Analysis · Security
Can Ledger's Genuine Check catch a hardware implant?
Ledger's own buying guide says the check cannot detect implants if the original Secure Element is intact, and its posts name no other way to test a device.
By Phil4 min read

Ledger's Oct. 10, 2026, post on X confirmed an unauthorized implant in one affected user's device and told CryptoBilis buyers to skip setup or consider a new seed. In Ledger's buying guide, a tampered device is genuine hardware modified after leaving the factory, generally so an attacker can capture remotely what the screen displays. The seed is the 24-word recovery phrase that controls your coins. Ledger's Oct. 9 post had covered purchases in the previous 90 days; the Oct. 10 update addresses everyone who bought from this reseller.
For a CryptoBilis buyer, the step is clear. Ledger's Oct. 10 update defines the risk group only by where you bought, with no device model and no purchase window. The same post confirms the implant without naming the device model or where it was bought.
The guide also sets a limit on Ledger's own check. The Genuine Check, the authenticity test in Ledger's app, cannot detect implants if the original Secure Element is intact. That chip holds your keys. A Ledger statement naming affected models, sale dates or a check procedure would settle who is at risk.
- Skip setup on any Ledger device you bought from CryptoBilis.
- Consider moving your assets to a new Ledger signer with a new seed if your device is already set up. Our guides cover creating and storing a new recovery phrase, setting up a replacement hardware wallet and storing XRP.
- Use only official Ledger channels for updates. Ledger warned that scammers often try to exploit incidents like this one, and it will never ask for your 24-word recovery phrase.
CryptoBilis has stopped selling while Ledger investigates
In an Oct. 9 post, Ledger announced an investigation into reports of fund losses from users in Southeast Asia who bought products from CryptoBilis. As a precaution, it asked the reseller to pause all sales and shipments of Ledger devices pending the investigation.
Ledger's Oct. 10 update carries CryptoBilis's confirmation that it stopped selling all of its hardware wallet inventory until the investigation is concluded.
One study describes an implant that reads seeds
A Tibane Labs study, as reported by ForkLog, examined two Ledger Nano X units with suspected hardware implants. The implant it describes reads the 24 recovery words from display signals. It sends them out through an embedded cellular module, without hacking the Secure Element.
One unit came from Yahoo! Auctions Japan, the other from a third-party Amazon Japan seller that shipped from Malaysia. The study does not prove such implants were in CryptoBilis devices. No direct link to Ledger's investigation has been established.
The two loss estimates share eight addresses
In an Oct. 9 post, analyst Specter estimated total losses of more than $86 million. The basis is inflows to traced theft addresses from hundreds of victim wallets, on chains including Ethereum, Tron and Bitcoin. Ledger has given no count of affected customers and no loss value.

Analyst tanuki42, in an Oct. 9 post embedded by ForkLog, put the total loss to eight listed addresses at more than $72 million and still rising. Neither analyst discloses a method. All eight addresses are among the 10 Specter listed. The two minimums therefore overlap, and adding them would count the same eight addresses twice.
One address on both lists shows the scale on a single wallet. As of Oct. 11, 2026, 10:10 UTC, mempool.space showed that bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl had received 79 outputs totaling 92.50622679 BTC. All 79 were still unspent.
A device from another seller would test Ledger
If you bought your Ledger elsewhere, the question is whether Ledger itself was breached. Ledger's answer in its Oct. 10 post is "no indication" that its security infrastructure, systems or services were compromised, and its investigation is ongoing. Cointelegraph and ForkLog quote the company with a firmer line, that its systems "were not compromised."
Both outlets reported that CryptoBilis was listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines. Ledger's own posts call it "a reseller."
Ledger also told Cointelegraph that the incident appeared to be isolated to the single reseller and its market. ForkLog reports that the cause has not been determined and that no problems have been reported with devices bought directly from Ledger. A report of a tampered device bought from another seller would test Ledger's view.
Ledger is contacting affected users and has asked anyone with information to reach its bounty program. Its advice to CryptoBilis buyers applies whether or not Ledger has contacted you.
Ledger is also working on further anti-tampering measures. It has given no details or timeline.
Sources
- Ledger Support on X: post confirming an unauthorized hardware implant (Oct. 10, 2026) · Ledger
- Ledger Support on X: initial advisory on fund losses among CryptoBilis buyers (Oct. 9, 2026) · Ledger
- Ledger Academy: Best Practices To Securely Buy Your Ledger Signer · Ledger
- Cointelegraph: Ledger confirms unauthorized hardware implant, losses may exceed $86M · Cointelegraph
- ForkLog: Ledger Investigates Potential Compromise of Wallets Sold by Reseller CryptoBilis · ForkLog
- Specter (@SpecterAnalyst) on X: trace of theft addresses (Oct. 9, 2026) · X (@SpecterAnalyst)
- mempool.space: address data for bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl · mempool.space
- BleepingComputer: Criminals are mailing altered Ledger devices to steal cryptocurrency (June 16, 2021) · BleepingComputer
- Grand Idea Studio: Reverse Engineering a Ledger Nano X Hardware Implant · Grand Idea Studio
- X post by @sirshibaninja on CryptoBilis ownership (Oct. 9, 2026) · X (@sirshibaninja)



