Ledger, a prominent maker of hardware wallets, has confirmed that one of its devices sold through Southeast Asian reseller CryptoBilis contained an unauthorized hardware implant. The discovery comes amid ongoing investigations into reported cryptocurrency losses linked to the devices, with estimates suggesting the total losses could exceed $86 million across Bitcoin, Ethereum, and Tron.
The company announced on Sunday via a post on X that it was actively reaching out to affected users as part of its investigation. Ledger urged anyone with relevant information to contact its bounty program at bounty@ledger.fr. As a precautionary measure, CryptoBilis has temporarily halted the sale of all hardware wallet inventory until the investigation concludes.
Ledger advised users who purchased devices from CryptoBilis to avoid setting up the device if they have not already done so. Those who have set up their Ledger device are recommended to transfer their assets to a new Ledger signer using a new seed phrase. The incident appears to be isolated to CryptoBilis and its market, with Ledger asserting that its own infrastructure, systems, and services were not compromised.
CryptoBilis was previously listed as an authorized Ledger reseller in Indonesia, Malaysia, and the Philippines. Ledger has not yet confirmed the exact number of affected customers or the full extent of the reported losses. For further assistance, users are encouraged to contact Ledger customer support through official channels.