Ledger suspects spy hardware in supply chain attack on CryptoBillis wallets
Ledger has asked reseller CryptoBillis to pause sales after reports suggest spy hardware intercepted seed phrases and drained crypto accounts from hundreds of users.

Suspected spy implant found in devices
Photos shared on social media show a small circuit board hidden under the screen of some wallets. This component allegedly intercepts information displayed during setup, such as the seed passphrase. The device uses an embedded SIM card to send stolen data back to attackers.
Attack targets specific reseller and region
The issue appears limited to users in Southeast Asia who bought devices through the CryptoBillis reseller. Ledger stated that its own systems were not compromised and direct purchases remain unaffected. The company has issued guidance for customers to check if their hardware has been tampered with.
Total financial loss reaches high figure
Reports indicate that attackers have stolen over 86 million worth of cryptocurrency from affected accounts. This supply chain attack represents a significant breach involving hundreds of individual wallets. Ledger continues to investigate the root cause while sales through the reseller are paused.
Reported by one outlet
Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.
Reported by
1 independent outlet. Headline as published. Links open the original report.