Ledger said an unauthorized hardware implant was found inside an affected device, confirming that the incident involved physical tampering. The company said there is no evidence its infrastructure, systems or services were compromised. Earlier on-chain analysis estimated losses linked to the incident at more than $86 million.
Why it matters
The incident shifts the security focus from Ledger's online infrastructure to the device supply chain. A compromised device can create risk before a user ever connects it, making distribution and initialization controls central to hardware-wallet security.
Distributor CryptoBilis has suspended hardware-wallet sales. Ledger advised users not to initialize unused devices and to consider moving assets to wallets created with new recovery phrases.
Market impact
The immediate impact is concentrated on affected devices and their owners, but the episode could increase scrutiny of hardware-wallet distributors and device verification practices. Users with unused hardware should follow Ledger's guidance before initializing or funding it.
Frequently asked questions
-
What did Ledger find inside the affected hardware wallet?
Ledger said an unauthorized hardware implant was found inside an affected device, confirming physical tampering.
-
Were Ledger's online systems compromised in the incident?
Ledger said there is no evidence that its infrastructure, systems or services were compromised.
-
How large were the losses linked to the incident?
Earlier on-chain analysis estimated losses linked to the incident at more than $86 million.
-
What action did CryptoBilis take after the attack?
Distributor CryptoBilis suspended hardware-wallet sales following the incident.
-
What did Ledger advise users with unused devices to do?
Ledger advised users to avoid initializing unused devices and to consider moving assets to wallets created with new recovery phrases.
WuBlockchain