XIYU.NEWS EVENTS

【Specter:数百个 Ledger 用户钱包疑似被盗,损失超 8600 万美元】

MonitoringCryptoSecurity incidentFirst tracked 2026-10-09Last changed 2026-10-09

Current outcome

Ledger is investigating reported fund losses tied to Southeast Asian authorized reseller CryptoBilis; Ledger has asked CryptoBilis to suspend sales and shipments and warned customers who bought devices in the past 90 days. Onchain researchers estimate losses at roughly $72 million to $90 million, and Tether has frozen related USDT. Industry figures including Changpeng Zhao have publicly commented and called for industry help tracing funds, while Mark Karpelès is investigating whether malicious hardware components were implanted; the attack method, device tampering and attacker identity remain unconfirmed, and the investigation is ongoing.

Progress timeline

10 material updates
  1. #01
    Initial2026-10-09 12:28 · publication time

    【Specter:数百个 Ledger 用户钱包疑似被盗,损失超 8600 万美元】

    Chain analyst Specter reports that hundreds of Ledger users have had wallets drained across Ethereum, TRON and Bitcoin, with traced stolen funds exceeding $86 million.

    Source evidence: foresightnews · theblockbeats · The Block · Cointelegraph · U.Today

  2. #02
    Confirmation2026-10-09 13:47 · publication time

    【Ledger:正调查东南亚用户资金损失报告,涉事设备购自经销商 CryptoBilis】

    Ledger is investigating reports of Southeast Asian users losing funds from devices bought via reseller CryptoBilis, has told the reseller to pause sales and shipping, and advises affected users to abandon a 90-day purchase window or migrate assets to a new device with a fresh seed phrase, as on-chain analysts estimate $72M–$86M+ drained from hundreds of Bitcoin, Ethereum and TRON wallets.

    Source evidence: foresightnews · BitPinas · CoinDesk · theblockbeats · The Defiant · wublockchainenglish · Decrypt

  3. #03
    Escalation2026-10-09 14:05 · publication time

    ⚡️CZ警告Ledger硬件钱包供应链攻击风险,疑似单一经销商出售假冒或遭篡改设备

    CZ publicly warned Ledger hardware wallet users about supply-chain attack risk, saying the incident appears limited to one reseller (CryptoBilis) selling counterfeit or tampered devices, and called on BNB ecosystem and crypto industry to help track stolen funds.

    State after update: Ledger is investigating the theft of funds from Southeast Asian users who bought devices via CryptoBilis, has told the reseller to pause sales and shipping; CZ publicly warned of supply-chain attack risk and called for industry help tracking stolen funds; on-chain estimates exceed $86M.

    Source evidence: theblockbeats

  4. #04
    Escalation2026-10-09 15:22 · publication time

    ⚡️Ledger安全事件损失接近9000万美元,Tether正冻结涉事地址中的大量USDT

    A Ledger-related security incident has caused losses approaching $90 million, with MistTrack tracking the funds and Tether freezing substantial USDT in addresses tied to the event.

    Source evidence: theblockbeats · foresightnews · The Defiant · theblockbeats

  5. #05
    Confirmation2026-10-09 15:34 · publication time

    Many #Ledger users who bought their devices from reseller CryptoBillis have had

    Lookonchain reports that one user (address TY24Ya) bought a Ledger device from reseller CryptoBilis three weeks ago and deposited 7M USDT, all of which was stolen about 10 hours before the report, possibly the largest single loss in the incident.

    State after update: The Ledger-related supply-chain attack has confirmed losses approaching $90 million, with MistTrack tracking funds, Tether freezing substantial USDT in related addresses, and a new possible largest victim losing 7M USDT.

    Source evidence: lookonchainchannel · theblockbeats

  6. #06
    Confirmation2026-10-09 16:02 · publication time

    🔍 链上侦探 | 某用户6月抄底80枚BTC浮盈138万美元,一周前存入Ledger现已全部被盗

    Lookonchain reports another victim: a user bought 80 BTC about four months earlier for ~$5.2M, moved all BTC into a Ledger hardware wallet bought a week earlier from reseller CryptoBilis, and the entire balance was stolen; the case is linked to other CryptoBilis customer drains, though device tampering, attack method and attacker identity remain unconfirmed.

