Ledger Confirms Hardware Implant Attack, Urges User Action
More than $86 million in linked losses raises the stakes for hardware-wallet supply-chain security, even as Ledger says its own systems remain uncompromised.
Every Zipp story tagged #HardwareWallet, newest first.
More than $86 million in linked losses raises the stakes for hardware-wallet supply-chain security, even as Ledger says its own systems remain uncompromised.
The reported loss highlights the risks of buying hardware wallets through resellers, though the account does not establish how the funds were lost.
The account describes a major self-custody loss, but does not explain how the funds disappeared or establish that the device caused it.
The reported losses remain unverified, but Ledger's advice to pause setup and move funds highlights the security risk of devices obtained through untrusted channels.
No Bitcoin keys or funds were exposed, but names and delivery addresses can make recovery-word phishing look credible long after a wallet purchase.
Wallets remain safe, but a third-party newsletter breach exposed email lists across multiple Bitcoin firms. The danger is in following the email's recovery-seed instructions.
Trezor's second third-party breach in two months, and this time attackers sent phishing from the vendor's own domain, not a look-alike address.
Hardware-wallet owners face phishing and physical-targeting risk as roughly 67,000 more records resurface from a vendor Trezor believed had purged them. The 90-day deletion policy did not hold.
HWI stays open and supported devices keep working, but successor BHWI ships parity tests for only four devices, with no wallet in production.
Ledger merged the fix for one bug on May 5 and the other on May 25. They shipped in August. The gap between merge and release is the uncomfortable read for hardware-wallet customers.
The 683M ZIL figure gets the headline, but the seven-year survival of the bug inside a Ledger-signed application is the real read for any token still relying on native hardware-wallet signing.
The bug was structural rather than random: a feature flag treated as present let attackers reconstruct private keys from a single button press, and Coinkite says severe losses have occurred even…
The patch tightens the RNG and signing flow, but seeds from affected firmware between 2021 and July 2026 still need replacement. AI-assisted auditing is the broader industry signal here.
The $100M in physical theft is the headline; the 40,000-record breach is the structural warning. Hardware-wallet security now means controlling what sits behind the device, not just the device itself.
The bug sat in open-source code for five years while a community built on 'don't trust, verify' outsourced its judgment to one vendor's reputation, Foundation CEO Zach Herbert argues.
Private keys and seed phrases are untouched, but names, physical addresses and contact details are now in the wild, giving attackers a clean phishing dataset that will linger well past the patch.
Galaxy Research has traced 1,596 BTC stolen across three confirmed attack waves, with a suspected fourth wave that would push total losses to roughly 2,000 BTC.
Roughly $38M has been swept from single-sig seeds generated between 2021 and 2023, and the exploit is unpatchable by design: any firmware fix would tip off attackers to wallets still holding funds.
The seed-randomness flaw had lurked in firmware since March 2021 and went unnoticed for years, exposing the practical ceiling of single-device self-custody for serious BTC holders.
Nearly 1,200 addresses and 1,000 BTC later, the incident has crossed from isolated phishing to a coordinated drain, putting self-custody users on notice about supply-chain risk in hardware wallets.