BlockBeats news, October 9: Hardware wallet manufacturer Ledger is once again embroiled in a security controversy today, with third-party security firms estimating losses from this incident at approximately $90 million. The company is currently investigating fund losses related to devices sold by Southeast Asian authorized reseller CryptoBilis, and has requested that it suspend sales and shipments, advising users who purchased devices from this channel within the past 90 days to exercise caution or move their assets. The cause of the incident has not yet been definitively confirmed, with suspected supply chain/device tampering risks.
Reviewing major attacks and fund loss-related incidents in Ledger's history:
2018: A concentrated outbreak of early hardware and supply chain research vulnerabilities. Security researchers demonstrated the possibility of Nano S being tampered with before leaving the factory, as well as issues such as MCU bootloader bypass, isolation vulnerabilities, and Bitcoin change address injection. Ledger successively released security advisories and fixes, mostly at the research level or requiring physical contact scenarios.
2020: Large-scale customer data breach. Attackers obtained e-commerce and marketing databases through third-party API keys and Shopify-related vulnerabilities, exposing over 1 million email addresses and approximately 272,000–292,000 customer detailed records (names, addresses, phone numbers, etc.). Hardware and private keys were unaffected, but this directly spawned long-term phishing, social engineering, and fake official letter scams.
December 2023: Ledger Connect Kit supply chain attack. A former employee was phished, leading to control of an NPMJS account, and attackers published a malicious version of Connect Kit, injecting it into DApps dependent on the library to induce users to sign asset-stealing transactions. During an active window of about 2 hours, losses amounted to approximately $480,000–$600,000. Hardware and Ledger Live itself were not directly compromised.
January 2026: Third-party Global-e order data breach. The payment and logistics partner's system suffered unauthorized access, exposing some Ledger.com order-related information (names, addresses, contact details, etc.). Ledger's own systems and private keys were unaffected, but phishing risks were once again elevated.
April 2026: Fake Ledger Live app scam on the App Store. A counterfeit app was listed for about a week, tricking users into entering their seed phrases, with over 50 victims losing approximately $9.5 million across multiple chains. Apple subsequently removed it, and Ledger emphasized that it will never ask for the 24-word seed phrase.
August 2026: Ethereum app signing-related vulnerabilities (LSB-023, etc.). These included issues such as command interleaving causing display and signing parameters to be out of sync, and Clear-signing bypass. A malicious host was required to cooperate, and Ledger stated there was no evidence of actual user exploitation, with fixes already released in new versions.
October 9, 2026 (Latest): A large-scale wallet drain incident linked to a CryptoBilis reseller. Estimated losses are close to $90 million, Ledger is investigating, and it is suspected to be a supply chain or device tampering attack targeting a single channel. Officials have taken measures including suspending sales and advising users to migrate assets.

