Suspected hardware wallet thefts linked to Ledger device distributor CryptoBilis have reached nearly $90 million, prompting Tether to freeze stolen USDT on-chain. Following reports of compromised funds, Ledger issued an Oct. 9 statement urging customers who purchased devices from the Southeast Asian reseller within the past 90 days to refrain from initializing them.
Key Takeaways
- Blockchain security firm MistTrack estimates total losses near $90 million, up from an initial $86 million calculation by investigator Specter.
- Ledger paused all shipments and sales from CryptoBilis, an authorized reseller operating in Malaysia, Indonesia, and the Philippines.
- Binance founder Changpeng Zhao stated the incident appears to be a localized supply chain attack affecting physical device hardware.
- Tether has begun freezing stolen USDT addresses, though native Bitcoin, Ethereum, and Tron assets remain beyond direct contract freezes.
Hardware Tampering and Supply Chain Vulnerabilities
According to blockchain security researchers, compromised funds flowed from hundreds of victim wallets across Bitcoin, Ethereum, and Tron networks. While initial estimates by researcher Specter placed total losses above $86 million, security firm MistTrack later reported figures closer to $90 million. This comes alongside broader security concerns regarding self-custody hardware, echoing incidents where a trader lost $6.6 million in Bitcoin after buying a new Ledger wallet.
Former Mt. Gox CEO Mark Karpelès asked CryptoBilis to inspect the internal circuit boards of unsold Ledger units for spying implants or unauthorized hardware modifications. Ledger's official documentation confirms that while its Genuine Check system authenticates the Secure Element microchip, it cannot detect external physical modifications if the original chip remains unaltered. Binance founder Changpeng Zhao publicly commented on X, writing, "Based on information so far, it seems to be localized to a supply chain attack with one vendor," while adding, "I expect and know all BNB ecosystem players (and all industry) to help trace and recover the funds."
Tether Intervention and Recovery Limits
In response to the exploit, Tether exercised its administrative smart contract controls to freeze USDT tokens associated with the flagged hacker addresses. However, MistTrack noted that the precise dollar amount of frozen USDT remains unconfirmed, leaving the total proportion of recoverable assets uncertain. Because administrative freezes do not apply to native layer-1 assets like Bitcoin or Ethereum, asset recovery for non-stablecoin funds relies heavily on central exchange cooperation and law enforcement intervention.
Why It Matters
This supply chain compromise underscores a critical vulnerability in crypto hardware security: even secure enclave architecture cannot fully defend against upstream physical tampering. While Tether's freeze functionality offers partial asset mitigation for USDT, the incident highlights that decentralized native assets remain irrecoverable once signed by a compromised device. Hardware vendors will likely face mounting pressure to introduce cryptographic physical tamper-evidence throughout their third-party retail distribution networks.



