SECURITY ALERT · UPDATE
The first count was $86 million.
The second is higher.
Blockchain-data firm Bitquery now counts $92.9 million taken from 311 wallets on five chains: TRON, Bitcoin, Ethereum, BNB Chain and Polygon. That is its own tally, with a data cut-off of 16:45 UTC on Friday. Ledger has not confirmed any total, and it has not said what caused the losses.
Related: Our first alert has the background.
What Ledger has said
Ledger’s statements have stayed narrow.
At 13:32 UTC on Friday its support account said it was investigating lost funds among users in South East Asia who bought from a reseller, and had asked the reseller to pause sales.
At 16:54 UTC the main Ledger account wrote: “Based on the information available so far, we believe the funds drained are limited to devices sold through a reseller named CryptoBilis in South East Asia.”
It also told Cointelegraph that “Ledger’s infrastructure, systems and services were not compromised”, and that it had received no reports involving devices bought directly from the company.
Ledger has not said how the keys were exposed.
Four counts, four cut-offs
These are different tallies, not a revision of one number.
- tanuki42, 12:00 UTC: more than $72 million across eight addresses.
- Specter, 12:24 UTC: more than $86 million.
- MistTrack, 15:15 UTC: losses “approaching $90 million”.
- Bitquery, to 16:45 UTC: $92.9 million from 311 wallets, which it says includes BNB Chain and Polygon drains and five TRON addresses missing from public lists.
By Bitquery’s chain split, TRON accounts for $70.5 million, Bitcoin $16.8 million (about 203.8 BTC), Ethereum $3.7 million, BNB Chain $1.45 million and Polygon $0.58 million.
What Bitquery says the chain shows
Bitquery reports that 25 TRON wallets signed the same approval within three seconds, starting at 05:07:48 UTC on Friday. It says a further 111 Bitcoin wallets were swept in one block at 05:54 UTC.
It also reports 21 small test transfers on TRON and 20 on Ethereum between 26 Sep and 7 Oct, run by the same two control addresses.
From that, Bitquery concludes that one actor held the keys to every drained wallet. That is its inference. It says the chain cannot show where the keys leaked from, and cannot test claims that devices were tampered with.
Some public figures have suggested tampering. Ledger has not confirmed a cause.
Where the money went
Tether acted within ten minutes of the first public post.
We read the USDT contract’s blacklist events on TronGrid at 03:56 UTC on Saturday. There were 37 AddedBlackList events between 12:09:39 and 14:10:51 UTC on Friday, 35 of them in the first minute. Four addresses were removed at 15:30:33 to 15:30:39 UTC.
Related: Those four were the THORChain vaults we reported.
That leaves 33 blacklisted addresses. Twenty hold about 500,000 USDT each, 10,000,001 USDT in total, which matches Bitquery’s $10.0 million.
Tether-blacklisted, ~500,000 USDT each (examples):
THk28GmnhDYJoEiQYDJ8172hu6a7Fp1Wnh (listed 12:09:45 UTC)
TKzgP8f4eoxKex2P7scsZkScWte8LYNcby (listed 14:10:51 UTC)
A blacklist stops USDT moving. It does not return anything to victims. Tether can later reissue frozen coins, Bitquery notes.
The rest took other routes. Bitquery says about $14.9 million of the stolen USDT was swapped into USDD, a stablecoin outside Tether’s blacklist, and that 15.1 million USDD sat in seven TRON wallets at 16:45 UTC. The Defiant, citing Tron records, reported one 2 million USDT conversion through USDD’s stability module, so the size depends on which transfers are counted.
Another $20.0 million of USDT crossed to Ethereum in 40 equal pieces through the USDT0 bridge, Bitquery says, and was swapped for 7,994 ETH.
Bitquery’s snapshot of where the $92.9 million sat at 16:45 UTC:
| Where | Amount |
|---|---|
| Bitcoin, unmoved | $16.8M |
| ETH in attacker wallets (about 14,810 ETH) | $36.9M |
| USDD on TRON | $15.1M |
| USDT frozen by Tether | $10.0M |
| Sent to Tornado Cash (1,254 ETH, three batches, 15:17–15:56 UTC) | $3.1M |
| Spent or not yet traced | $11.1M |
Source: Bitquery, at 16:45 UTC on 9 Oct, at its 9 Oct prices; the parts are an estimate of the whole. Frozen is not recovered.
Nothing has been reported as recovered.
If Tether can only freeze what it can see, who watches the other stablecoins?
Who may be affected
Ledger’s advice, as reported by CoinDesk, covers buyers from the reseller in the past 90 days. Bitquery says about six in ten victim wallets received their first deposit inside that window and more than eight in ten from June onwards. A first deposit is not proof of when a device was bought.
Protect yourself
- If you bought a Ledger from CryptoBilis at any time, check Ledger’s official channels before you rely on that device.
- If you have not set it up, do not set it up.
- If you have, Ledger says to move assets to a new signer with a newly generated recovery phrase. Buy that device directly from Ledger.
- Never type a recovery phrase into a website, app or support chat. Why that phrase is the master key
- Be wary of anyone offering to “recover” funds. Ledger has warned that impersonators are active.
If the chain can show the how but not the why, who is left to answer it?
Corrections and new evidence: [email protected]
Update, 11 Oct: Ledger has since confirmed an unauthorized hardware implant in one affected user’s device; see our update.
This article is for information only and is not investment advice.
