Ledger probes CryptoBilis-linked wallet drain, losses estimated near $90 million
AI مارکیٹ کا خلاصہ
Reports of a ~$90m wallet-drain tied to Ledger devices sold via authorized distributor CryptoBilis revive supply-chain risk concerns in self-custody. Even if Ledger's core systems were not breached, the incident can pressure near-term crypto sentiment by raising perceived operational risk, increasing caution around hardware wallets and related on-chain activity. Ledger's directive to halt sales and urges to migrate assets may add to short-term risk aversion.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+2.23%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Odaily Planet Daily reports that hardware wallet maker Ledger is dealing with another security incident, with third-party security firms putting the impact at close to $90 million.
Ledger said it is investigating funds lost in connection with devices sold through its authorized Southeast Asia distributor, CryptoBilis, and has asked the distributor to halt all sales and shipments. Users who purchased devices via this channel within the past 90 days are urged to proceed cautiously and consider moving assets to a safe wallet.
The root cause has not been confirmed. Early indications point to a supply-chain compromise or device tampering.
Ledger's major past incidents and disclosures include:
• 2018: Researchers highlighted multiple early hardware and supply-chain risks, including the potential to tamper with Nano S devices before shipment, MCU bootloader bypass techniques, isolation weaknesses, and Bitcoin change-address injection. Ledger issued advisories and rolled out fixes; most issues were research-level or required physical access.
• 2020: A large-scale customer data breach. Attackers leveraged third-party API keys and Shopify-related weaknesses to access e-commerce and marketing databases, exposing more than 1 million email addresses and roughly 272,000 to 292,000 customer records (names, addresses, phone numbers). Hardware wallets and private keys were not compromised, but the breach fueled long-running phishing, social engineering and impersonation scams using forged communications.
• December 2023: A supply-chain attack on Ledger Connect Kit. A former employee's NPMJS account was compromised via phishing, enabling attackers to publish a malicious Connect Kit version. The tainted library injected code into DApps that relied on it, prompting users to sign transactions that drained funds. The exposure window was about two hours, with estimated losses of $480,000 to $600,000. Ledger hardware devices and Ledger Live were not directly compromised.
• January 2026: A third-party Globale order-data incident. Unauthorized access to the payment and logistics partner's systems exposed certain Ledger.com order details, including names, addresses and contact information. Ledger's internal systems and private keys were not affected, though phishing risk increased.
• April 2026: A counterfeit Ledger Live app appeared on the App Store and tricked users into entering seed phrases. The fake app remained available for about a week, causing roughly $9.5 million in losses across more than 50 victims and multiple blockchains. Apple removed the app; Ledger reiterated it will never request a 24-word seed phrase.
• August 2026: Ledger disclosed Ethereum app signing vulnerabilities, including command interleaving that could desynchronize on-screen information from signing parameters and clear-signing bypass issues. Exploitation required cooperation from a malicious host; Ledger said it found no evidence of user exploitation and noted the issues were fixed in newer versions.
• October 9, 2026: A large-scale wallet-draining event tied to the CryptoBilis distribution channel, with losses estimated near $90 million. Ledger said the incident appears concentrated in a single channel and is consistent with supply-chain compromise or device tampering. Sales have been suspended and potentially affected users have been advised to migrate assets.