Ledger Verifies Tampered Hardware Component in Device; Potential Losses Surpass $86M
The company stated that the security breach appears confined to one reseller operating within Southeast Asian territories.

The cryptocurrency hardware wallet manufacturer Ledger, currently examining claims of digital asset theft connected to its products sold through Southeast Asian distributor CryptoBilis, has verified that an affected customer's device was equipped with an unauthorized hardware component.
In a Sunday statement published on X, Ledger announced it was contacting customers as it continues its investigation into the financial losses, which security investigator Specter has calculated could surpass $86 million spanning Bitcoin, Ethereum and Tron networks.
The company requested that anyone possessing relevant information about the ongoing investigation contact its bounty program via email at bounty@ledger.fr.
Taking preventative action, CryptoBilis announced within the same post that it has halted all sales of hardware wallet stock pending the completion of the investigation. The company stated that Ledger maintains active dialogue with CryptoBilis regarding subsequent actions.
Users who obtained their devices from this particular reseller are advised by Ledger not to begin the setup process if they haven't already initiated it. For those who have already configured their Ledger device, the recommendation is to transfer their digital assets to a new Ledger signer (utilizing a new seed phrase).
On Friday, Cointelegraph's reporting indicated that CryptoBilis held status as an authorized Ledger distribution partner across Indonesia, Malaysia and the Philippines.
The number of potentially impacted customers and the precise value of the documented losses have not been disclosed by Ledger.
In an official statement provided to Cointelegraph, Ledger indicated the security incident seems to be limited to this particular reseller and its regional market.
"Ledger's infrastructure, systems and services were not compromised," the company said, adding that its investigation remained ongoing.
Users seeking assistance or additional information should reach out to Ledger customer support via official communication channels at http://support.ledger.com.