Bitcoin Forum
October 11, 2026, 11:22:46 AM *
News: Serious possible issue involving Ledger hardware wallets and CryptoBilis
 
   Home   Help Search Login Register More  
Pages: « 1 2 3 4 5 [6] 7 »  All
  Print  
Author Topic: Reports about wallet-draining by Ledger users. Total losses $86M+  (Read 1582 times)
Meuserna
Sr. Member
****
Offline

Activity: 402
Merit: 750


View Profile WWW
October 10, 2026, 08:44:11 PM
 #101

After this story no way that I would every buy hardware wallet from official resellers. I can't trust third part anymore after this. And yeah, why always Ledger, like their reputation wouldn't be bad enough. But people will continue to buy from them, no matter what.
 
If you buy direct from Ledger, you get your name and home address leaked. If you buy from an authorized reseller, you get a hacked device. You're screwed either way.

This is why I recommend DIY solutions like SeedSigner, ShieldSigner, Krux & Kern to those who know understand self custody. By not using "hardware wallet" hardware, you remove supply chain risks from your setup. In theory, you can remove those risks by buying direct from the company that makes a hardware wallet... but then again, maybe not, especially for smaller hardware wallet companies. In the end, you still have to trust those companies.

Going the SeedSigner route means using an off the shelf Raspberry Pi. There's no supply chain risk because the thing wasn't designed to be a hardware wallet. To be even safer, manually generate your own random seed phrase.

Imagine the attacks thieves and hackers will be attempting to pull off when Bitcoin hits a million.
Yes, there is some alternatives. I looked into these names that you mentioned and it looks way too complicated for average user who wants ready to use, simple product. Yes, it's an option for more tech advanced people, but I guess such people is minority.

We have to start being more honest about who should and shouldn't be doing self custody. This isn't like traditional finance where companies are regulated and funds are insured.

Too often, people learn how to use a gadget instead of learning the basics of Bitcoin. Even in a form like this, it's shocking how many people don't realize their coins aren't in their wallets. I think Bitcoin self custody becomes easier when people understand the basics: Coins are online, on the blockchain. Keys and addresses are in the wallet. If you understand that, something like SeedSigner becomes easier too.

My hope is that eventually ETFs become insured, and those who aren't able or willing to do DIY will go ETF instead. I say this because self custody comes with risks, and many of them are directly related to companies. Not all, but many. Ledger employees have leaked customer names and addresses. Ledger employees have been phished. Now Ledger's authorized resellers have either been hacked or are complicit in theft. The risks of trusting a company are piling up.

philipma1957
Legendary
*
Offline

Activity: 4998
Merit: 12575


'The right to privacy matters'


View Profile WWW
October 10, 2026, 08:45:36 PM
 #102

hmmm looks like trezor will be next.

I shifted some coins about we will see what is next to get stolen.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Meuserna
Sr. Member
****
Offline

Activity: 402
Merit: 750


View Profile WWW
October 10, 2026, 08:49:24 PM
 #103

People still use Ledger after they released this product years ago?
Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties entities

You would be surprised. It doesn't look their growth[1] has been slowed down in anyway since the release of the recovery feature in 2023. Currently at 8 million units sold vs 2M+ from Trezor. Still don't understand why myself.

[1] https://coinlaw.io/how-many-people-work-at-ledger/

The more something goes mainstream, the more it's getting fucked by the people.
I actually think that most Ledger customers believe that the recovery feature is a brilliant idea.
But this is just how homo sapiens roll.
Pointing to the Bell Curve, the ratio isn't favoring the more intelligent humans, so normality seems to be tied to individuals making worse decisions over time. Add Dunning-Kruger to this and there we go.

You're 100% right. That thing is a ticking time bomb. Only a fool would think hackers aren't using AI to reverse engineer Ledger's built-in key extraction API. I believe Ledger users are at risk even if they don't subscribe to that Recover feature.

The things I see people say to defend Ledger Recover make my jaw drop. "It's only active if you enable it." Prove it. The code is closed source. Even Ledger has admitted they can't prove their code has no backdoors.

