Ledger Wallet Mystery Deepens as Suspected Losses Hit $93.4M

Ledger Wallet Mystery Deepens as Suspected Losses Hit $93.4M

On Friday, the crypto community finds itself confronting yet another security controversy, this time involving hardware wallet manufacturer Ledger. Although preliminary reports placed the alleged theft at $86 million, suspected losses may have reached $93.4 million, and with Ledger yet to provide an official account, a supply chain attack has emerged as the most credible explanation thus far.

Key Takeaways

  • Ledger’s suspected losses may have hit $93.4 million across 471 addresses, according to Yfarmx.
  • Chainalysis is tracking a complex laundering operation tied to reports of nearly $100 million in losses.
  • With Ledger still investigating on Oct. 9, questions remain about a possible supply chain attack.

Onchain Investigation Points to $93.4 Million in Suspected Losses

According to an extensive deep dive and onchain analysis by Yfarmx reporter John Kamal, suspected Ledger-related losses may have reached $93.4 million across 471 distinct addresses. However, Ledger has yet to verify the findings or confirm the nearly $100 million in alleged losses.

Bitcoin.com News reported earlier that Ledger was investigating the reports of losses from “users in South East Asia who purchased products from a reseller named CryptoBillis.” Since then, the company has offered no further findings, leaving independent investigators and onchain sleuths to piece together what may have happened.

Blockchain intelligence firm Chainalysis acknowledged the situation on X, stating that it is “investigating reports of funds stolen from holders of Ledger products.” The firm further disclosed that its analysts had identified a “sophisticated cross-chain laundering operation.”

Bitquery also investigated the matter and its numbers were very close to Kamal’s analysis. The blockchain data infrastructure and intelligence company’s report puts the number at around $92.9 million across 311 unique addresses. “One thief had all the keys,” Bitquery’s analysis explains.

Hidden Hardware Discovery Raises Supply Chain Attack Suspicions

Alongside this, former Mt Gox CEO Mark Karpelès has documented Ledger devices containing hidden surveillance hardware capable of capturing recovery phrases during setup. Karpelès’ discovery suggests that wallets purchased from third-party vendors may have been compromised before users even unboxed the devices and transferred their crypto assets into them.

While hardware investigators have documented a plausible method for stealing recovery phrases from modified devices, definitive evidence remains elusive. Investigators and Ledger have yet to establish whether affected customers received compromised hardware or whether those devices transmitted their recovery phrases.

However, despite the theory gaining traction, neither Ledger nor independent investigators have established a definitive connection between these suspected implants and Friday’s reported losses.

Wallet Drains and Cross-Chain Transfers Deepen the Mystery

Kamal’s report in Yfarmx indicates that the recorded transfers appeared to have been authorized using the victims’ own signing credentials, while on Bitcoin, certain addresses were drained entirely, with no change UTXOs returned to the original wallets.

The Yfarmx report notes that at least seven blockchains were used, including Tron, Bitcoin, Ethereum, BNB Chain, Polygon, Base, and Arbitrum.

Several blockchain networks were used alongside applications like Thorchain and Tornado Cash. Presently, the consensus is that this was likely a supply chain attack that managed to get a subset of Ledger machines. It doesn’t seem to be anything like the Coldcard firmware bug, and nothing points to a remote zero-day.

As stated, Ledger has not confirmed the loss totals. Nor has the company bolstered any of the theories making their rounds on social media. The developments also come on the heels of recent data breaches involving Trezor and Safepal, which exposed the order information of tens of thousands of customers. Kamal’s analysis of the situation further notes that CryptoBillis sold “Trezor, Safepal, Tangem, [and] Onekey” hardware wallets, among others.

For now, the crypto community awaits a formal postmortem from Ledger, hoping the company can shed light on the circumstances behind this perplexing episode and provide some much-needed answers.

Read More

Zaļā Josta - Reklāma