Podcast transcripts, polished for reading

Ledger Devices Hacked. $86M GONE. ‘Not Your Keys’ Is DEAD WRONG | Digital Asset News Transcript

Polished transcript · Digital Asset News · 9 Oct 2026 · @nonbureaucrat

Ledger hardware wallet supply chain hack results in $86M stolen from users

Rob Nelson of Digital Asset News covers a major supply chain attack on Ledger hardware wallets sold through an authorized reseller.

Summary

A supply chain attack on Ledger hardware wallets distributed through an authorized reseller called CryptoBillis, primarily affecting buyers in Southeast Asia, is the subject of this breaking report from Digital Asset News. More than $86 million — later revised upward to $90 million — was stolen across Bitcoin, ETH, and Tron from hundreds of wallets, with victims reporting they had done everything correctly: storing seed phrases offline, avoiding leverage and risky trades, and using hardware wallets exactly as recommended. The attack was made possible by physical spy modules implanted into Ledger Nano X devices before sale, which monitored on-screen data including seed phrases and transmitted them to a third party. The incident is argued to expose a critical flaw in the "not your keys, not your crypto" doctrine, making the case that storage diversification — including custodial services and Bitcoin ETFs — is now essential. Mark Karpelès, the former CEO of Mt. Gox, is credited with uncovering the attack, with the report noting that without his investigation it could have continued undetected for years.

The report also highlights a separate but concurrent threat: a fake Ledger website appeared at the top of Google search results with over one million visits in the past 30 days, designed to steal seed phrases — meaning users who did not purchase from CryptoBillis could still have been compromised through this second attack vector.

Key Takeaways

  • The attack was a physical hardware implant, not a software hack. Spy modules were soldered into Ledger Nano X devices by an authorized reseller, CryptoBillis, before sale. Ledger's own genuineness checks could not detect the tampering because the devices themselves were not modified — only monitored.
  • CryptoBillis was a reputable, authorized Ledger dealer for four years before being sold to a buyer in March 2026. The sale of the reseller business appears to be the point at which the attack was enabled, making the supply chain compromise extremely difficult for ordinary buyers to anticipate or detect.
  • Victims did everything right. Multiple affected users reported storing seed phrases offline, avoiding internet-connected devices, never entering their phrases digitally, and conducting no suspicious transactions — yet still lost everything. This directly challenges the assumption that correct hardware wallet hygiene is sufficient protection.
  • Mark Karpelès, former CEO of Mt. Gox, is credited with uncovering the scheme. He was independently investigating cheap ledger devices from resellers and posted findings that triggered the wider investigation. Without his intervention, the report argues the slow, low-level siphoning of funds could have continued for months or years without detection.
  • The scale may be larger than initially reported. Initial reports cited $86 million; within hours the figure was revised to $90 million. Rob notes a pattern from previous incidents — such as the Coldcard hack — where initial figures grew substantially as the full scope emerged. Tai Zen also reported tampered devices across multiple Southeast Asian countries, not just one vendor.
  • "Not your keys, not your crypto" is no longer sufficient as a standalone strategy. Rob argues the maxim made sense in the era of exchange collapses (Mt. Gox, FTX, Celsius, Voyager), but the growing sophistication of hardware-level attacks means self-custody is itself now a meaningful attack surface. He calls for storage diversification as the new standard.
  • No ETF holder has been hacked in this manner. Rob poses the question directly and notes that, to his knowledge, no Bitcoin ETF holder has lost funds to this type of attack — using this as an argument for including regulated custodial products as part of a diversified storage strategy.
  • Stolen funds were being laundered across multiple blockchains, with 430 ETH deposited into Tornado Cash across four wallets. Tether froze some funds, prompting Rob to raise the tension between decentralization principles and the practical desire to recover stolen savings.

  • FULL TRANSCRIPT

    Introduction and breaking reports of the hack

    Rob Nelson: These are the days that I hate being in the crypto market, because what we're going to go through today is a PSA — a public service announcement. It is a warning, and the emails that I've gotten so far are pretty horrific.

