Ledger Wallet Tampering Suspected After Reports of Crypto Thefts
Users of Ledger crypto wallets report drained accounts, and suspicion has fallen on a small spy device allegedly fitted into units sold by reseller CryptoBillis. Ledger has asked the reseller to pause all wallet sales during its investigation.

Hardware crypto wallets made by Ledger, which are used to store digital assets, may have become the target of a supply chain attack. Users have recently reported that funds disappeared from their accounts, and suspicion has fallen on the reseller CryptoBillis and a piece of covert hardware. Ledger has asked CryptoBillis to pause all sales of its wallets until an investigation is complete.
Photos and videos posted on X and Threads appear to show a small circuit board sandwiched under the device's screen. The implant allegedly intercepts everything shown on the display, including the seed passphrase presented during initial setup. Using an embedded SIM card, it then sends that data to the attacker, who can drain funds from the victims' accounts.
Scale of the losses
According to reports, whoever is behind the attack has stolen more than $86 million worth of crypto from hundreds of wallets.
What is and isn't affected
There is no indication that Ledger's own systems were breached or that wallets bought directly from the company were affected. The problem appears to be a supply chain attack mainly involving users in Southeast Asia and the CryptoBillis reseller.
Ledger has published guidance on how to check whether a wallet has been tampered with. This is especially relevant for buyers who purchased a device through a third-party seller, since that is the route by which a unit could have been modified before reaching the customer.


