Ledger Probes CryptoBilis-Linked Wallet Drains Exceeding $86M
The losses remain unconfirmed and the cause is unknown, but Ledger has urged some recent buyers not to set up their devices and to move assets if already activated.
Every Zipp story tagged #SupplyChainAttack, newest first.
The losses remain unconfirmed and the cause is unknown, but Ledger has urged some recent buyers not to set up their devices and to move assets if already activated.
The suspected supply-chain attack has not been confirmed, and Ledger says there is no evidence its hardware or core infrastructure was directly compromised.
The reported losses remain unverified, but Ledger's advice to pause setup and move funds highlights the security risk of devices obtained through untrusted channels.
GoPlus says the attackers forged transaction data inside a compromised wallet backend, making Bitget's own authorized signing system generate valid signatures for $387.5M in unauthorized transfers.
The $38M theft from a single compromised wallet makes this the largest hardware-wallet supply-chain attack on record, with Coldcard pointing users straight at a firmware load-bearing weakness.
Roughly 500 wallet addresses were drained in a pattern tied to a Mk3 firmware bug, putting the total stolen above $35M and forcing Coinkite to flag every device that ever generated a seed on 4.0.1 or…
The real target isn't a developer's wallet file — it's the workstation, where SSH keys, AWS credentials, GitHub tokens and live AI coding sessions all sit on the same machine.
Socket's TrapDoor disclosure named 34+ malicious packages across npm, PyPI and Crates.io targeting developer machines, CI/CD credentials and AI coding files — the control plane a smart-contract audit…