    As a quick reminder, as we've talked about many times on the show, it's not just about diversification of your portfolio — it's also diversification of your storage. That's an important thing to remember, whether you use that in tandem with ITR Capital for custodial services (which is the same one that BlackRock and MicroStrategy use), or even a Bitcoin ETF. As we go through this, I want you to think to yourself: how many people have gotten hacked using a Bitcoin ETF?

    You're going to see stuff like this today, and it's going to keep going, it's going to keep growing — just like we saw with the Coldcard hack. And I see some things in the comment section like, "Hey guys, it's just about rolling some dice and making sure that seed phrase is very, very safe, and there should be no problems." What I'm going to show you today is that there are a lot of problems. We've had a lot of problems in this space.

    The individual victims

    This is from a post on the channel. It says: "Four months ago, this guy bought 80 Bitcoin worth $5.2 million" — which, let's be honest, that's a pretty big baller, probably got a lot of money. He bought at a low price of $65,000, did a better job than Michael Saylor, and was sitting on $1.38 million in profit. But a week ago he bought a Ledger device from reseller CryptoBillis and deposited all 80 Bitcoin into it. Now he's lost everything.

    And then we have this from Walter Ego — and if you see his profile, he's been operating a probabilistic trading machine and in Bitcoin since 2016. This person has probably been doing his due diligence, trading, and doing quite well. Unfortunately, he lost $5 million in a day. He says: "The worst part is I did everything right, quote unquote. No leverage, no memecoin, no gambling. I kept my funds in a hardware wallet" — again, we've heard this a couple of times before, cold wallet being another one — "exactly like we're all told to. Remember: not your keys, not your crypto." Right now that's the answer, but it doesn't make any sense.

    "Today, Ledger confirmed they're investigating reports of lost funds. I checked my balance three times before I believed it. I chose safety and it still wasn't enough. I've been sitting here for hours. I haven't eaten. I haven't opened a single chart. I don't even know what I'm feeling yet."

    And for you watching this video, you might think, "Well, they should have done this, they should have done that, they should have done this other thing to keep them safe." I am telling you from experience — the people I talk to most of the time do everything they're supposed to do, and then just this one thing screws everything up.

    How the attack worked

    What was that one thing? A redistributor for Ledger put out a lot of these different Ledger wallets, and they had implanted — or soldered in — a device that spied on users and took all their funds. And here's the crazy part: if there hadn't been one person from Mt. Gox who alerted people to this, it would have gone on for probably years. You would have seen little bits and pieces of people saying, "Hey, I woke up and there was some things drained from my Ledger, I don't understand why." The smart play for the attackers would have been to just keep quiet and steal from you over the next year, three years, ten years. So this is what happened.

    Breaking: Ledger users report $86 million in stolen funds. Hundreds of wallets belonging to Ledger users have been drained — more than $86 million across Bitcoin, ETH, and Tron. We've identified 10 addresses allegedly receiving stolen funds, including one Bitcoin address reportedly receiving more than 21 Bitcoin. Victims claimed their recovery phrases were stored offline. Again — they did everything they were supposed to do. Stored it offline. Didn't put it anywhere on the internet. Didn't have anything connected. Wrote it all down. Put it in a safety deposit box, potentially. Still got hacked. Didn't even do any unauthorized transactions. Cause remains unknown — that was only four or five hours ago. Well, now we know what it is, and Ledger told us.

    Ledger's response — and what's missing from it

    Although I found it very odd — let me refresh this because I don't think this is right. This is Ledger's main account. It has 676,000 followers. And the thing that's pinned at the top is something about Ledger Open 2026 coming — save the date, October 15th. So this is what they decided to pin. And I'm like, well, maybe they just didn't unpin it. Maybe they're talking about it elsewhere. No, on their main X account there's nothing about this hack.

    But to be fair, over on Ledger Support — which has far fewer followers, 73,000 — they say: "We're investigating reports of loss of funds from users only in Southeast Asia who purchased products from a reseller named CryptoBillis. As a precaution, pending the results of our investigation, we've asked CryptoBillis to pause all sales and shipments of Ledger devices. We recommend Ledger users who purchased from this seller in the last 90 days to not initiate setup if you have not done so yet." And so on and so forth.

