HomeCrypto NewsCrypto Hacks & CrimeLedger Confirms an Unauthorized Hardware Implant in One Device Affected in the...

Ledger Confirms an Unauthorized Hardware Implant in One Device Affected in the CryptoBilis Case

Ledger, the French maker of hardware wallets (devices that keep a person’s crypto keys offline), has confirmed that one affected user’s device “contained an unauthorized hardware implant”. It said so on X at 18:09 BST on Saturday 10 October 2026. That is new: TSN’s earlier post covered Ledger’s investigation and its belief that drained funds were limited to devices sold through the reseller CryptoBilis, but Ledger had not said what it had found.

Spotted via @Ledger_Support on X

What Ledger confirmed

Confirmed (Ledger’s own statement). The verified Ledger Support account wrote: “Ledger can confirm that one of the impacted users’ devices contained an unauthorized hardware implant. Ledger is reaching out to impacted users as part of the ongoing investigation.” [1]

In plain terms, a hardware implant is a chip or component added to a device without the owner’s or maker’s authorisation. Ledger’s post does not say what the implant was, what it did or where it was added.

What else the post says

The rest of the post says Ledger is “working with the appropriate authorities”. It says CryptoBilis “confirmed it has ceased sales of all hardware wallet inventory until the investigation is concluded”; that is Ledger relaying CryptoBilis, and TSN has not seen a CryptoBilis statement. Ledger repeats that it has “no indication that Ledger’s security infrastructure, systems or services have been compromised”, and its advice: buyers from this reseller who have not set up a device should not, and those who have should “consider moving assets to a new Ledger signer (with a new seed)” [1].

The loss figures are still not Ledger’s

Reported. Bitquery, a blockchain-data firm, counts $93.2 million taken from 315 wallets; TSN’s earlier post quoted its earlier $92.9 million from 311 wallets [2]. That is Bitquery’s claim, TSN has not checked it, and Ledger has confirmed no total.

What this does not show

  • That every affected device had an implant. Ledger said one.
  • How, when or by whom an implant was added, or how many devices are involved. Ledger has not said.
  • What caused the losses. Ledger’s post does not link the implant to any amount lost.
  • That any loss figure is right. The totals are Bitquery’s and others’, not Ledger’s [2].

The Bottom Line

Ledger has confirmed that one impacted user’s device contained an unauthorized hardware implant and that its investigation continues. Scale, cause and losses remain unconfirmed by Ledger.

Related on TSN: Ledger Investigates Lost Funds Among CryptoBilis Buyers and Pauses the Reseller’s Sales

Sources

  1. Ledger Support (@Ledger_Support, verified), “Situation Update”, X post, 10 October 2026, 18:09 BST (read in full via the X API long-post field; primary statement). https://x.com/Ledger_Support/status/2108968264055345381
  2. Bitquery (Gaurav Agarwal), “Ledger CryptoBilis Hack”, read 11 October 2026 (Bitquery’s own count, now $93.2M from 315 wallets; reported, not confirmed by Ledger; TSN has not checked the tracing; the page’s title uses the word “hack”, which TSN does not). https://bitquery.io/investigations/ledger-cryptobilis-hack
  3. TSN, “Ledger Investigates Lost Funds Among CryptoBilis Buyers and Pauses the Reseller’s Sales”, 9 October 2026, updated 10 October. https://tsnmedia.org/ledger-cryptobilis-reseller-investigation-sales-pause/

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.