Ledger Suspends CryptoBilis Sales Amid Reports of User Fund Losses

Last Updated:
Hackers Access Over 13,000 Trezor Users’ Data by Breaching Third-Party Shipping Company
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Ledger pauses CryptoBilis sales and shipments while investigating reports of missing crypto funds.
  • Specter claims potential losses exceed $86 million, but the amount remains unconfirmed.
  • CZ warns of a possible supply-chain attack, though the cause remains unknown.

Ledger, a cryptocurrency hardware wallet maker, has reportedly suspended sales and shipments through a Southeast Asian reseller. The move comes after reports revealed that some customers had lost crypto funds after purchasing devices through the reseller, CryptoBilis.

Why Has Ledger Suspended CryptoBilis Sales?

According to the official statement issued by Ledger, users have lost crypto funds while purchasing devices through CryptoBilis, a Southeast Asian reseller. The team is now investigating the issue and has asked the reseller to pause all sales and shipments while it looks into the incidents.

Following the incident, blockchain sleuth Specter stated on X that more than $86 million in crypto may have been stolen from hundreds of wallets. But this has not been officially confirmed. It is still not clear whether these incidents are all connected.

Users who have purchased devices through CryptoBilis within the past 90 days are urged to avoid setting them up if they haven’t already done so. The company added that those who have already activated their devices should consider transferring their crypto assets to a new Ledger signer using a newly created recovery phrase.

How Does the Incident Impact Crypto Wallet Security?

Notably, the Ledger incident has raised concerns about the safety of buying crypto hardware wallets through third-party resellers. Usually, Ledger devices are supposed to keep private keys offline. But the latest incident highlights the importance of checking where devices come from. Security precautions should also be followed during the setup.

However, the cause of the reported losses remains unknown. It is also not confirmed whether Ledger’s wallet technology was compromised. The investigation hasn’t revealed whether the incident involved devices, the setup process, or another security issue.

Could a Supply-Chain Attack Be Behind the Ledger Fund Losses?

Significantly, experts claim that a supply-chain attack could be one possible reason for the Ledger incident. This happens when a product is tampered with before it reaches the customer. In a hardware wallet attack, the hacker could potentially interfere with the device or its setup process to gain access to the funds stored in it.

In detail, if the wallet’s recovery phrase is already known to the attacker, they could use the phrase to access the associated crypto assets after the user deposits funds. Thus, it is important for users to create their own recovery phrases during the setup process. They should never trust a phrase that has already been provided by another individual.

Nonetheless, there is currently no confirmation that the supply-chain attack has occurred in the CryptoBilis case. Ledger hasn’t stated whether the reported losses resulted from device tampering, the setup process, or another security issue.

(adsbygoogle = window.adsbygoogle || []).push({});

CZ Warns Ledger Users Over Possible Supply-Chain Attack

Binance founder Chanpeng Zhao has also warned Ledger users to remain cautious. He noted that the reported incidents may be linked to a possible supply-chain attack involving a single seller. CZ added,

“Beware if you use a Ledger hardware wallet, especially if you bought one recently. Based on information so far, it seems to be localized to a supply chain attack with one vendor. A small number of people probably bought fake (or tampered) Ledgers.”

But it is worth noting that the supply-chain attack theory remains only a preliminary assessment. The exact cause of the crypto fund losses is still not identified or confirmed.

Related: CZ Shocked After Token2049 Attendee Reports Attack in Singapore

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.