SNACK: 3-line summary
- Ledger confirmed an unauthorized hardware implant in one affected wallet; the wider investigation continues.
- Ledger’s October 9 notice advises CryptoBilis customers who bought within the preceding 90 days not to begin setup if they have not already done so.
- Customers who already completed setup should consider moving assets to a new Ledger device with a new recovery phrase.
The Verge reported on October 10 that Ledger had confirmed an unauthorized hardware implant in one affected customer’s device. Ledger’s precautionary advice concerns purchases through CryptoBilis, so the seller on your receipt matters when checking whether that guidance applies to you.

Snackgirls react
AIKO: An offline wallet still has to pass through a physical supply chain. I’d want to know how the device is protected as it changes hands.
Nea: I can imagine how unsettling it would be to look back through an order after funds go missing. I hope affected customers get clear answers about what happened to their devices.
The finding concerns one affected device
Ledger is investigating reports of missing funds from customers in Southeast Asia who bought devices through CryptoBilis. Possible tampering in the supply chain is under investigation.
The implant confirmed in The Verge’s report establishes physical tampering in one affected device. It does not establish that the same alteration caused every reported loss.
For CryptoBilis buyers, setup status matters
In its October 9 notice, Ledger said it had asked CryptoBilis to pause all sales and shipments of Ledger devices pending the investigation. Customers who had purchased from that reseller within the preceding 90 days were advised not to begin setup if they had not already done so.
For customers who had already completed setup, Ledger advised considering a move of assets to a new Ledger device with a newly generated recovery phrase. The guidance specifies a new phrase, not reuse of the existing one on a replacement device.
Start with the seller on your receipt
Check the seller on your receipt or order record and whether you have already completed setup. If your purchase falls within the group covered by the October 9 notice, direct questions about the guidance to Ledger’s official support channels.
The number of affected customers and the connections between reported losses remain unconfirmed. Neither The Verge nor CoinDesk reports a confirmed breach of Ledger’s own systems or confirmed compromise of devices purchased directly from Ledger.
Sources and checked date: October 11, 2026

Comments
0No login needed. Edit or delete your comment from the same browser.
All comments 0
한국어 · English · 日本語No comments yet. Start the conversation.