MinerCompare Logo
News

Ledger Hardware Implant in Southeast Asia: What We Know and How to Protect Your Coins

Ledger has confirmed an unauthorized hardware implant in a device sold through a Southeast Asian reseller, and analysts trace tens of millions in stolen crypto to the case. What is confirmed, what is still rumour, what to do if you own a Ledger, and why miners should care.

10 min read MinerCompare Team
Dark banner with the title Ledger Hardware Implant in Southeast Asia

On 10 October 2026 Ledger confirmed that a device sold through a Southeast Asian reseller contained an unauthorized hardware implant, after customers reported drained wallets worth tens of millions of dollars. The case is still developing, so this article separates what has been confirmed from what is only claimed, and explains what you should do if you own a Ledger or any other hardware wallet.

The short answer

This looks like a tampered-device supply-chain case, not a hack of Ledger. Customers who bought through one reseller, CryptoBilis, had their wallets emptied from 9 October. Ledger asked the reseller to stop selling, then confirmed a hardware implant in one affected device.

If you did not buy through that reseller, nothing in the public reports says your device is at risk. If you did, do not set the device up, and if you already have, move your coins to a new wallet with a new recovery phrase.

How the case unfolded

The first reports came on 9 October 2026. Customers in Southeast Asia described wallets emptied shortly after setup, and on-chain analysts began tracing the stolen funds. Ledger said it was investigating a specific issue concerning the reseller CryptoBilis and asked it to pause all sales and shipments of Ledger devices.

CryptoBilis is listed as a Ledger reseller for Indonesia, Malaysia and the Philippines, and it also sells hardware wallets from other makers. Mark Karpelès, the former head of Mt. Gox, publicly claimed that devices sold by the reseller had been tampered with and carried spyware.

On 10 October Ledger posted an update confirming an unauthorized hardware implant in the device of one affected user. The reseller suspended its hardware-wallet sales until the investigation ends, and Ledger said it is working with the authorities and thanked the SEAL 911 security group for its help.

Four numbered steps showing how the Ledger reseller case unfolded, from the first thefts to the implant confirmation and the advice to move funds
The case in four steps, from the first reported thefts on 9 October to Ledger’s confirmation of an implant.

What is confirmed and what is not

A story like this moves fast, and rumours travel faster than facts. These are the points that Ledger or several independent sources support.

  • Ledger investigated the reseller and asked it to stop selling. Ledger said this itself, and the reseller later suspended hardware-wallet sales.
  • Ledger confirmed an unauthorized hardware implant in one affected device. It has not said which model it was, how the part was installed or whether it sent anything out.
  • Ledger says it has no indication that its own systems were compromised. It is working on additional anti-tampering measures.
  • Large amounts left many wallets in a short time. Several analysts traced the movement across Bitcoin, Ethereum and TRON, even though their totals differ.

Other points are still open, and anyone who states them as fact is guessing.

  • Whether the implant explains every theft. Ledger has not tied the one confirmed device to all the losses.
  • How many devices and customers are affected. No official number exists.
  • Who did it. No group, arrest or seizure has been reported.
  • Whether the reseller knew. Whether it was a victim, a negligent link or involved is not established, and we will not guess.

How a hardware implant can steal a recovery phrase

A hardware wallet keeps your keys in a secure chip, but the recovery phrase still has to travel to your eyes. During setup the device shows 24 words on its screen and you write them down. Anything that can read the screen’s data lines at that moment can read the words too, without ever touching the secure chip.

This is the mechanism security researchers have described for this case: a small microcontroller wired to the display, recording the characters shown and sending them out through a cellular link. Karpelès showed images of a device with a small component hidden under the screen area. Ledger has not confirmed these technical details, so read them as a working theory.

The same logic explains why an attacker needs the device before you do. Once you have generated the phrase yourself on an untouched device, an implant added later would have nothing new to record. The risk sits at the moment of setup, which is why a tampered unit is far more dangerous than one bought clean and left on a shelf.

What the inside of a Ledger Nano X should look like

An untouched Ledger Nano X has nothing under its screen. The device has two sides: the component side, with the main chip, the USB-C port and the battery connection, and the screen side, which carries only the OLED display and its connector. The two photos below show an unmodified device opened for reference.