Dogedegen
Sr. Member
****
Offline

Activity: 532
Merit: 285



View Profile
October 10, 2026, 09:02:54 PM
 #104

Edit:
Someone lost $5.2m in this theft after he deposited all of his 80BTC in a ledger wallet he bought from this same reseller in question just one week ago. This is really sad.

I wonder why people are still buying ledger wallets to store their coins at this point in time with all the big crypto theft and hacks that happened this year.

https://x.com/lookonchain/status/2108585005635301427?s=46
This is so sad. I hope that some forum users have more understanding why certain groups of people like to invest with regulated exchanges or ETFs. Just imagine if you were 50 or 60 years old, you read all the stories about self custody and then you invest a large amount into Bitcoin the right way and then this happens to you. The person would really have to love Bitcoin for them to get over this if they had a lot more money, to get back into the game and try again with another hardware wallet. Some people could say wrongly that this is the fault of Ledger, but such things can happen to any hardware wallets that has resellers.  Quite a sad recent few months with so many things going wrong and they are completely different attack ways, some before were with software methods and now this is with a hardware one.

It's another nail on their coffin, not sure the last one as we all have to wait and witness what will happen next with Ledger.

Ledger is so crappy from data breaches, to Ledger Recover (smh with this product), then this Ledger authorized reseller CryptoBilis but maybe more, it's hard to trust Ledger again.
Ledger is not responsible for this, and it can happen to any hardware wallet so please don't spread this kind of bad information.

How can the average user ever trust a hardware wallet at this point and where does it stop? We’re talking about a step that should create extra protection but instead has been compromising it. Heck, how can you even trust wallet apps aren’t skimming your seed phrases too?? Are we forced to go back to generating our own air gapped device paper wallets and forever letting our funds sit there without any interaction?
I don't know what to say to this, we must provide more understanding for people who choose not to self custody instead of blaming them. These situations are making me also think twice about that decision..


███████▄▄███▄███▄
███▄▄████████▌████▄
▄██████████████▐███▌
██▄███████████▌████▌
████████▀███████▐▌█
███████████████▌█▌▐
████████▄████████▐▐
██████████████████▌
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

█▄▄▄██████▄▄▄███████▄▄▄
████████████████████████████
████▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
████▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀██████████▌█████████████▄▄████▀
██████████▄█████▀████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌

█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████
 
P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K
 
█████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
98%
RTP


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
HIGH
ODDS


▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀

██████
██
██
██
██
██
██
██
██
██▄▄▄▄
▀▀▀▀▀▀

███████████████████████████████
 
PLAY NOW
 
███████████████████████████████

██████
██
██
██
██
██
██
██
██
▄▄▄▄██
▀▀▀▀▀▀
[/
Taskford
Legendary
*
Offline

Activity: 3360
Merit: 1074


Bitz.io Best Bitcoin and Crypto Casino


View Profile
October 10, 2026, 10:38:41 PM
 #105

hmmm looks like trezor will be next.

I shifted some coins about we will see what is next to get stolen.

After seeing how Coldcard got compromised, then now we are dealing with issue of Ledger.

Who knows the next will bite the dust is trezor, so best to be prepared with that situation, knowing that maybe the bad actors are actively scanning about what they could able to do to stole huge money from people.

So yeah best to check if they are still doing fine and move those funds when you feel its so risky to hold your funds in that wallet. Nobody expect that this situation will happen early on Ledger, since people are not done yet discussing with incident happened on Coldcard.

███ 
███████▄▄███▄███▄
███▄▄████████▌████▄
▄██████████████▐███▌
██▄███████████▌████▌
████████▀███████▐▌█
███████████████▌█▌▐
████████▄████████▐▐
██████████████████▌
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀
Bitz.io███ ████████▄████▄▄▄█████▄▄
██████▄████████▀▀██▀▀
█████▀▀█████▀▀▄▄█
███████████▄▀▀███
████████████████▐▌
████████████████▐▌
███▄▄█████▄▄█▄▄█████▄▄
█▄█████████████████████▄
▄███████████████████████▄
██
███████████████████████
▀██
█████████████████████▀
█▀████
█████████████████▀
███▀▀████▀▀██▀▀█████▀▀
98%
RTP
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄███████████████
██████▄
▄███████████████████████▄
█████████████████████████
█████████████████████████
█████████████████████████
████████████████████████▀
▀█████████████████████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
HIGH
ODDS
 ████ PLAY NOW   ███
Wind_FURY
Legendary
*
Offline

