Attackers tampered with Ledger Nano X hardware wallets sold through CryptoBilis, an authorized reseller (which was later sold to a Chinese company in secrecy) in Southeast Asia, and used a hidden implant to capture recovery phrases while users set up their devices. More than $86 million in Bitcoin, Ethereum, and Tron has been drained from victim wallets, and Ledger has paused all sales and shipments by the reseller.
The implant does not touch the device’s Secure Element or exploit a firmware bug. It sits on the internal bus that drives the screen, copies the 24-word seed phrase as it is displayed, and sends it out over a cellular modem.
What happened
Blockchain investigator Specter flagged the first anomalies on October 9, 2026, when a cluster of collection addresses began receiving large, simultaneous transfers from hundreds of unrelated wallets. MistTrack and Arkham Intelligence later traced the stolen funds, which they put closer to $90 million, almost exclusively to users who had recently bought a Ledger device from CryptoBilis. The victims were mostly high-net-worth holders with large cold storage balances.
CryptoBilis is an authorized Ledger reseller serving Malaysia, Indonesia, and the Philippines. Ledger told users who bought a device from the reseller in the past 90 days not to initialize it. Anyone who already has should move their assets to a new, untampered hardware signer with a fresh seed phrase.
The attackers did not exploit Ledger Live or the Nano X’s Bluetooth Low Energy stack. They already held each victim’s BIP-39 recovery phrase from the moment the wallet was set up, so they imported the seed into their own software wallets and swept the balances.
Where the trust boundary breaks
A Ledger device uses two chips. The Secure Element, typically an ST33 or ST31, is hardened against side-channel attacks, voltage glitching, and laser fault injection. It generates the entropy, derives the seed phrase, and signs transactions. An STM32 microcontroller handles the user interface, Bluetooth, and routing between the Secure Element, the USB port, and the OLED screen.
The Secure Element has no display controller of its own. At setup it passes the recovery words to the STM32, which formats them and sends them to the OLED over an internal bus. That bus is the weak point the CryptoBilis implant exploits.
Three generations of the implant
Researchers including Joe Grand of Grand Idea Studio and the team at Tibane Labs have reverse-engineered compromised units and identified three versions.
The first, documented in late 2025, was a proof of concept. Hand-soldered, enamel-coated copper wires tapped the OLED data lines and fed an unmarked ARM Cortex-M0+ microcontroller and a Luat Air700E LTE modem with an MFF2 eSIM, often on an anonymous IoT data profile. To make room, the attackers shrank the internal battery and bypassed the fuel gauge with a 10kΩ resistor so the device always reported a full charge.
The second version replaced the wires with a custom polyimide (Kapton) flex circuit laminated across the back of the main board. It tapped factory test pads for ground, battery voltage, and the display SPI lines. It still needed modifications to the battery housing to fit the modem.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →The third version, linked to the CryptoBilis thefts, leaves almost no outside trace. The retail shrink wrap is intact and the casing shows no sign of prying. Inside, the attackers removed the foam pad behind the OLED, which normally blocks light bleed and cushions the glass, and used the sub-millimeter cavity to hold an ultra-thin black flex PCB carrying the spy chip and antenna. They abraded or chemically scraped the markings off the ARM microcontroller and the eSIM chip to slow identification. The one visible giveaway is a thin black antenna wire routed along the top inner edge of the casing, which gives the modem a signal through the device’s shielding.
How the implant captures the seed
The implant taps the SPI clock (SCK) and data (MOSI) lines between the STM32 and the display driver. The bus is neither encrypted nor authenticated, so the implant can monitor it passively without disturbing the display.
The Cortex-M0+ buffers the bitstream and compares it against a hardcoded dictionary of glyphs for the letters a to z and the digits 0 to 9. When it recognizes the byte sequence for the recovery phrase screen, it stores the 24 words in local flash, powers up the LTE modem, and sends them to the attackers’ command-and-control server by HTTP or SMS. Until then it stays dormant. The user writes down the words, sets a PIN, and starts moving funds with no sign anything is wrong.
Ledger’s Genuine Check also passes on these devices. The check has Ledger Live query the Secure Element and verify its signature against Ledger’s root certificates. The Secure Element in a tampered unit is authentic and generating sound entropy, and the implant never touches it, so Ledger Live reports the device as genuine.
