On October 9, 2026, hardware wallet manufacturer Ledger announced an investigation into reports of stolen funds from Southeast Asian customers who had bought devices through regional reseller CryptoBilis. Ledger asked the reseller to suspend sales and shipments. In its October 10 update, Ledger confirmed that one affected customer's device contained an unauthorized hardware implant, a finding subsequently covered by The Verge. That confirmation concerned one device and did not establish the cause of every reported theft.
The investigation and supply chain questions
CoinDesk reported on October 9 that blockchain investigator Specter estimated suspected losses above $86 million. The figure has not been independently verified, and investigators have not established whether all reported losses share a cause. The Block also covered the ongoing investigation. The implant has raised questions about the supply chain, but it has not yet been established whether tampering occurred within it. Public evidence also does not establish whether the modification occurred during manufacturing, warehousing, distribution or shipping, or who was responsible. A connection to devices sold by CryptoBilis does not establish that the reseller made the modification. Ledger has said it found no indication that its own security infrastructure, systems or services had been compromised.
Ledger's initial advice applied to customers who had bought from the reseller within the previous 90 days: delay setup of unused devices, and consider moving funds from devices already set up to a new Ledger device with a fresh seed. Restoring the old recovery phrase on another device would retain the same keys, so changing the device alone would not remove any exposure of those keys.
Community analysis points to a hardware implant
Community teardown videos and preliminary analysis have focused on suspicious components inside the Ledger Nano X. The Nano X is a Ledger hardware wallet with a screen, battery and Bluetooth connectivity. Ledger's product documentation describes a secure chip that protects private keys and a display for checking information before approving operations. A Reddit post discussing the teardown suggests that a smaller battery was fitted to make space for an additional component. Mark Karpelès, the former CEO of cryptocurrency exchange Mt. Gox, separately described a suspicious communications module and proposed that an implant could capture the recovery phrase from the display and transmit it over a cellular connection. The YouTube teardown and community analysis have not been independently verified; the component's functions and its connection to the losses remain unconfirmed.
In an earlier post, Karpelès compared older and more recent implants in the Nano X, noting how the modifications had evolved. In an earlier documented case, an added storage component carried a fake Ledger Live application that prompted users to enter their recovery phrase. The current community analysis proposes that an implant could instead capture the phrase as the device displays it. If confirmed, this would mean exposure could occur during normal setup even when a user had not entered the phrase into a fraudulent application.
Image source: @MagicalTux on X
If that explanation proves correct, the recovery phrase could be exposed during initial setup. This sequence of words restores a wallet's keys, so capturing it could allow an attacker to recreate the wallet on another device without defeating the original secure chip. For a wallet controlled solely by that phrase, the attacker could then sign transactions independently. Keeping the original device offline, changing its PIN or locking it away would not revoke access to the copied keys. This remains a possible attack path pending formal investigation, but it illustrates why protection during setup matters.
Are hardware wallet risks greater than we think?
Questions about hardware wallet security predate the Ledger investigation. A security issue affecting Coldcard had already raised concerns about how wallet keys are generated. In a security advisory first issued on July 30, manufacturer Coinkite explained that affected firmware generated seeds with insufficient randomness, making it easier for attackers to search possible seeds and derive their keys. Assets could therefore be at risk even if the keys had never been directly stolen. Coinkite released firmware fixes, but its migration guidance states that an update cannot repair a weak seed already in use. Affected users must follow the guidance to create a fresh seed and move their funds. For more on the incident and the seed-generation flaw, read Cregis's earlier analysis of the Coldcard incident.
These incidents expose the limits of assessing security through offline storage alone. Hardware wallets and cold storage reduce the exposure of private keys to internet-connected environments, but protection also depends on device delivery, key generation, backups, recovery and transaction approval. Keeping a device offline cannot undo an exposure that occurred at another stage. To assess whether a wallet provides the protection they expect, users need to examine the full path from key generation to use and identify the risks that require additional safeguards.
From key protection to business asset operations
Cregis believes that a secure environment for digital asset operations needs to account for both key protection and the way people use their wallets. For individuals, this means protecting private keys and recovery phrases, regularly checking device status and official security updates, and learning to recognize phishing messages and suspicious authorization requests. Businesses also need controls that support collaboration and ongoing operations. Responsibilities for initiating and reviewing transactions should be clear, along with procedures for changing access when people or devices change. Allocating funds and responsibilities appropriately can help limit the assets exposed by a compromised key or an operational mistake.
Multi-party computation, or MPC, provides a way to distribute control over the keys in a self-custody wallet and underpins Cregis's wallet signing approach. With distributed key generation, participants jointly create and separately hold key shares. During routine signing, they compute together using their respective shares without reconstructing the complete private key. A signing threshold defines the participation required: a three-of-five arrangement needs at least three valid shares. When shares are managed independently by different participants, an attacker must compromise several parties to obtain enough signing authority, increasing the difficulty of an attack. Obtaining a single share from one device is insufficient to gain control over the wallet's transfers. NIST's work on threshold cryptography describes this approach to distributing trust.
Cregis combines MPC with trusted execution environments, or TEEs, to isolate key-share storage and signing computations, helping protect shares from unauthorized access and the signing process from tampering. Users can participate in signing through desktop and mobile applications on their existing supported devices, without purchasing or carrying a dedicated hardware wallet. The approach retains hardware-backed isolation for sensitive operations while reducing dependence on the manufacture, delivery and safekeeping of a separate wallet device. Businesses can also configure approval workflows, transaction limits and permissions through business policies to align distributed signing with their operational requirements.
Digital asset security is a long-term responsibility
Ledger's investigation has yet to reach a final conclusion, but the incident is a reminder that digital asset security requires a long-term commitment. That work continues after a device is purchased or a wallet is deployed, and must adapt as user needs, business activity and risks change. A reliable approach to asset management needs ongoing maintenance and must remain practical for everyday operations. Businesses evaluating self-custody or reviewing their digital asset workflows can speak with Cregis about wallet architecture and authorization arrangements suited to their operations.
关于Cregis
Cregis成立于2017年,总部位于香港,是一家面向企业的数字资产基础设施平台。过去九年间,Cregis已服务全球50多个国家和地区的4,000余家企业客户,涵盖加密交易所、金融科技公司、支付服务商、数字银行、经纪商及Web3企业等机构。
围绕企业数字资产运营需求,Cregis构建了覆盖钱包基础设施(WaaS)、资金流编排(Rails)及合规托管能力(Custody)的产品体系,帮助企业完成从资产存放与控制、资金流转与运营,到治理与合规管理的完整闭环。
其中,核心产品 Wallet-as-a-Service 和 Payment Engine 已广泛应用于企业级数字资产运营场景。随着数字资产基础设施需求持续全球化,Cregis始终专注于一件事:帮助企业以更强控制力、更低运营复杂度和更完善的合规能力使用数字资产。