Activity: 3794
Merit: 2228



View Profile
October 10, 2026, 11:50:16 PM
 #106

Everyone keeps blaming Ledger for the attack, but everyone didn't notice that the reseller "CryptoBilis" also SELLS OTHER HARDWARE WALLETS, including the Trezor.



   ¯\_(ツ)_/¯

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
BitMaxz
Legendary
*
Offline

Activity: 4130
Merit: 3695


#kycfree ❎


View Profile WWW
Today at 12:11:58 AM
 #107

Is this Ledger hardware wallet "safe?

   [~snip~]

If you read my posts in the topic "Show off your hardware wallet", I have already said that I have NEVER used it since the moment that I opened the box.

BUT we probably need to start disassembling our Ledger devices and post pictures to show everyone and ask the technical hardware wizards if their normal/safe.

Here's my Ledger. I believe it's safe?

[~snip~]

[~snip~]


Based on the image, I don't see any suspicious components. Most of the ledgers with impanted have batteries, antennas, small board modules, and SIM cards that look like small ICs or smart cards.
If one of these exists in your ledger, then your wallet is already compromised. However, I couldn't see any from your image. How about the housing or frame?

I'm actually thinking about how the SIM has unlimited data internet?  My mind tells me if I have this, I might use that SIM card for unlimited internet if it exists. What do you think? It's free data lifetime.

taufik123
Legendary
*
artcontest
Online Online

Activity: 3402
Merit: 2633


Duelbits.com


View Profile
Today at 12:30:50 AM
 #108



How's this scenario:
  • Someone knows you own a hardware wallet (thanks to a data leak).
  • Someone breaks into your house and swaps your hardware wallet for a compromised device with esim broadcasting "feature".
  • You don't notice anything wrong, and use your hardware wallet.
  • The moment you enter your PIN, it's broadcasted to the thief, who has your real hardware wallet and steals your coins.
This kind of scenario is a fairly systematic scenario, we already know how the main flow is,
we have already discussed it, starting from the data leak that occurred and became an early warning that there was something wrong with Ledger and all those affected

Some users have already discussed how to check the integrity of Ledger hardware whether or not it is safe from spy devices, keyloggers and the like.


Image Source: Generate AI

August 14, 2023
GazetaBitcoin explained about how to do a Ledger hardware integrity check that he received from Betnomi and even this was earlier than anyone
and 2 years later found a Ledger Nano X device with an Implant that has been described as a 1st generation Implant
https://bitcointalk.org/index.php?topic=5461815.msg62694410#msg62694410

Pmalek has also talked about the reverse engineering of the Ledger Nano X hardware implant carried out by Joe Grand, a crypto user from Thailand
https://bitcointalk.org/index.php?topic=5432116.msg67083679#msg67083679



Alright, that's what it is? Then manufacturers should be able to add a coated later of thick aluminium inside the shell, to prevent cellular signals from exiting in the first place. This would kill the remotely exploitable part.

And please nobody suggest to put all of your money in an iPhone. You can't airgap a phone.

@LoyceV: hopefully thick aluminium layers can solve this, right?
It may be a new type of Ledger with a thick aluminum coating, but there will always be new ways for scammers to modify the implants they will implant on the devices they distribute. Actually, the main problem is that the distribution is carried out even involving an authorized reseller who turns out to be already in the Acquisition, so that they have full access to make the implant and then take it all at once.

Ledger has failed and scammers are one step ahead.


Bitcointalk Forum users are actually one step ahead of anyone else, but the Producers and developers associated with it have never been involved with the community like ours.
underestimate people who remain consistent in their view of the development of crypto technology and how it is used.

hmmm looks like trezor will be next.

