Ledger owners who bought a hardware wallet through Southeast Asian reseller CryptoBilis now have something more concrete to check for.
Ledger said on October 11 that one device belonging to an affected customer contained an unauthorized hardware implant, moving the investigation beyond the suspected tampering that FinanceFeeds first reported on October 9.
That confirmation is important but narrow. Ledger has not said every reported theft involved the same modification, disclosed how many devices may have been altered or established where in the distribution chain the implant was added. The company also maintains that “Ledger’s infrastructure, systems and services were not compromised.”
The dollar figure remains unsettled too. Onchain researcher tanuki42 put suspected losses above $72 million, Specter estimated more than $86 million across Bitcoin, Ethereum and Tron, and MistTrack put the figure near $90 million. Arkham separately showed about $71.6 million in addresses it labelled as connected to the incident at one snapshot. Those figures use different scopes and should not be treated as a confirmed loss total.
So who should be most concerned, and what can an owner actually check?
Who Is in Scope?
Ledger’s strongest warning is aimed at customers who purchased devices from CryptoBilis during the previous 90 days.
If the device has not been initialized, Ledger says not to set it up. If it has already been used, the company says the owner should consider moving assets to a new Ledger signer initialized with a completely new recovery phrase.
CryptoBilis, which had been listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines, has now stopped sales of its hardware-wallet inventory while the investigation continues.
There is currently no evidence that all Ledger devices, or devices bought directly from Ledger, are affected. But anyone who bought through a reseller can perform the same basic authenticity checks.
1. Check Exactly Where and When You Bought It
Start with the invoice rather than the device.
Confirm the seller, purchase date and whether the seller appears in Ledger’s authorized distribution network. If the purchase was from CryptoBilis within the last 90 days, Ledger’s current advice takes priority: do not initialize an unused device.
The CryptoBilis case also shows why “authorized reseller” cannot be the only security test. The investigation concerns an authorized channel, not an obviously counterfeit marketplace listing.
2. Check the Box and Recovery Sheet
Inspect the packaging for anything unusual, but do not assume intact packaging proves the hardware is safe.
More importantly, the recovery sheet inside a new Ledger package should be blank. A new device should generate its recovery phrase itself during setup. If a card already contains recovery words, or instructions tell you to use a supplied phrase, stop immediately.
Ledger has consistently warned that users should never use a device supplied with someone else’s PIN or recovery phrase.
That matters because whoever knows the recovery phrase can recreate the wallet elsewhere and move its assets without possessing the physical Ledger.
3. Watch What Happens on the First Boot
A factory-state Ledger should start with its normal welcome and setup sequence and require you to choose your own PIN.
It should not arrive already configured, open directly into an existing wallet or ask for a PIN supplied by the seller.
The recovery phrase should also be generated and displayed by the Ledger device itself during setup, not by a website, desktop program, QR code or printed card.
This is one reason earlier counterfeit devices were dangerous. In April, FinanceFeeds covered a modified Nano S Plus sold through a Chinese marketplace that paired altered hardware with a fake companion-app flow designed to capture recovery information.
4. Run Ledger’s Genuine Check – but Do Not Treat It as the Only Test
Use only the official Ledger Wallet application, formerly Ledger Live, obtained through Ledger’s own website, and run the Genuine Check.
The check uses cryptographic attestation to determine whether the device contains a genuine Ledger Secure Element and can authenticate with Ledger’s servers. A device that fails the check should not be used.
But passing it should not now be treated as the only question.
Former Mt. Gox CEO Mark Karpelès has claimed that a modified device he examined contained an implant beneath the screen while still passing Ledger’s Genuine Check. Ledger has now confirmed an unauthorized implant in one affected device, but it has not publicly confirmed Karpelès’ description of how that implant worked or whether the specific unit passed the Genuine Check.
Ledger’s own hardware-integrity guidance therefore remains relevant alongside the automated check.
5. Inspect the Physical Device
Look for obvious differences in the casing, screen fit, buttons, USB connection or signs that the housing has been opened or reassembled.
Ledger publishes reference information for different hardware revisions, including board images that advanced users can compare against their devices. Its documentation notes that the Secure Element checks the microcontroller at boot and that advanced users can inspect the board for unexpected components.
Opening the device, however, can void warranty or return rights and is not a sensible first step for most owners. If something looks wrong, photograph it and contact Ledger rather than dismantling a device while funds remain associated with it.
If You Are in Doubt, a Genuine Check Is Not the End of the Decision
For a CryptoBilis customer who has already initialized a potentially affected device, the safest response is not simply to buy another Ledger and restore the same recovery phrase.
If that phrase may have been exposed, restoring it preserves the same compromised keys.
Instead, initialize a trusted replacement as a new device, generate an entirely new seed, verify the receiving address on the new hardware and move the assets onchain from the old wallet to addresses controlled by the new seed.
Anyone seeing unexplained outgoing transactions should also contact Ledger through its official support channels. Security Alliance’s SEAL 911 provides free emergency assistance for active crypto-security incidents and says it will never ask for a seed phrase, private key or payment.
What Ledger Still Has Not Explained
The confirmed implant answers one question but opens several others.
Ledger has not publicly explained what the unauthorized component did, where it was installed, how many devices may contain one or whether the same technique accounts for all of the reported thefts. Binance co-founder Changpeng Zhao has described the episode as a supply-chain attack, but the exact point at which the supply chain was compromised remains under investigation.
FinanceFeeds’ October 11 update on the investigation also notes that Ledger is working with authorities and contacting affected users while it examines the modified hardware.
For now, the practical distinction is simple: there is no confirmed compromise of Ledger’s wider infrastructure, but there is now a confirmed physically modified device linked to the CryptoBilis investigation. For recent buyers from that reseller, that is enough reason to follow Ledger’s migration advice rather than wait for a final dollar figure.
