CZ Flags Supply-Chain Threat to Ledger Hardware Wallets

AI Market Summary
CZ and Ledger flagged a supply-chain compromise affecting a distributor, with reports that counterfeit or tampered devices led to wallet drains across Bitcoin, Ethereum, and Tron totaling over $86M. The incident elevates custody and counterparty risk perceptions for self-custody hardware and may pressure near-term crypto risk sentiment as users rotate wallets and scrutinize device provenance. Ongoing investigation leaves uncertainty on root cause and scope.
Impact level
● Medium
Affected assets
BTC/USDT+2.23%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Oct. 9 — Binance co-founder Changpeng Zhao (CZ) urged Ledger hardware wallet users to stay alert, particularly anyone who has bought a device recently, after reports that a supply-chain issue may have led a small number of customers to receive counterfeit or tampered Ledger units. CZ said Ledger remains a well-established and highly secure brand, but warned that even leading hardware wallets can be exposed to supply-chain incidents. He called on the BNB ecosystem and the wider crypto industry to help trace the stolen funds and support recovery efforts. Ledger has confirmed it is investigating a theft affecting users in Southeast Asia. The company said the devices in question were purchased via distributor CryptoBilis, and it has asked the distributor to halt sales and shipments. Ledger advised customers who bought devices through CryptoBilis within the last 90 days not to initialize them. Users who have already completed setup were told to create a new Ledger signing device with a new recovery phrase and move assets to the new wallet. On-chain investigator Specter estimates hundreds of wallets across the Bitcoin, Ethereum and Tron networks were compromised, with losses exceeding $86 million. Security researcher tanuki42 previously pegged losses at more than $72 million and said the figure continues to climb. The root cause and whether any affected devices contained security vulnerabilities remain under investigation.