I shifted some coins about we will see what is next to get stolen.
WILL THE NEXT CASE TARGET TREZOR OR OTHER HARDWARE WALLETS?
Let's see

X-ray
Hero Member
*****
Offline

Activity: 3752
Merit: 582


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 01:13:59 AM
 #109

Everyone keeps blaming Ledger for the attack, but everyone didn't notice that the reseller "CryptoBilis" also SELLS OTHER HARDWARE WALLETS, including the Trezor.

   ¯\_(ツ)_/¯
Probably anyone in that region who bought hardware wallet in this year should move their crypto somewhere, better be safe than sorry!

Even though it's hard to believe if the reseller had planted the same supply chain attack to other type of hardware wallet, they decided not to drain other wallet as well.

This kind of attack could only be executed once, after the reputation blew up everybody would've become alerted and take precaution such as migrating their money to CEX.

But i'd prefer to move over my crypto elsewhere over having paranoid thoughts any day if I were in that situation.

██████████████████████████████████████████████████████████████
████████████
▀▀███████▀████████████████████████████████████████
██████████
▀██▄▄████▄██▐████▀▀███████████▀▀████████████████████
█████████
▌██▐██████▌██████▌█▐█████████████▐███████████████████
█████████
▌█████████▄▄▄██████▀▀▀▀███████▌█████▀████████████████
██████████
▄███▀███████▀▀██████▄██████████▐█▀█▄███▀▀███████████
████████████
▄▄███▀▀██▄▄▄▄██▐███▀██▄█▐█▌██▀█▄██▀██▄▄███████████
████████████████
▄▄███▀██▌███████▄█▌███████▐██▌███▀█▄██████████
██████████
▀███▄███████████▐██▌█▐████████▐██▐████▄██▀██████████
█████████
▌██▄███████████▄████▄████▄██▄██████▀▄█████▄▀█████████
█████████
▌██▀███▀▀███▄█████████████████████▄██▀▀▀▀▀█▄█████████
██████████
▄██████▄▄██████████████████████████▄▄▄▄▄▄███████████
██████████████████████████████████████████████████████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██

 🎰  🎲 ..Play Smarter.. 🏀  ⚽ ..Play Now..
Gravitypull$
Newbie
*
Offline

Activity: 12
Merit: 0


View Profile
Today at 03:56:10 AM
 #110

Just my thoughts. I read that CryptoBilis sold one of its company in Malaysia to a Chinese national called Jaiming on March, 2026. And the shares of the company was fully handed over to Jaiming in August 3, 2026. Is it possible that this new owner was the one who planted this SIM stealing seed phrase. I saw it on X.


Anything is possible. CryptoBilis wasn't supposed to sell this company in Malaysia to the Chinese man secretly without informing Ledger. I think that company in Malaysia is an unauthorised dealer currently.

Ledger has their latest update on this matter.

https://x.com/i/status/2108968264055345381
stompix
Legendary
*
Offline

Activity: 3766
Merit: 7443



View Profile WWW
Today at 04:14:35 AM
Merited by ABCbits (1)
 #111

Some users have already discussed how to check the integrity of Ledger hardware whether or not it is safe from spy devices, keyloggers and the like.


Image Source: Generate AI

This reminds me of this:



God, do crypto nerds love fantasy stories on James Bond scenarios or Lupin the 3rd

So the evil guy will
- find your address from the ledger hack
- not knowing if you still have that, if it's in your home, if you actually have any coins on it
- he will stalk you, he will enter your house, he will magically find your hidden ledger between the 3rd and 4th brick in the kitchen wall, and then all his master plans described above

Or...
- He will find out where you live, enter during the night, beat the crap out of you till you hand him all your cash, all your jewelry, all your coins in every damn wallet you have



▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
The Cryptovator
Legendary
*
Offline

Activity: 3038
Merit: 2623


Protect your privacy 🔏 it's very important


View Profile WWW
Today at 04:21:30 AM
 #112

Really sad. Yesterday I noticed this hacking. Even hardware wallet users aren’t safe, and funds aren’t secured anyway. I know this happens from the supplier chain, but it has become very hard to trust any hardware wallet nowadays. Although I bought my Ledger from the direct Ledger store from Amazon, I am still feeling risk. I am out of my home on vacation; after reaching home, I have to check everything.

