On Saturday, crypto sold safety three times before dinner. Only one of the pitches came with evidence.
At 05:42 UTC on Saturday, Justin Sun wrote that Tron’s post-quantum cryptography was “now live on testnet” and that the network was “ready to bring quantum resistance to mainnet at any time.”¹ At 12:14 UTC, StarkWare, the company behind Starknet, said that becoming an independent layer 1 was its “clearest path forward.”² At 17:09 UTC, Ledger Support wrote that “one of the impacted users’ devices contained an unauthorized hardware implant.”³
That is eleven and a half hours, three companies, and one theme. I’ll admit the theme is tidy. Real weeks are rarely this well edited.
Three pitches, three kinds of evidence
The first two are promises about a future threat. The third is a statement about a present one.
Tron’s promise has a reasonable foundation: the code is public, and a testnet has been running it since the summer. When our Bitcoin and macro writer checked the public parameter lists on Saturday, the Falcon-512 switch was on for the testnet, and neither post-quantum switch appeared on the mainnet list.⁴ “At any time” is a fair description of the code. It is not yet a description of the network.
StarkWare’s promise is a step further from delivery. On 8 Oct, Starknet said it was “actively considering” becoming an L1. On Saturday, the company said it was the clearest path forward. Nobody has published a proposal, a date or a vote.⁵ The token did not wait: STRK has risen about 137% from the 8 Oct open on Kraken, to $0.116 as of Sunday morning, a market value near $862 million.⁶ I would call that the market paying for a sentence, though I accept the sentence is a good one.
Then Ledger. Its statement is the only one of the three that is, in the plain sense of the word, a finding. It also arrived with the least decoration: no roadmap, no target year, a bounty address and a list of precautions.
The bunker, as a brand
The word of the week was Justin Drake’s. On 7 Oct, hours after Europol published two reports urging early preparation for quantum computers, the Ethereum Foundation researcher called for calm planning for a “bunker mode”, including a controlled migration of assets to addresses whose public keys remain hidden.⁷
Europol’s own line was calmer than the genre it started. “Cryptocurrencies will not collapse due to quantum computing,” it said, in the words Decrypt quoted. Its worry is narrower and more boring: wallets whose public keys are already visible on-chain, which Glassnode put at about 30% of bitcoin’s supply.⁸ Decrypt notes that no quantum computer can break these systems today, and CoinDesk reported that Coinbase cryptographer Yehuda Lindell called the bunker warning “FUD.”⁹
I don’t need to settle that argument, and I can’t. The risk is real in the way long-dated risks are real, and it is also, by a happy coincidence, the sort of risk a project can announce solutions to without anyone being able to check them. A roadmap is a bunker drawn in pencil. It reassures, it costs little, and it does not have to survive a visitor.
Fear is a product category. The quantum version is unusually clean, because it has no victims yet and therefore no refund policy.
The bunker that arrived by courier
Ledger’s problem is the opposite: a present-tense incident, and a supply chain.
Here is what the company has said. One affected user’s device contained an unauthorised hardware implant. The reseller, CryptoBilis, “confirmed it has ceased sales of all hardware wallet inventory until the investigation is concluded.” Ledger has “no indication that Ledger’s security infrastructure, systems or services have been compromised.” It advises people who bought from this reseller not to set up an unused device and, if they have set one up, to “consider moving assets to a new Ledger signer (with a new seed).”¹⁰
The detail in that last sentence is the one worth underlining. A new seed means a new set of keys. Restoring the old recovery phrase on a fresh device would carry the problem along with it.
Here is what has not been said. The company has not named the model. It has not said how many devices were changed, who changed them, or when. It has not tied the implant to any particular loss. Blockchain-data firm Bitquery counts $92.9 million taken from 311 wallets on five chains, a figure that is its own.¹¹ Nothing in Ledger’s post says CryptoBilis knew of the implant, and nothing in it says devices bought directly from Ledger were involved. The news update has the details; I won’t repeat them.
What I will say is that this is the awkward part of the week’s theme. People buy a hardware wallet to buy a bunker. The bunker arrives in a box, by a route the buyer cannot inspect, and the buyer’s only defence is that the box looked fine. In fairness, it is easy to be wise about someone else’s supply chain.