Inside of an untouched Ledger Nano X, component side: a green circuit board with the main chip, a USB-C port and small chips, laid out next to the open black case with its lithium polymer battery, the metal shell and the key ring
Component side of an unmodified Nano X. The main chip, the USB-C port and the battery connection sit here.
Inside of an untouched Ledger Nano X, screen side: the green circuit board shows only the black OLED display and its flat connector, with no extra board or component under the screen
Screen side of an unmodified Nano X: only the OLED display and its connector. Nothing is hidden beneath it.

Now compare that with the screen side of a tampered unit. With the display lifted off, three parts show up where an untouched device has only a flat surface: a chip on the left, a Nordic nRF9151 cellular module in the middle and a second chip on the right, next to the display connector. The markings on both chips look ground off, so we have marked them by position and by the Tibane Labs diagram below, not by what is printed on them.

Photo of the screen side of a tampered Ledger Nano X with the display lifted off, with three parts outlined in red: 1 a chip on the left with ground-off markings, 2 a Nordic nRF9151 cellular module in the middle, 3 a second chip on the right beside the display connector
Screen side of a reported tampered Nano X, annotated by us. Parts 1 and 3 are chips with ground-off markings and part 2 is the Nordic nRF9151 cellular module. None of the three belongs under the screen of an untouched device.

Researchers describe a different picture in a tampered device: lift the screen and an extra board sits underneath. The diagram below credits the Tibane Labs article and users’ disassembly photos, and labels an eSIM, a Nordic nRF9151 cellular module and a second microcontroller under the display, with a coaxial antenna cable along the edge. It is a translated and annotated summary, so read the component placement as indicative and not as an official teardown.

Annotated diagram of a tampered Ledger Nano X: with the screen removed, an additional board with an eSIM, a Nordic nRF9151 cellular module and a microcontroller is exposed, with a coaxial antenna cable and a U.FL antenna terminal
Annotated diagram of the reported tampered layout, based on the Tibane Labs article and user photos and translated from a Japanese original.

The photo below was shared as the European finding. It shows a Nano X opened up, with red wires soldered to the battery’s protection board, a black coaxial cable ending at a soldered pad on the case, and what looks like a second board beneath the main board. The battery label also differs from the reference unit above, which alone proves nothing. We cannot verify who took the photo or when, and Ledger has not commented on it.

Opened Ledger Nano X shared as the European finding: red wires soldered to the battery protection board and a black coaxial cable soldered to the case, leading to a green circuit board with what looks like a second board beneath it
Photo shared on social media as the European finding. It is unverified: its origin and date are unknown.

How much was taken

There is no official total. Independent analysts counted the stolen funds on-chain, and their figures differ because they group wallets differently and price the assets at different moments.

Third-party estimates as of 11 October 2026, not confirmed by Ledger. The wallet counts are not directly comparable.
Source Estimate Wallets
Specter $86.9M+ ≈ 98
tanuki42 $72M+ –
Bitquery ≈ $92.9M 311

Most of the value moved on Ethereum, TRON and Bitcoin, with Bitquery also naming BNB Chain and Polygon. Some of the stolen Tether has been frozen, and tracking firms report part of the Ether going into mixing services, which makes recovery harder with every hour.

The report from Europe

One person reported on social media that a Ledger bought a few weeks ago from a European reseller contained a similar implant. The post described unusual wiring that a normal device does not have, and said no funds had been stolen from it.

This is the weakest part of the story. No reseller or country was named, no photo has been verified by Ledger or by us, and Ledger has not commented. If it holds up, it would mean the problem is not confined to Southeast Asia, so it deserves attention without being treated as established.

If you own a Ledger: what to do now

The steps depend on where the device came from, and they follow Ledger’s own published guidance.

1

Bought from CryptoBilis and not set up

Do not start setup. Keep the box and contact Ledger through its official support page.

2

Bought from CryptoBilis and already set up

Treat the recovery phrase as compromised. Create a new wallet on a device you trust, with a new phrase, and move your coins there.

3

Bought anywhere else

Nothing in the public reports says your device is affected. Check that the packaging was sealed and that you generated the phrase yourself.

4

Whatever you do next

Use only official Ledger channels. Ledger never asks for your recovery phrase, and nobody offering help or recovery should either.