I am not sure about my funds, although there is a small amount. I bought the device long ago and from a real source. These hardware companies shouldn’t assign any suppliers; they should only sell the device from the website and deliver themselves. Not sure if the delivery companies also try to temper the device, but they have to check everything and verify the device. The manufacturer should have some system to verify whether the device is tempered or not.

OcTradism
Legendary
*
Offline

Activity: 2618
Merit: 1050



View Profile
Today at 05:13:12 AM
 #113

Ledger is not responsible for this, and it can happen to any hardware wallet so please don't spread this kind of bad information.
I am not an anti fan of Ledger but let's say generic statement like if purchasing a device (whatever a device is) at an authorized store is still unsafe, that brand product is done.

Imagine that if I go to an authorized store of Apple, for example, and what I buy there is a fake iPhone, damn, I can not believe it and I don't mind what happened behind the scene, I will never use any Apple products later.

Apple or Ledger can blame on people who operate that authorized store but as customers of their products, my belief gone after that incident.

You would be surprised. It doesn't look their growth[1] has been slowed down in anyway since the release of the recovery feature in 2023. Currently at 8 million units sold vs 2M+ from Trezor. Still don't understand why myself.

[1] https://coinlaw.io/how-many-people-work-at-ledger/
I am surprised with the stats too and I don't understand why people still trust and use Ledger more than Trezor.

Good luck to Ledger but maybe this incident will change the customer shares in hardware wallet market between Ledger and Trezor.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████▄░░████░░▄███
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET.██████.IIIIICRYPTO'S FASTEST GROWING CASINO.██████.
|
▄
█▄█
▀█▀
▄████▄▄█████████▄▄████▄
█▄████▀█░░█████░░█▀████▄█
▀█▄▄░▐███████████▌░▄▄█▀
▐██▄▄█████████▄▄████▌
████████▄▄█████████
█
█
█▀▀████████████████
██████
█████████████
██
█▀▀████████████████
▀
▀▀▀███████████▀▀▀▀
| 
.
    PLAY NOW    
m2017
Legendary
*
Offline

Activity: 2632
Merit: 1749


keep walking, Johnnie


View Profile
Today at 05:40:54 AM
 #114

Even hardware wallet users aren’t safe, and funds aren’t secured anyway.
It seems that with any financial assets, there is no 100% guarantee of security; risks, however small, always remain. In the case of crypto assets, however, the risks appear even higher due to the intense scrutiny and frequent attacks by malicious actors. These HW devices are no longer merely storage solutions for crypto assets; it have become an attack vector that will be targeted with increasing frequency (especially as the asset's price rises) because the stakes are higher, making the effort worthwhile for attackers.

I know this happens from the supplier chain, but it has become very hard to trust any hardware wallet nowadays.
Therefore, when purchasing a HW device, you should factor in the possibility that it could be compromised, rather than blindly trusting the manufacturer or seller.

Therefore, one should not forget about risk diversification.

Although I bought my Ledger from the direct Ledger store from Amazon, I am still feeling risk.
Even if you were to buy the hardware wallet right at the doorstep of their production facilities, risks would still remain. Smiley

I am out of my home on vacation; after reaching home, I have to check everything.
Don't forget to open the HW device's casing and check the circuit board for any visible foreign objects (it seems every new buyer of these HW devices should make this a standard practice now Smiley). So far, malicious actors haven't figured out how to disguise them effectively.

I am not sure about my funds, although there is a small amount.
There’s no point in unnecessarily working yourself up into a state of fear. Things might just turn out okay after all. Although, knowing Ledger, it’s probably only a matter of time. Smiley Maybe it’s time to consider switching to hardware wallet from other manufacturers?

I bought the device long ago and from a real source.
This could prove to be your salvation from the ongoing hacking.

