- Ledger reported finding an unauthorized hardware implant in one affected user’s device.
- CryptoBilis temporarily suspended all hardware-wallet sales while Ledger and law enforcement investigate.
- A cybersecurity researcher separately warned that fake Ledger pages appearing in Google Search were designed to steal recovery phrases.
Ledger has reported finding an unauthorized hardware implant in one affected user’s device during an investigation into theft from users. The finding prompted CryptoBilis to suspend all hardware-wallet sales temporarily, while Ledger advised customers who bought devices from the retailer not to activate unconfigured units.
Ledger said it was contacting users as part of the investigation and working with law enforcement and CryptoBilis to hold those responsible accountable. The hardware-wallet manufacturer also thanked the SEAL 911 team for its assistance.
Ledger advises users to check their devices
Ledger said there were no current signs that its security systems, infrastructure or services had been compromised. CryptoBilis stopped selling all hardware wallets as a precaution and plans to maintain the suspension until the investigation is complete, according to the company. Ledger remains in contact with the retailer over the next steps.
The manufacturer advised customers who purchased a Ledger device from CryptoBilis but had not begun setting it up to refrain from doing so. Customers who already activated their wallets should consider moving their assets to a new device using a new seed phrase, it said.
Ledger also warned users about scams that can accompany such incidents and reiterated that it never asks customers for their 24-word recovery phrase. Users can submit information about the investigation through the company’s bug bounty program.
Researcher identifies fake Ledger pages in Google Search
Cybersecurity researcher Cyber Scrilla reported on Oct. 9, 2026 that a fraudulent Ledger website and app appeared among the top Google Search results. The pages were designed to steal seed phrases, the researcher said.
According to Cyber Scrilla, Google showed more than 1 million visits to the pages over the previous 30 days. The researcher said there was no confirmed link between the fraudulent resource and the alleged theft of $86 million.
Zscaler ThreatLabz researchers had previously described a phishing campaign that used fraudulent Google ads to target Ledger owners. Those ads redirected users through Google Cloud Storage and Vercel to a fake Google Sites page that imitated Ledger’s interface.
The fraudulent device-verification process asked users to enter their secret recovery phrase, which was then sent to a server controlled by an attacker, according to the researchers. They observed that the Vercel redirect domains changed about every 15 to 20 minutes, making the campaign harder to detect.
Earlier transaction-signing vulnerability
The incidents followed a vulnerability reported by the OneKey Anzen team in late August. OneKey founder and CEO Yishi Wang said researchers had reproduced an attack that allowed a transaction to be swapped during signing in version 1.22.1 of the Ethereum app for Ledger.
Under that scenario, a user could see one transaction while actually signing another, Wang said.
Source: Incrypted
