SECURITY ALERT · UPDATE

It was not only the chain.

It was the device.

Ledger said on Saturday that one of the affected users’ devices “contained an unauthorized hardware implant.” The company posted the update from its Ledger Support account at 17:09 UTC on 10 Oct. It has not said how many devices were altered, who altered them, or whether the implant explains the thefts.

Related: Our earlier alerts have the background.

What Ledger has confirmed

The update says, in sequence:

  • Ledger can confirm that one impacted user’s device contained an unauthorized hardware implant, and is reaching out to impacted users.
  • As a precaution, CryptoBilis “confirmed it has ceased sales of all hardware wallet inventory until the investigation is concluded.” Ledger is in active communication with the reseller.
  • Ledger is working with the appropriate authorities and thanked SEAL 911 for its support.
  • Ledger says it has “no indication that Ledger’s security infrastructure, systems or services have been compromised.”
  • It is adding security mitigations and “working on further, enhanced anti-tampering solutions.”

The post does not name the device model. It does not describe what the implant does.

What Ledger advises

Ledger recommends that users who bought a device from this reseller do not set it up if they have not already. If you have set it up, it says to consider moving assets “to a new Ledger signer (with a new seed).”

A new seed matters. Restoring the old recovery phrase on new hardware would carry the same keys with it.

It also repeats that it will never ask for a 24-word recovery phrase, and that scammers target incidents like this. Its bounty address for people with information is in the post.

What is not confirmed

Mark Karpelès, who ran Mt. Gox, posted on 9 Oct that he was de-soldering a part from a Ledger device, which he called a spy implant. The Crypto Times reports he said the device was bought in Malaysia. Ledger has not said whether its confirmed implant matches his. We have not verified his account.

Nor has the link to the losses been shown. Blockchain-data firm Bitquery counts $92.9 million from 311 wallets, its own figure. Ledger has not confirmed a total.

Related: Where the money went

Nothing in Ledger’s post says CryptoBilis knew of or installed the implant. Nothing says devices bought from Ledger directly were affected.

Where in the chain from factory to desk was the device changed?

Protect yourself

  • If you bought a Ledger from CryptoBilis, follow Ledger’s current advice before using it.
  • If you have set it up, move assets to a new signer with a newly generated seed, bought directly from Ledger. Why the recovery phrase is the master key
  • Never type a recovery phrase into a website, app or support chat.
  • Be wary of anyone offering to “recover” funds.

Corrections and new evidence: [email protected]

This article is for information only and is not investment advice.