These hardware companies shouldn’t assign any suppliers; they should only sell the device from the website and deliver themselves.
What about even eliminating the intermediary - the postal service or delivery provider (which, incidentally, represents yet another attack vector)? That’s simply not feasible, as setting up an in-house delivery service makes no economic sense.

By the way, manufacturers don't ship their devices to every country (even where postal services are available).

Not sure if the delivery companies also try to temper the device, but they have to check everything and verify the device.
Just because a vulnerability hasn't been exploited yet (like the 5 year period in the case of Coldcard) doesn't mean it won't be exploited in the future.

The manufacturer should have some system to verify whether the device is tempered or not.
Trezor, for instance, has this protection - a sticker on the casing. Cheesy

By the way, as far as I know, Ledger never used anything of the sort, but times have changed, and the presence of "new integrated components installed by malicious actors to steal funds from wallet owners" will force the implementation of new measures.

libert19
Legendary
*
Offline

Activity: 3374
Merit: 1204


★Bitvest.io★ Play Plinko or Invest!


View Profile WWW
Today at 05:44:44 AM
 #115

As of currently, this appears to be a supply-chain attack, as the wallets were tampered with. So, now your choice is to only purchase from official websites; once that's also compromised, we'll see about it later. You are welcome.
Because that worked so well for Coldcard users. At this point, you’re better off just not using a hardware wallet.

My advise only minimizes supply-chain attacks, you are susceptible to everything else as usual. As for being done with HWs, until my Trezor treasures my peanuts, you don't say no shit about HWs.

The average user simply lacks the ability to verify, not trust with these devices.

Breh, my brain cells are barely good enough to be good at one thing that's why we delegate security to these companies thinking they may be competent.

Even though it's hard to believe if the reseller had planted the same supply chain attack to other type of hardware wallet, they decided not to drain other wallet as well.

Don't think attackers would be 'generous' to not drain other hardware wallets if they had means to; I wonder if Ledger had some particular flaw that allowed attackers to execute this attack on 'em while not on others?

║
★
║
.
.BIG WINNER!.
[15.00000000 BTC]
║
★
║
▄████████████████████▄
██████████████████████
██████████▀▀██████████
█████████░░░░█████████
██████████▄▄██████████
███████▀▀████▀▀███████
██████░░░░██░░░░██████
███████▄▄████▄▄███████
████▀▀████▀▀████▀▀████
███░░░░██░░░░██░░░░███
████▄▄████▄▄████▄▄████
██████████████████████

▀████████████████████▀
▄████████████████████▄
██████████████████████
█████▀▀█▀▀▀▀▀▀██▀▀████
█████░░░░░░░░░░░░░████
█████░░░░░░░░░░░░▄████
█████░░▄███▄░░░░██████
█████▄▄███▀░░░░▄██████
█████████░░░░░░███████
████████░░░░░░░███████
███████░░░░░░░░███████
███████▄▄▄▄▄▄▄▄███████

██████████████████████
▀████████████████████▀
▄████████████████████▄
███████████████▀▀▀▀▀▀▀
███████████▀▀▄▄█░░░░░█
█████████▀░░█████░░░░█
███████▀░░░░░████▀░░░▀
██████░░░░░░░░▀▄▄█████
█████░▄░░░░░▄██████▀▀█
████░████▄░███████░░░░
███░█████░█████████░░█
███░░░▀█░██████████░░█
███░░░░░░████▀▀██▀░░░░
███░░░░░░███░░░░░░░░░░

▀██░▄▄▄▄░████▄▄██▄░░░░
▄████████████▀▀▀▀▀▀▀██▄
█████████████░█▀▀▀█░███
██████████▀▀░█▀░░░▀█░▀▀
███████▀░▄▄█░█░░░░░█░█▄
████▀░▄▄████░▀█░░░█▀░██
███░▄████▀▀░▄░▀█░█▀░▄░▀
█▀░███▀▀▀░░███░▀█▀░███░
▀░███▀░░░░░████▄░▄████░
░███▀░░░░░░░█████████░░
░███░░░░░░░░░███████░░░
███▀░██░░░░░░▀░▄▄▄░▀░░░
███░██████▄▄░▄█████▄░▄▄

