The company says one affected user's device contained an unauthorized hardware implant, and that CryptoBilis has now stopped selling hardware wallets altogether. Ledger still confirms neither a loss total nor a cause, and the researcher estimates above $86 million remain unverified.
Ledger said on Saturday that one of the devices belonging to an affected user contained an unauthorized hardware implant, the first physical finding the company has published since it began investigating reports of drained wallets among Southeast Asian customers of the reseller CryptoBilis.
The statement went out through the company's support account at 17:09 UTC and is written as a situation update rather than a conclusion. Ledger says it is contacting affected users, that it is working with the appropriate authorities, and that it has "no indication that Ledger's security infrastructure, systems or services have been compromised." It also records a change on the reseller's side: CryptoBilis "confirmed it has ceased sales of all hardware wallet inventory until the investigation is concluded," and Ledger says it is in active communication with the company on next steps. That goes further than the pause Ledger requested on Friday, which covered Ledger devices alone.
What the update supplies is evidence of tampering in at least one device. What it does not supply is a count, a cause or a chain of events. Ledger has not said how many devices carried an implant, what the implant did, who installed it or at which point in the distribution chain, and it has published no finding that the implant is what emptied the wallets. On Friday the mechanism was unestablished and the strongest available explanation was inference from the pattern of losses. One confirmed implant narrows that question without closing it.
The most detailed public account of a device comes from an affected owner rather than the company. Mark Karpeles, the former Mt. Gox chief executive, wrote on Friday that his own unit arrived from Malaysia with "flawless shrink wrap" and that the implant was "cleverly hidden where the screen's padding is supposed to be," invisible on first opening the case. Three hours later he posted a microscope image and described the component as a "spy SIM card, a 2x2mm chip," adding that further details including the provider were still to come. That establishes what Karpeles found and photographed in one device he bought. It does not establish the chip's function, and he has named no supplier.
Ledger's statement rules out one location and leaves the rest open. It says there is no indication that the company's own security infrastructure, systems or services were compromised, and it does not say where between the factory and the buyer the implant was fitted. A buyer who receives a sealed box from an official reseller has no step at which to inspect the board, and intact shrink wrap is the signal most owners rely on. Owners have been reached through intermediaries before: a breach at a third-party email provider in September let attackers send phishing from Trezor's own domain, exploiting a channel customers had reason to trust. A compromised reseller would exploit the same trust earlier, before the customer has done anything at all.
The money involved is still an outside estimate. Ledger has confirmed no total. The pseudonymous on-chain investigator Specter put losses above $86 million on Friday after tracing suspected theft addresses across Bitcoin, Ethereum and Tron, a figure CoinDesk reported without independent confirmation, and a second researcher, Tanuki42, put more than $72 million into a group of suspected theft addresses. Both totals rest on judging which addresses received stolen funds and then adding what flowed in, and it is not clear that the two cover the same transactions. Later tallies circulating above $90 million were not traceable to a published source and are not reported here.
Ledger is asking for help from outside its own investigation. The update directs anyone with information to the company's bounty program at bounty@ledger.fr and credits the security collective SEAL 911 for what it calls collaborative support on the investigation. The company says it is continuously adding security mitigations and is working on further anti-tampering solutions, which is a statement of intent rather than a described change to any shipping device.
Changpeng Zhao, the Binance co-founder who said last week that the available information suggested a supply-chain attack involving a single vendor, has since disclosed a commercial interest in the category. Writing on Saturday that he is not against hardware wallets or self-custody, he noted that his investment arm YZiLabs has put money into OneKey and SafePal, both hardware wallet makers, and into the mobile wallet Trust Wallet. The disclosure does not bear on whether his reading of the incident is right, and it is relevant context for a public comment about a competitor's distribution.
Ledger's guidance has not changed. Anyone who bought a device from the reseller and has not begun setting it up is told not to start, and anyone who has is told to consider moving assets to a new Ledger signer with a new seed. That instruction assumes the worst about any unit from the affected channel, which is the only safe assumption available while the number of implanted devices is unknown. CryptoBilis is listed as an official Ledger reseller in Indonesia, Malaysia and the Philippines, and its confirmation that it has stopped selling hardware wallets reached the public through Ledger rather than in a statement of its own.