Cybersecurity

Ledger finds a hidden chip in a crypto wallet sold by a Malaysian reseller

Susan Hill
Add us on Google

A Ledger hardware wallet, the device people buy so that nobody else ever sees their crypto keys, has been found with an extra circuit board hidden inside. Ledger confirmed that the device of one user caught up in a wave of thefts in Southeast Asia contained an “unauthorized hardware implant,” and it has told customers of the reseller CryptoBilis not to switch on wallets they have not yet set up.

The problem reaches beyond one shop. A hardware wallet’s whole promise is that the secret recovery phrase is created and shown only on its own small screen, never on a phone or laptop that malware can reach. If someone can open the box before it reaches the buyer and wire a spy into that screen, the secure chip inside stops mattering, because the attacker reads the secret at the moment it is created.

The sums involved are large. On-chain analysts tracking the drained addresses put the losses above $86 million across hundreds of wallets on Bitcoin, Ethereum and Tron, and blockchain data firm Bitquery estimated about $92.9 million across 311 wallets. Ledger has not confirmed any total. The company said it believes the drained funds are limited to devices sold through the reseller and that it has no indication its own security infrastructure, systems or services were compromised.

The alarm went up when Mark Karpelès, the former head of the collapsed Mt. Gox exchange, posted photos of a Ledger he said he had bought in Malaysia still in its shrink wrap. By his account, a second board sat where the screen padding should be, carrying a microcontroller, an antenna and a cellular module with a data eSIM. He said the chip watches the display, recognizes the setup screen and sends the recovery phrase out over the mobile network, and that the wallet’s own firmware would not notice it because it only reads what the screen shows. Karpelès has not said his device came from CryptoBilis, and Ledger has not confirmed his description of how the implant works.

CryptoBilis sold Ledger devices in Indonesia, Malaysia and the Philippines and presented itself as the authorized Ledger reseller for Malaysia. Ledger asked it to pause all sales and shipments, and the reseller has since suspended sales of its hardware-wallet stock until the investigation ends. Ledger’s advice splits buyers into two groups. Anyone who bought through CryptoBilis in the past 90 days and has not set up the device should not start. Anyone who already has should move their funds to a new Ledger with a freshly generated recovery phrase. There is no sign that wallets bought directly from Ledger, or outside this reseller, are affected.

Much is still unproven. Ledger has confirmed an implant in one device, and that alone does not show every drained wallet was compromised the same way. The loss figures come from third-party trackers rather than from Ledger, and estimates have ranged from about $72 million to more than $90 million. CryptoBilis also sells Trezor, Tangem, OneKey and SafePal wallets, and buyers in the region have asked whether those are safe; nobody has answered yet. Reports of hardware implants in Ledger devices also surfaced in Thailand earlier this year, which points to resale channels in the region as a target rather than a one-off.

Some checks apply to anyone who owns a hardware wallet. Ledger has published guidance on spotting a device that has been opened or altered, and its long-standing rules still hold: a genuine wallet never arrives with a recovery phrase already written down, and the company will never ask for the 24-word phrase. That last point matters now, because thefts on this scale draw fake recovery services that ask victims for exactly that phrase. Buying straight from the manufacturer removes the step where a box can be opened and resealed.

Ledger first acknowledged the reports on October 9 and confirmed the implant in a situation update on October 10. It says it is working with the authorities and with SEAL 911, a volunteer crypto security-response group, and is developing further anti-tampering measures. Two questions remain open: how many devices were altered, and where between the factory and the buyer someone opened the boxes.

Tags: , , , , ,

Add us on Google

Discussion

There are 0 comments.