    State after update: The Ledger-related supply-chain attack has confirmed losses approaching $90 million, with MistTrack tracking funds, Tether freezing substantial USDT in related addresses, and a new possible largest victim losing 7M USDT; the latest report adds another victim who bought a Ledger from CryptoBilis and had 80 BTC drained, while device tampering and attacker identity remain unconfirmed.

    Source evidence: theblockbeats · lookonchainchannel

  7. #07
    Escalation2026-10-09 16:10 · publication time

    Mt.Gox前CEO称发现被植入间谍模块的Ledger硬件钱包,可通过LTE发送助记词信息

    Mt. Gox ex-CEO Mark Karpelès disclosed that a Ledger hardware wallet he received from Malaysia contained a hidden spy module with LTE, antenna, eSIM and a microcontroller wired to the device's SPI bus, capable of capturing displayed characters and exfiltrating seed phrases after setup, and urged users to follow Ledger's official device-verification guidance.

    Source evidence: theblockbeats

  8. #08
    Escalation2026-10-09 16:31 · publication time

    ⚡️Ledger盗币黑客向Tornado Cash转入107万美元ETH,部分资金流入Binance热钱包

    Suspects moved 430.2 ETH (~$1.07M) to Tornado Cash via 4 wallets, and after Tether's freeze converted USDT to USDD via SUN.io and the USDD PSM, with some funds routed to a Binance hot wallet; suspect wallets still hold ~$70.6M.

    State after update: The Ledger-related supply-chain attack has confirmed losses approaching $90 million, with MistTrack tracking funds and Tether freezing substantial USDT; latest on-chain monitoring shows suspects moved 430.2 ETH (~$1.07M) to Tornado Cash and converted USDT to USDD via SUN.io and the USDD PSM, with some funds routed to a Binance hot wallet, while suspect wallets still hold ~$70.6M; device tampering and attacker identity remain unconfirmed.

    Source evidence: theblockbeats

  9. #09
    Response2026-10-09 16:40 · publication time

    Ledger says Southeast Asia reseller linked to $86M draining

    Ledger officially confirmed it is investigating a CryptoBilis-linked supply-chain compromise and told CryptoBilis to pause all sales and shipments of Ledger devices; users who bought devices from CryptoBilis in the past 90 days were advised not to initiate setup and, if already set up, to move assets to a new Ledger signer.

    State after update: Ledger has officially confirmed it is investigating a CryptoBilis-linked supply-chain compromise, instructed the reseller to pause Ledger device sales and shipments, and advised affected users to migrate assets to a new signer; loss estimates range above $80M–$86M, with earlier on-chain tracking indicating ~$90M in related losses, Tether freezing some USDT, and suspects moving 430.2 ETH to Tornado Cash and converting USDT to USDD via SUN.io/USDD PSM; device tampering details and attacker identity remain unconfirmed.

    Source evidence: Protos

  10. #10
    Confirmation2026-10-09 21:10 · publication time

    Ledger hack scare nears $90 million as Tether moves to freeze stolen USDT

    Industry figures publicly intervened: Binance founder Changpeng Zhao warned users and said the incident appears localized to a single-vendor supply-chain attack; former Mt. Gox CEO Mark Karpelès is investigating whether malicious hardware components were implanted in customer devices and asked CryptoBilis to open some unsold Ledger wallets for circuit-board inspection. Reports also note Ledger's Genuine Check verifies the Secure Element but may not detect physical modifications elsewhere in the hardware.

    State after update: Ledger is investigating reported fund losses tied to Southeast Asian authorized reseller CryptoBilis; Ledger has asked CryptoBilis to suspend sales and shipments and warned customers who bought devices in the past 90 days. Onchain researchers estimate losses at roughly $72 million to $90 million, and Tether has frozen related USDT. Industry figures including Changpeng Zhao have publicly commented and called for industry help tracing funds, while Mark Karpelès is investigating whether malicious hardware components were implanted; the attack method, device tampering and attacker identity remain unconfirmed, and the investigation is ongoing.

    Source evidence: CryptoSlate

All events · Back to the feed

XIYU.NEWS APP

Install xiyu.news

Open in a standalone window, check for updates online and read saved pages offline.