▀██░████████░███████░█▀
▄████████████████████▄
████████▀▀░░░▀▀███████
███▀▀░░░░░▄▄▄░░░░▀▀▀██
██░▀▀▄▄░░░▀▀▀░░░▄▄▀▀██
██░▄▄░░▀▀▄▄░▄▄▀▀░░░░██
██░▀▀░░░░░░█░░░░░██░██
██░░░▄▄░░░░█░██░░░░░██
██░░░▀▀░░░░█░░░░░░░░██
██░░░░░▄▄░░█░░░░░██░██
██▄░░░░▀▀░░█░██░░░░░██
█████▄▄░░░░█░░░░▄▄████
█████████▄▄█▄▄████████

▀████████████████████▀
║
★
║
║
★
║
✔ Rainbot
✔ Daily Quests
✔ Faucet
Meuserna
Sr. Member
****
Offline

Activity: 402
Merit: 750


View Profile WWW
Today at 07:35:01 AM
Merited by libert19 (1)
 #116

Breh, my brain cells are barely good enough to be good at one thing that's why we delegate security to these companies thinking they may be competent.

I realize you're mostly kidding, but... That, right there? That's the problem. Whether intentionally or not, you summed it up perfectly.

Too many people want to trust somebody else. A stongman, a company, whoever posts a stupid effing lazer-eyes pic. It's all so astonishingly stooooooooopid.

Dumber than dumb.

We have to do a better job of preaching the fact that self-custody means self-responsibility. You are responsible for your coins, and choosing to trust anyone other than yourself is a choice made by you.

Ledger leaked their entire customer database, including customers' home addresses. But people kept trusting them. WHAT?!

Ledger employees got phished, leading to loss of customer funds. But people kept trusting them. WHAT?!

Then, the story got worse. It was Ledger's former employees who got phished, and Ledger couldn't explain why former employees still had access to their code. But people kept trusting them. WHAT?!?!?!?!?!?!

And y'know why people kept trusting them? Because the devices look cool. My God.

We saw the same thing with ColdCard. ColdCard's abysmal code cost over a hundred million dollars in losses for their customers, but idiots thought their "calculators" were so cool, so they are as we speak making excuses for trusting ColdCard. Just wow. So much wow.

So many people are not serious about doing Bitcoin self custody.

I love Bitcoin, but so many of our fellow hodlers don't even understand the basics.

Never trust your coins to any code that isn't open source. Bitcoin is open source. Every line of code you use to secure your coins should be open source too. No exceptions.

Never trust companies to secure your coins. Not until those companies include insurance for coins they secure. They will always protect themselves before you.

Always assume anything known to be related to Bitcoin is a risk to buy or receive in the mail. Supply chain attacks are real. Name and address leaks are real.

Generate your own random seed by hand. Don't trust code to do it. The ColdCard catastrophe proved why this matters.

Everything I'm seeing pushes me further and further into DIY, and my coins are more secure because of it.

SeedSigner hardware, running the ShieldSigner fork. In 2026, that's as good as it gets in terms of security. Nothing is better, at any price. And for your seed phrase: Metal backup, secured in a safe with a home automation sensor that notifies you instantly if the safe is opened or moved. The home automation will cost less than $60.

Anyone who thinks this is over the top needs to rethink what just happened over the last three months. $200 million dollars in Bitcoin has been stolen due to ColdCard's code and Ledger's AUTHORIZED resellers. Thieves are only going to get smarter. So, be smarter too.

Generate your own seed phrase.

Only trust open source code that has been vetted.

Get an airgapped hardware wallet. Anything that can connect to the internet cannot be trusted. No exceptions.

Think like an attacker to solve self custody issues.

ABCbits
Legendary
*
Offline

Activity: 3752
Merit: 10428



View Profile
Today at 08:04:48 AM
 #117

Everyone keeps blaming Ledger for the attack, but everyone didn't notice that the reseller "CryptoBilis" also SELLS OTHER HARDWARE WALLETS, including the Trezor.



   ¯\_(ツ)_/¯

No, someone already mentioned it earlier on https://bitcointalk.org/index.php?topic=5596352.msg67224125#msg67224125.