    I just find it interesting that they didn't put it on their main account and blast it everywhere. But maybe I'm being a little too harsh on Ledger.

    CryptoBillis and the supply chain compromise

    This is what's been uncovered in the last hour or so. CryptoBillis was a reputable and authorized Ledger and Trezor OneKey dealer for over four years. And this just registered with me — CryptoBillis was a reputable and authorized dealer for four years, but they just decided to sell the company. And Zach XBT said it was sold to a Chinese buyer, most likely from northern China, in March 2026.

    So if you got a Trezor or a OneKey and bought from whatever this reseller was, you have to move everything now. Apparently there were modifications of the devices within the supply chain itself. The physical device was hacked — namely Nano X devices were found to contain an implanted module. Ledger's validity and genuineness checks cannot detect this because the device wasn't tampered with in the traditional sense — it was just spied on. The implant simply monitors what's shown on the screen. Remember how Ledger was saying how important it is that you see that screen? Well, because they have that screen, it got monitored and tracked by this implant, and everything got stolen. It takes note of the seed phrase as shown to you, then transmits it to a third party. Conveniently, funds start getting siphoned a few weeks before this magical due date and are being laundered across all blockchains.

    Mark Karpelèsès and the discovery

    The person who found it was Mark Karpelèsès. Who the hell is that? That's the CEO of Mt. Gox. He lost a lot of weight — good for him. And what he was talking about as of yesterday was that he was investigating Ledger devices from resellers. He put this out on October 8th: "Free data. Buy a cheap Ledger off a dodgy seller. Pull the SIM out of the spy implant and enjoy while you can. Law enforcement visits you thinking you were the one making these transactions."

    I need to make this clear. If Mark Karpelèsès, the former CEO of Mt. Gox, hadn't posted stuff like this and been investigating it, this could have gone on for months or years. People would have randomly lost everything on their redistributed Ledgers, and then they'd post about it and people would lambast them and say, "No, no, no — you screwed up. You didn't store your seed phrase in the right place. You must have been on open Wi-Fi and they hacked into your phone." We never would have known.

    What this means for hardware wallet users

    To make this 100% clear — this is not happening at Ledger's own distributorship. These redistributors, the ones that actually take in Ledger devices — Nano X, Nano S, whatever they are — were implanting these chips as spyware, essentially, and tracking everything on the screen: seed phrases, transactions, everything else. So if it's coming directly from Ledger, I suppose it's okay. But I moved everything off my Ledger today, because I don't know. And I'm not trying to spread FUD — fear, uncertainty, and doubt — but I'd rather spread a little bit of FUD than be the guy that says, "Hey Rob, I just lost my entire life savings."

    Funds being laundered — and the Tether freeze

    Onchain Lens states the Ledger hackers are on the move. They moved their funds to Binance. The suspected hacker linked to the reported $90 million Ledger reseller incident — now it's $90 million, and it's going to go up. Remember the Coldcard situation: first it was $10 million, then $40 million, then it blew up to I don't know how much at the end. The suspected hacker has deposited 430 ETH into Tornado Cash across four wallets, following Tether's fund freeze — because remember, Tether will freeze funds if they realize their chain is being used for illicit activities, and that goes totally against decentralization.

    So I have a question for everybody. If you are big into decentralization, you know this kind of freeze is against that — nobody should be freezing it, that sounds like the government's job. But if it's your life savings on the line, and you need it for your family, for your medication, for whatever it is — would you support freezing it? I'm just curious, because it is interesting how people will go on about decentralization and "not your keys, not your crypto" until it happens to them, and then all of a sudden they go to the other side. I'm not here to judge — I'm just asking the question.

    Onchain Lens is tagging Binance to investigate these transfers and freeze accounts linked to the stolen funds as soon as possible. I support that. I know people say you shouldn't support that because it's decentralization. I still support it.

