the implant then sends that information back to the attacker, who can then siphon funds from user accounts.
This content isn’t visible due to your cookie preferences. To load this content, click the Allow button below to opt in to “Social Media & Embedded Content” cookies. These cookies are set and controlled by the third party sources from which the embedded content originates.
Reports indicate that whoever is behind the hack has stolen over $86 million worth of crypto from hundreds of wallets. There’s no indication that Ledger’s systems have been compromised or that wallets purchased directly from the company have been affected.
Instead, the issue appears to be a supply chain attack primarily involving users in Southeast Asia and the CryptoBillis reseller. Ledger has provided guidance on how to check if your wallet has been tampered with.
Update October 10th, 2026: Added additional statment from Ledger.