Move the funds in a calm order: send a small test amount first, confirm it arrives, and then move the rest. Do it from a clean computer, and ignore any link in a message that tells you to hurry.

Why miners should care

A miner’s whole output ends up in an address, and the address comes from a wallet. Pool payouts, solo block rewards and rental income all go to whatever address you give the pool. If the phrase behind that address was recorded at setup, every future payout belongs to someone else.

Miners also buy hardware from resellers, the same kind of channel that failed here. The lesson applies to an ASIC just as it does to a wallet: the cheapest or the most convenient seller is not always the safe one.

How to buy and set up a hardware wallet safely

None of these steps is complicated, and together they would have prevented almost every theft described here.

  • Buy from the maker or an official reseller. Open the maker’s own site and follow its link to the reseller list, never a link from an ad or a message.
  • Inspect the box and the device. Look for broken seals, signs of glue or tools, a device that is already set up, or a card with words already written on it.
  • Generate the phrase yourself. A phrase that came on a card, a PDF or a message is never yours alone, so reject any device that arrives with one.
  • Write the phrase on paper, once, away from cameras. Never photograph it, type it into a phone or store it in a cloud note.
  • Send a small test amount before the real one. Also confirm the address on the device screen, not only on your computer.
  • Split larger sums. Use more than one wallet for large holdings, so one failure does not take everything.
Four numbered steps for buying and setting up a hardware wallet safely: buy direct, inspect the device, create your own phrase, test with a small amount
The four checks that matter most when you buy and set up a hardware wallet.

The same care applies when you buy mining hardware. Our buying guide explains how to judge a seller, and the vendor pages show who is verified on this site. ASIC Miner Buying Guide: What to Check Before You Pay · Verified ASIC Miner Vendors

The scams that follow the headlines

Every incident like this brings a second wave of fake help. Researchers have already warned about fake search ads, fake migration apps and messages that promise to recover stolen funds for a fee.

  • Ledger will never ask for your 24-word recovery phrase, by message, call, form or app.
  • Support never contacts you first. Go to the official site yourself and type the address by hand.
  • A recovery service that asks for an upfront fee or for access to your wallet is a second theft.
  • Download wallet software only from the maker’s official site, and check the address twice.

Earlier Ledger incidents, for context

This is not Ledger’s first security headline, but it is a different kind of problem from the earlier ones.

  • December 2023: a malicious software library. A compromised release of Ledger’s Connect Kit was used to drain wallets for a few hours before it was replaced.
  • January 2026: an exposure at a payment partner. A breach at the partner Global-e exposed order data of Ledger customers. Payment data and recovery phrases were not affected, but phishing followed.
  • October 2026: tampered devices in one sales channel. The current case involves physical modification before the device reaches the customer.

These articles and pages go further on wallets, pools and safe setups. How to Set Up an ASIC Miner: Power, Network, Pool and Cooling, Step by Step · Bitcoin Mining Pools Explained: The Largest Pools, Fees and Payout Methods · Is Solo Mining Worth It? The Honest Bitcoin Odds in 2026 · Crypto Mining Pools · Bitcoin Mining Calculator

Bottom line

A hardware wallet is only as trustworthy as the path it took to reach you. The Ledger case shows that a genuine brand can still arrive modified through a weak link in the sales chain.

Buy direct, create your own phrase, test with small amounts and ignore anyone who offers help unasked. If you bought through the reseller named in this story, move your coins now, and follow only Ledger’s official instructions.

The guide covers power, network, pools and wallets, so your miner and your payouts start on a safe footing.

Read the mining guide
* FAQ

Questions people ask

Customers who bought Ledger devices from the Southeast Asian reseller CryptoBilis reported drained wallets from 9 October 2026. Ledger asked the reseller to pause sales, then confirmed an unauthorized hardware implant in one affected customer’s device. The investigation is still running.

Ledger says it has no indication that its own infrastructure, systems or services were compromised. The case points to tampered devices that reached customers through one reseller, which is a supply-chain problem and not a breach of Ledger’s servers.

No. Ledger’s warning covers devices bought through CryptoBilis, and the reports so far describe a limited channel, not the whole product line. A device bought directly from Ledger or from a verified reseller is not part of this case.

