Ledger Attacker Related to CryptoBilis Deposits 2,990 ETH into Tornado Cash
On-chain detective Specter disclosed that in an unauthorized hardware implant incident involving Ledger hardware wallets related to CryptoBilis, the attacker's address deposited 2,990.3 ETH, worth approximately $7.45 million, into Tornado Cash between October 9 and 10. Monitoring showed that the attacker previously dispersed funds to 14 addresses, then cross-chain converted the funds to the ZEC network via NEAR Intents for privacy processing. There were address associations during the transfer process: some withdrawals reused previously deposited addresses, while others were initiated from addresses associated with wallets that paid Gas fees during the theft, aiding researchers in tracking the flow. The previous incident involved Ledger devices sold by Southeast Asian distributor CryptoBilis, with an estimated loss of $86 million to $93 million in assets from hundreds of wallets, covering ETH, BTC, USDT, and more. Ledger confirmed that at least one device had unauthorized hardware implants, requested distributors to suspend sales, and advised buyers from the past 90 days not to initialize unconfigured devices, while those already configured should transfer to new devices and generate new seed phrases. Specter previously tracked multi-chain inflows, and Tether froze part of the USDT. The attacker continues to move and hide related funds. Ledger stated that its systems and firmware were unaffected and is investigating while cooperating with law enforcement. These fund flows transfer stolen assets from multi-chain victim wallets through mixing and privacy coin paths; tools like Tornado Cash and NEAR Intents temporarily carry laundering traffic, while on-chain analysis and address associations allow for some tracking, putting pressure on hardware supply chain trust. Source: Public Information
ABAB AI Insight
As a major hardware wallet manufacturer, Ledger has long emphasized secure elements and offline seed generation; this incident points to supply chain tampering through the Southeast Asian distributor CryptoBilis, with a module implanted in devices that can monitor screens and transmit seeds externally. Researchers have previously publicly dissected similar implant cases. On the capital path, the attacker dispersed stolen funds to multiple addresses, then bridged to ZEC via NEAR Intents and attempted mixing, motivated to use privacy tools to cut off tracking; resources flowed from victim-controlled seeds to mixers and privacy networks, while address reuse and Gas associations left traceable marks. This is similar to other cases of hardware supply chain implants or distributor channel tampering leading to key leaks, and is close to common paths for laundering through mixers and cross-chain tools; the self-custody hardware wallet field is currently in a phase of expanding trust from the device level to supply chain and channel verification. Essentially, this is a reconstruction of the industry chain: the security boundary of hardware wallets extends from the device itself to distributors and the physical supply chain, with the mechanism being that unauthorized implants can capture seeds during initialization, bypassing firmware checks, allowing attackers to control assets without cracking secure elements, thus shifting self-custody risks from user operation centers to supply chain trust and channel verification centers. ABAB News · Cognitive Laws
- The weaknesses of hardware wallets are outside the box.
- Mixers cannot prevent their own operational errors.
- Supply chain implants are quieter than remote hackers.