Ledger investigates CryptoBillis wallet sales after suspected supply chain thefts
Ledger has asked reseller CryptoBillis to pause sales of its wallets while it investigates reports that customers’ accounts have been drained. Images shared online appear to show a hidden circuit board that may capture information displayed on a wallet’s screen, including the seed passphrase entered during setup, then send it to an attacker.
Reports say more than $86 million in cryptocurrency has been stolen from hundreds of wallets. The suspected issue appears to be a supply chain attack affecting customers in Southeast Asia who bought through CryptoBillis; there is no indication that Ledger’s systems or wallets bought directly from the company have been compromised. Ledger has published guidance on checking whether a device has been tampered with.
- Ledger is investigating suspected tampering linked to reseller CryptoBillis.
- Reports put the stolen cryptocurrency at more than $86 million.
- No compromise of Ledger’s systems or directly purchased wallets is indicated.
New here? Start with this
Ledger makes hardware wallets: physical devices used to manage cryptocurrency keys and approve transactions. A recovery phrase, sometimes called a seed phrase, can restore access to a wallet, so anyone who obtains it may be able to take control of the funds.
CryptoBillis is a reseller that supplied Ledger wallets to customers in Southeast Asia. Reports describe a possible supply chain attack, in which devices may have been altered before reaching buyers. The case matters because it raises questions about how customers can check a device’s safety and where it came from.
Read the full article at the source →
Originally published by The Verge as “Ledger wallet tampering suspected after reports of crypto thefts”.