← Back to the feed

Ledger investigates CryptoBillis wallet sales after suspected supply chain thefts

The Verge ·

Ledger has asked reseller CryptoBillis to pause sales of its wallets while it investigates reports that customers’ accounts have been drained. Images shared online appear to show a hidden circuit board that may capture information displayed on a wallet’s screen, including the seed passphrase entered during setup, then send it to an attacker.

Reports say more than $86 million in cryptocurrency has been stolen from hundreds of wallets. The suspected issue appears to be a supply chain attack affecting customers in Southeast Asia who bought through CryptoBillis; there is no indication that Ledger’s systems or wallets bought directly from the company have been compromised. Ledger has published guidance on checking whether a device has been tampered with.

  • Ledger is investigating suspected tampering linked to reseller CryptoBillis.
  • Reports put the stolen cryptocurrency at more than $86 million.
  • No compromise of Ledger’s systems or directly purchased wallets is indicated.

New here? Start with this

Ledger makes hardware wallets: physical devices used to manage cryptocurrency keys and approve transactions. A recovery phrase, sometimes called a seed phrase, can restore access to a wallet, so anyone who obtains it may be able to take control of the funds.

CryptoBillis is a reseller that supplied Ledger wallets to customers in Southeast Asia. Reports describe a possible supply chain attack, in which devices may have been altered before reaching buyers. The case matters because it raises questions about how customers can check a device’s safety and where it came from.

Business Crypto

Read the full article at the source →

Originally published by The Verge as “Ledger wallet tampering suspected after reports of crypto thefts”.