ORBITRUM← Back to Signals

Ledger · security

Ledger Confirms Hardware Wallet Tampering Amid $86 Million Theft Reports

Ledger confirmed on October 10, 2026, that an affected customer's hardware wallet contained an unauthorized implant, while investigators reported more than $86 million in suspected cryptocurrency thefts linked to devices sold through reseller CryptoBilis.

By Orbitrum
Illustration of a Ledger cryptocurrency hardware wallet alongside a magnified view of an unauthorized electronic implant. The image highlights Ledger's confirmation of tampering in an affected device and reports of over $86 million in cryptocurrency stolen. Ledger says its own systems have not been compromised, while an investigation into reseller-supplied devices continues.

Were Ledger's own systems compromised?

Not according to the available evidence. Ledger reported no indication that its internal systems or security infrastructure were compromised, and the investigation has focused on devices distributed through CryptoBilis.

Orbitrum Investor Impact

Why does the hardware tampering matter for Ledger's business?

The incident could damage customer trust in Ledger's hardware security and reseller distribution network, potentially affecting sales and increasing security-related costs. The financial impact on Ledger has not been quantified.

Has Ledger confirmed that more than $86 million was stolen?

No. The figure comes from an independent blockchain investigator tracking suspected thefts across Bitcoin, Ethereum and Tron, not from a confirmed Ledger loss assessment. The number of affected customers and the total losses remain unverified.

How could the modified wallets expose customer funds?

The suspected attack involves an unauthorized circuit board concealed inside a hardware wallet that could capture recovery information displayed during setup. Reports suggest the information could then be transmitted to attackers, potentially allowing them to access the customer's cryptocurrency.

Has CryptoBilis stopped selling Ledger wallets?

Yes. Ledger requested a sales suspension during its investigation, and CryptoBilis subsequently halted hardware-wallet sales. Ledger also advised customers who purchased affected reseller devices within the previous 90 days not to initialize unused devices and to consider moving existing funds to a new wallet with a fresh recovery phrase.

What remains unresolved in Ledger's security investigation?

Investigators still need to establish how the devices were modified, how many customers were affected and whether the discovered implant caused the reported thefts. The findings will help determine the extent of Ledger's supply-chain exposure and the corrective measures required.

Sources

Original signal: The Verge ↗

See more Orbitrum in Google

Add Orbitrum as a Preferred Source to make our research more likely to appear for you in Google Search.