Do not start setup on a device you have not initialised yet. If you already set it up, treat the recovery phrase as compromised, create a new wallet on a device you trust with a freshly generated phrase, and move your coins there. Follow Ledger’s official instructions only.

In principle yes, if a device is physically modified. A component wired to the screen could record what is displayed while you write the phrase down. That is why the phrase must come from a device you have reason to trust, and why buying from the manufacturer matters.

Not reliably. The check confirms that the secure chip is genuine, but analysts note that a component added next to the screen would not necessarily change the result. Treat it as one check among several, not as proof of an untouched device.

Reports describe an extra board hidden under the screen, carrying an eSIM, a cellular module and a second microcontroller, with a coaxial antenna cable along the edge. An untouched device has only the display and its connector there. Do not open your own device to check, because opening it can damage it.

Nobody knows yet. Independent analysts put the total between roughly 72 and 93 million US dollars, depending on who counts and how. These are third-party estimates, and Ledger has not confirmed a figure.

One person reported on social media that a device from a European reseller contained a similar implant. No reseller or country was named, no funds were reported stolen, and Ledger has not commented, so treat it as an unconfirmed lead.

The same reseller also sold other brands, so the weak point looks like the sales channel and not one brand. Any hardware wallet bought from an unverified seller carries the same risk, which is why you should buy from the maker or an official reseller.

Yes, for amounts you do not need to move often, but only a wallet you bought safely and set up yourself. Never mine to an address that came with a pre-written phrase, and test every new address with a small payout first.

That is not known. No group has been named, and no arrests or seizures have been reported at the time of writing. Be sceptical of anyone who claims to know more than the public sources do.

No refund programme had been announced when this article was written. Ledger says it is working with the authorities and is developing additional anti-tampering measures, and we will update this article if that changes.
* Keep reading

Related articles

All articles →
BTC $83,684.00 ↗0.59%
ALPH $0.068700 ↘0.64%
KAS $0.041150 ↗0.52%
ETC $8.45 ↗0.29%
LTC $64.20 ↗0.15%
DOGE $0.086550 ↗0.41%
RXD $0.000032 ↗0.19%
BCH $283.53 ↗1.04%
CKB $0.001705 ↗12.72%
HNS $0.009443 ↗5.79%
KDA $0.009426 ↘1.87%
SC $0.000994 ↘0.25%
ALEO $0.038140 ↗1.02%
FB $0.389300 ↘0.65%
XMR $538.28 ↗1.41%
BELLS $0.128100 ↗0.07%
XTM $0.001404 ↘4.12%
ZEC $1,268.69 ↗2.13%
BTC $83,684.00 ↗0.59%
ALPH $0.068700 ↘0.64%
KAS $0.041150 ↗0.52%
ETC $8.45 ↗0.29%
LTC $64.20 ↗0.15%
DOGE $0.086550 ↗0.41%
RXD $0.000032 ↗0.19%
BCH $283.53 ↗1.04%
CKB $0.001705 ↗12.72%
HNS $0.009443 ↗5.79%
KDA $0.009426 ↘1.87%
SC $0.000994 ↘0.25%
ALEO $0.038140 ↗1.02%
FB $0.389300 ↘0.65%
XMR $538.28 ↗1.41%
BELLS $0.128100 ↗0.07%
XTM $0.001404 ↘4.12%
ZEC $1,268.69 ↗2.13%
BTC $83,684.00 ↗0.59%
ALPH $0.068700 ↘0.64%
KAS $0.041150 ↗0.52%
ETC $8.45 ↗0.29%
LTC $64.20 ↗0.15%
DOGE $0.086550 ↗0.41%
RXD $0.000032 ↗0.19%
BCH $283.53 ↗1.04%
CKB $0.001705 ↗12.72%
HNS $0.009443 ↗5.79%
KDA $0.009426 ↘1.87%
SC $0.000994 ↘0.25%
ALEO $0.038140 ↗1.02%
FB $0.389300 ↘0.65%
XMR $538.28 ↗1.41%
BELLS $0.128100 ↗0.07%
XTM $0.001404 ↘4.12%
ZEC $1,268.69 ↗2.13%
Selected miners

You can compare up to 5 miners at once.