The CryptoBilis connection
According to the former co-founders of CryptoBilis, the company was acquired by new owners earlier in 2026. Analysts suspect the compromise happened in the last stretch of distribution, either through an insider at a regional fulfillment warehouse or through counterfeit, pre-tampered units entering the authorized supply stream.
Either way, an attacker who gets hands-on access to a batch after it leaves the factory and before it reaches customers can install hardware that software audits will not catch. Breaking AES or finding a zero-day in the STM32 firmware is unnecessary. A soldering iron and an OLED flex cable are enough.
How to check a device
Anyone who suspects a unit came from the affected batch can open it and look for the signs below. Opening the device voids the warranty and can damage the fragile OLED ribbon cable, so use ESD-safe tools.
- A thin black enameled wire along the top inner rim of the casing that is not the factory Bluetooth antenna.
- Missing foam padding behind the OLED, or a rigid black flex PCB between the screen and the mainboard.
- An unusually thin battery, or a 10kΩ resistor soldered across the battery connector pins, which indicate a first- or second-generation implant.
Electrical testing is possible in principle. An active LTE modem draws a distinct current spike when it connects and transmits, so a high-sampling-rate USB meter might catch an anomaly during seed generation, when a clean Nano X should draw a steady baseline. The extra processing could also add microsecond-level latency to screen rendering that a logic analyzer on the SPI bus would show. These methods are impractical for most owners, which leaves chain of custody as the main defense.
What owners should do
If you bought a Nano X or Nano S Plus from CryptoBilis or another Southeast Asian reseller within the past 90 days, treat it as compromised and do not power it on to test it. If it is already initialized, assume the attackers have your seed phrase.
To move funds off a suspect device:
- Buy a replacement directly from the manufacturer’s website, such as Ledger.com, Trezor.io, or Coinkite. Avoid Amazon, Shopee, Lazada, eBay, and regional resellers for high-value storage.
- Initialize the new device offline to generate a new 24-word seed.
- Power on the compromised device one last time and sweep 100% of your Bitcoin, Ethereum, and other assets to addresses on the new device.
- After the transfers confirm, destroy the old device, including the Secure Element and the STM32.
Adding a passphrase (the 25th word) to a compromised device is only a stopgap. An attacker holding the 24 words could still try to brute-force the passphrase, so a full seed migration is the only reliable fix. On a new device, a strong, memorized passphrase adds a layer the implant cannot read from the display bus, unless it also logs PIN or passphrase entry, which teardowns have not confirmed.
When the new device arrives, inspect the holographic tamper seals. The third-generation implant defeats the outer shrink wrap, but misaligned or damaged holograms are still a sign of interception.
The display trust problem
Consumer hardware wallets ask users to trust that what the screen shows matches what the Secure Element holds. Because a second microcontroller drives the display over an unencrypted bus, users cannot verify cryptographically that the words they copy down are the ones controlling their funds.
One proposed fix is a secure display channel, in which the Secure Element sends a hash of the display frame that the user checks on an independent device. Until wallets adopt something like it, supply chain integrity is the only protection against bus-sniffing implants.
For large holdings, a multisignature setup limits the damage from one stolen seed. In a 2-of-3 or 3-of-5 arrangement, a single compromised phrase cannot move funds. Spreading signers across manufacturers and purchasing channels, for example one Ledger, one Coldcard, and one Trezor, means an attacker would have to breach several supply chains at once. Sparrow Wallet, Electrum, and Nunchuk support this kind of configuration.
A rough year for hardware wallets
Earlier in 2026, a firmware flaw in Coldcard wallets resulted in more than $111 million in losses. That bug was a predictable random number generator that let attackers reconstruct seed phrases mathematically without touching a device. It hit thousands of retail wallets averaging about $21,000 each. The Ledger implant is far narrower, with average losses above $890,000 per compromised unit.
Ledger has been hit before. In late 2023, attackers compromised the Ledger Connect Kit library and drained millions from DeFi protocols. In 2020, a customer database breach fed years of physical-mail phishing. The CryptoBilis case adds a hardware vector to that history.
The Secure Element itself was not broken, and the Genuine Check results are consistent with that. The theft came from the physical handling of devices before they reached customers.
Teardowns of hardware wallets risk damaging the device, voiding the warranty, and puncturing the lithium-ion battery. Follow the manufacturer’s guidance and use ESD-safe equipment.