The quiet counter-example
One more entry, because the week had a good one. On Friday, RippleX disclosed that the XRP Ledger had carried a flaw since 2015 that could have let an attacker create XRP. A researcher reported it on 22 Sep through the bug bounty, a fix shipped on 25 Sep, and RippleX says it found no evidence of exploitation.¹² No countdown clock, no token move, no tagline. It is the kind of safety that does not market itself, which may be why it is easy to overlook in a week like this.
Incident ledger
The week to 10 Oct, verified items only:
- Frogman wallets (Singapore): more than $4 million drained from two wallets overnight on 6–7 Oct, by his own estimate, which on-chain researchers EmberCN and Lookonchain put in the same range. Cause unconfirmed. Our alert.
- 79thVault (BNB Chain): about $12.5 million drained from the 79AU/USDT pool on 7 Oct, via a function open only to an operator-role address, according to monitors including Defimon Alerts and CertiK. The project has issued no incident report. Our alert.
- Ledger reseller drain (South East Asia): $92.9 million from 311 wallets on 9 Oct, per Bitquery. Tether froze about $10 million of USDT, which is frozen and not recovered. Our earlier alerts.
- XRP Ledger: no losses; the overflow bug was patched on 25 Sep and disclosed on 9 Oct. The details.
Losses this week, as tracked here: about $109.4 million across three incidents, which is the sum of one victim’s own estimate, one monitor’s estimate and one data firm’s estimate. None is a figure confirmed by the affected party, and the real total is probably different. Our tally counts only what we could confirm on-chain or from a named security firm.
Elsewhere
- Europol’s release is the calm document in this week’s debate and is worth reading in full.
- RippleX’s disclosure report is a model of how to explain a flaw, with the dull parts left in.
- Our own notes cover the quantum side: Zcash’s January target, Tron’s testnet check and what a quantum attack on bitcoin means.
What I would take from it
Three things were sold on Saturday: a date, a direction and a precaution. Only the precaution has been tested, and not in the way anyone wanted.
The money that actually left this week did not leave through mathematics. It left through a privileged key, a stolen night and a box that arrived looking fine. If the bunker has a weak door, it is usually a human-sized one. That is not an argument against the roadmaps. It is a suggestion that when a project announces how safe the future will be, the polite question is how safe the delivery is.
See you next Sunday. — L.C.
My footnotes:
- Justin Sun’s post is on X. The testnet part is not new; the code has been public since late June, as our Tron note records.
- StarkWare’s statement is on X; our news report has the numbers. I have kept the quote short.
- Ledger Support’s full “Situation Update” is on X, posted 10 Oct at 17:09 UTC. All quotations from it here are exact.
- Read of the public parameter lists on Saturday at about 13:45 UTC, per our Tron report.
- The Starknet community forum showed no L1 proposal when we looked at about 04:00 UTC on Sunday.
- Kraken’s STRK/USD open on 8 Oct, 00:00 UTC, was $0.0490; CoinGecko’s price at 03:49 UTC on 11 Oct was $0.1160. The largest hourly move came about two hours after the post, and we found no announcement timed to it.
- Justin Drake’s post of 7 Oct; Europol’s reports are linked in References.
- Glassnode’s estimate is from May and is cited by Europol’s report, as covered in our 7 Oct note.
- CoinDesk’s report is cited in our 9 Oct Starknet note; I have not re-read it for this column.
- Quoted from the Ledger Support post in note 3.
- Bitquery’s count, to a 16:45 UTC data cut-off on 9 Oct. It is a vendor tally.
- RippleX’s disclosure report; the researchers it credits are named there.
References
- Justin Sun on X, 10 Oct 2026, 05:42 UTC: x.com/justinsuntron/status/2108795299783168505
- StarkWare on X, 10 Oct 2026, 12:14 UTC: x.com/StarkWareLtd/status/2108893838186344666
- Ledger Support on X, 10 Oct 2026, 17:09 UTC: x.com/Ledger_Support/status/2108968264055345381
- Justin Drake on X, 7 Oct 2026: x.com/drakefjustin/status/2107837081313505768
- Europol, 7 Oct 2026; Decrypt, Europol warns crypto wallets are primary risk for quantum attacks
- Bitquery, The Ledger CryptoBilis hack took $92.9M from 311 wallets
- RippleX, XRP Ledger vulnerability disclosure report, 9 Oct 2026
- Kraken public API, STRK/USD candles
This article is for information only and is not investment advice.