It's another nail on their coffin, not sure the last one as we all have to wait and witness what will happen next with Ledger.

Ledger is so crappy from data breaches, to Ledger Recover (smh with this product), then this Ledger authorized reseller CryptoBilis but maybe more, it's hard to trust Ledger again.
Ledger is not responsible for this, and it can happen to any hardware wallet so please don't spread this kind of bad information.

Regardless or legal or ethical responsibility on Ledger side, it's enough to make more people skeptical or even distrust Ledger. People who do their research would aware this isn't first time 3rd party they use screwed up and harm Ledger customer in a way or another.

joker_josue
Legendary
*
Offline

Activity: 2534
Merit: 7584


**In BTC since 2013**


View Profile WWW
Today at 08:32:54 AM
 #118



How's this scenario:
  • Someone knows you own a hardware wallet (thanks to a data leak).
  • Someone breaks into your house and swaps your hardware wallet for a compromised device with esim broadcasting "feature".
  • You don't notice anything wrong, and use your hardware wallet.
  • The moment you enter your PIN, it's broadcasted to the thief, who has your real hardware wallet and steals your coins.
This kind of scenario is a fairly systematic scenario, we already know how the main flow is,
we have already discussed it, starting from the data leak that occurred and became an early warning that there was something wrong with Ledger and all those affected

Some users have already discussed how to check the integrity of Ledger hardware whether or not it is safe from spy devices, keyloggers and the like.


Image Source: Generate AI

Well, this type of scenario has always been possible; it wasn't necessary for this kind of event to happen.

Furthermore, something like this can happen with any brand, be it Ledger, Trezor, or any other.
They'll say the problem is that Ledger had customer data leaked. Yes, but apparently it's happened to other brands too; there are also logistics companies that deliver the orders.

Finally, if we go down this path, I think the best solution starts with memorizing the seed. Only then can we avoid external factors.  Roll Eyes

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
█████████░█████░█████████
████████▀▀░▄▄▄░▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄░▀▀▀░▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
█▀▀
█
█
█
█
█
█
█
█
█
█
█
█▄▄
▀▀█
█
█
█
█
█
█
█
█
█
█
█
▄▄█
 
  Open − code isolated Crypto Wallet     Sign Up    
cygan
Legendary
*
Offline

Activity: 4032
Merit: 13390


icarus-cards.eu


View Profile WWW
Today at 09:48:52 AM
Merited by Pmalek (3)
 #119

Mark Karpeles continues to investigate the case and, in the following tweet, shows how the spy implant was soldered onto the Ledger circuit board and which testpads it was connected to. apparently, there were two different versions...
for anyone who’s into this and 'understands' circuit boards, these images and this tweet are certainly very interesting.



https://x.com/MagicalTux/status/2109031679528702257

Comeacross
Full Member
***
Online Online

Activity: 308
Merit: 128



View Profile
Today at 10:19:42 AM
 #120

So the evil guy will
- find your address from the ledger hack
- not knowing if you still have that, if it's in your home, if you actually have any coins on it
- he will stalk you, he will enter your house, he will magically find your hidden ledger between the 3rd and 4th brick in the kitchen wall, and then all his master plans described above

Or...
- He will find out where you live, enter during the night, beat the crap out of you till you hand him all your cash, all your jewelry, all your coins in every damn wallet you have

Ahhaah Cheesy

I look at the image and it was like a movie to me. Your description makes it sound more funny. If it was this easier, we could be having incidents like this every day Cool

The possibility of this scenario happening is nearly zero but we really should not completely rule out the scenario even thou the chance is very slim. Unless someone very close to you is involved in the attack (which is also unlikely because how do you even tell people where you keep your device? Even the closest people?) because a random criminal will not come to your house to start searching for your device just to swap it. Of course, you could be physically attacked if they have info but that's not a swap deal, they come for your device directly which you either give willingly or suffer pains.

But, there's still a lesson to learn from it. As usual, never keep your device where anyone can access it  Wink

Pages: « 1 2 3 4 5 [6] 7 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!