This is a developing story, but it seems that certain Ledger devices have been found to contain cellular-enabled bugging chips which can capture seed phrases. The Ledger authorized reseller
CryptoBilis has especially been implicated as allegedly shipping these bugged devices, but more sellers could also be involved.
My recommendation would be:
- If you have crypto on
any hardware wallet which you bought from CryptoBilis in 2026, consider the seed phrase compromised, and move the crypto ASAP.
- If you have any Ledger device which you purchased since about mid-2025, keep watching this story very carefully, since bugged devices have been found to have come from sources other than just CryptoBilis. This might be a wider supply-chain issue.
More info:
https://bitcointalk.org/index.php?topic=5596352.0https://www.tibane.net/research/ledger-nano-x-implant