    Fake Ledger website also active

    This is also from Cyber Skrilla — great channel to watch, really good guy doing good things, alerting people, trying to keep them safe. He says — and this was at 9:30 this morning, even before this hack had actually been revealed: "Warning. I found a fake Ledger website app at the top of Google search that is designed to steal seed phrases. Google shows it has 1 million-plus visits in the past 30 days."

    So even if you didn't get hacked through this reseller, you might have gotten hacked this way. It's like you just can't win in this game.

    CZ weighs in

    As far as Binance being tagged — CZ stepped down as CEO of Binance, I want to say in 2023, after the legal proceedings with the US government. We always look to him to get some kind of insight into what Binance is doing, even though he's not the CEO or part of day-to-day operations. He states: "Beware if you use a Ledger wallet, especially if you bought one recently. Based on information so far, it seems to be localized to a supply chain attack with one vendor." I'm going to read that again: based on the information, it seems to be localized to a supply chain attack with one vendor. "A small number of people probably bought fake or tampered Ledgers. Ledger is one of the most secure and oldest hardware wallets in the industry — stood the test of time. But these things happen, just like that data leak that happened to them too. I expect all BNB ecosystem players and all industry to help trace and recover the funds."

    Well said, most of it. But I saw this post from Tai Zen — tech investor, citizen, methods to help people, family, and strong allies, and he's in the Southeast Asia region. He states: "It's not just one vendor, bro. It's multiple vendors. I have multiple tampered Ledger hardware wallets that have been tampered with in the supply chain. So it's definitely not just in Vietnam or just one vendor. It's happening across multiple Southeast Asian countries with our students."

    Take that as you will, because I can't verify this. I'm trying to give you the most cutting-edge information I possibly can. Anything with a Ledger, you've got to be super careful right now. I would be moving it, and I'd be moving it quickly.

    "Not your keys, not your crypto" is dead

    Let me just finish up with this. "Not your keys, not your crypto" is dead. Let me say that again — I know I'm going to get a lot of hate for this. "Not your keys, not your crypto" is dead.

    As this keeps happening — because it seems like back in the day, before AI and before everything was pouncing onto crypto, it made a lot of sense, especially with Mt. Gox. Then FTX, and Celsius, and Voyager, and BlockFi, Pharaoh's Capital — everything collapsed on those exchanges. It made a lot of sense. I get it. And to say that exchanges won't collapse again is foolhardy. Of course it's going to happen again. But "not your keys, not your crypto" needs to get phased out. We need to start talking about how we need to spread out our storage. We need to diversify storage. That's the best thing I can tell you.

    And I want to ask everybody a question: how many times has an ETF holder been hacked? As far as I know, zero. I know people got made fun of for saying, "I sold my Bitcoin that I held on my Ledger and I got an ETF." They're doing just fine right now.

    I know people say, "But Rob, this doesn't affect me." It doesn't affect you yet. Every single email I get is like, "I did everything right. I listened to your show. I did this. I put the seed phrase in a secret place. I didn't transmit anything. I didn't do any transactions — and all of a sudden, poof, it's gone."

    I don't know what it is, but I know there are some things we can do to make sure this doesn't happen to us. First of all, diversify your storage. Please. I'm begging. ITR has custodial services. None of these guys, I think, are losing sleep over it, even though it could happen. You've got BlackRock, you've got Michael Saylor from Strategy — they have Coinbase Prime for custodial services. They could get hacked. It could happen. So why would they keep everything in one place? They don't. They have other custodial services and partners. So why shouldn't you? You're just as important as these guys, even if you're not a billionaire.

    Live Q&A

    I have no problem with people disagreeing. I don't ban anybody who disagrees with me. All the different moderators, everybody has their chance to talk — but you have to respond and say exactly what it is, not just dismiss it.

    See, there's a problem with me. Even when I was in healthcare for two decades, when I would see people getting scammed out of their savings by some stupid Nigerian prince, I'd have to go and talk to the patients and their families about how they lost their entire life savings. It happened more often than not. It would really, really piss me off, because they did everything they were supposed to do. These people worked real hard their entire lives. They did what was safe, what was asked of them, what they were told to do — and then because of somebody unscrupulous who just takes and takes and takes, they lost everything. And now I'm seeing it again here in this space.

    Tandem Seedless is a solution — it's a good solution. There is no seed phrase with that option, or if you want to use a seed phrase, you can. But I don't think just Tandem is the solution. I think it really comes down to diversification, because anything can happen at any moment. That's why I don't have 100% of my net worth in, say, real estate — things can happen in real estate. Take a look at 2007, 2008, and 2009. Because of that, you dabble into equities, you put a big chunk into Bitcoin assets, maybe do some things that have to do with loans, businesses, stuff like that.

    Somebody asks: if I bought it direct from Ledger, should I be good? You should be good. There is nothing out there right now that says if you got it directly from Ledger, you have a problem. I don't know why people just don't do that — get it right from Ledger. But it is what it is. It was a reseller that did a hardware hack.

    And if you want to play the long game, I'm pretty sure that's what they were going for — because imagine being able to, with the click of a mouse, just siphon off $10 million from thousands of people. Take $500 here, $25 there, $1,000 there, and everybody's like, "What the hell happened?" Some people wouldn't even realize it because the amounts might be so small. Again, if it wasn't for the former CEO of Mt. Gox, we wouldn't have known. That's the crazy part.

    Ray says: "Not surprised. My Ledger was drained in 2024. They did nothing."

    Somebody asks: "Wait, people put their Bitcoin in used devices?" But this is the thing — these are resellers. This isn't like going to eBay and getting it from some random dude who probably used it and kept the seed phrase. No, no, no. This is different. This is an authorized reseller of an unopened Ledger device.

    And I forgot to mention this. I worked in pharmaceutical research for three years. Once you get past in vitro and animal studies, you go to people. I was essentially the lead medic at a place in Phoenix, making sure nobody died — that's pretty much how it went. We would dose subjects with new medications that companies were trying to get FDA approved. We had to go through our due diligence to make sure that the ingredients, and every place they sourced the actual parts of the medication, were exactly what they said they were. If they changed things, they had to report it and it had to go to the FDA.

    With this situation, there are no such guidelines. And this is the big problem we're trying to figure out, because this is such an emerging industry. What should have been done is: as soon as CryptoBillis was sold in March — six months ago — you'd think Ledger would be like, "Okay, who'd you sell to, and who are they? Because you're now an authorized reseller. We have to make sure they're doing their due diligence and meeting our standards." That should have been done. Was it done? I can't get anything from Ledger because their main X post said nothing, and Ledger Support had the other part. So yeah, I think that should have been done. Maybe I'm wrong — let me know in the comments.

    Quantum computing, AI, and the future of security

    Ivan says quantum computing is coming sooner than you think and will be able to hack everything. Ivan, I believe, is a developer and spent a big chunk of his life in that space. Things concern me. We'll see.

    Somebody asks: "Is there any way we can have 100% confidence in anything?" No. That's not how life works. Except for two things — we all know what those are: death and taxes. Besides that, everything else is up in the air.

    Abby Wolverine asks: "Why can't AI and quantum be used to protect us?" That's just it — they can. It's as easy as having a gun. A gun can be used for defense, for hunting, and it can also be used for nefarious purposes. Same thing with a knife — you can cut up a nice steak, cut vegetables, or cut somebody. There are two sides to that story. AI is going to be used to hack us, to social engineer us, and it's going to be a problem. Quantum computing can be used to hack not just the digital asset space, but also traditional markets, banks, and every kind of information that's out there. So if we have those negatives, why couldn't the reverse be true? And it is. That's why it's important that everybody understands AI and how it works — or at least starts playing around with it and using it in their day-to-day operations.

    Closing thoughts

    For all the different things that we're going through right now — and it's not the best, it's a difficult journey to get to the promised land, to hold for so long and then have these gains — you guys are doing the right things. You guys are doing good. Just stick to the plan. Don't go crazy. Diversify your storage, and you should be fine.


    Polished transcript of Digital Asset News. All views are those of the original speakers. Watch on YouTube ↗
    Published by @nonbureaucrat
    More from Digital Asset News
    More from @nonbureaucrat
    Summary