People usually buy a hardware wallet to sleep a little easier. They move their assets off an exchange, write down the recovery phrase and put the device away, often feeling that the most dangerous part is behind them. The recent theft reports involving Ledger are a reminder that much of the work of staying safe happens outside the device.
On October 9, 2026, Ledger said it was investigating losses reported by users in Southeast Asia who had bought devices from the reseller CryptoBilis, and asked the reseller to suspend sales and shipments. The company advised customers who had bought through this channel in the previous 90 days not to begin setup if they had not already done so. Those who had set up their devices should consider moving their assets to a new device with a newly generated recovery phrase. The warning has a specific scope; it cannot be expanded into a claim that every Ledger device has a problem.[1][2]
The loss estimates are still changing. Protos reported early onchain estimates ranging from USD 72 million to more than USD 86 million; a subsequent independent analysis by Bitquery estimated roughly USD 92.9 million across 311 wallets. These are researchers' figures, potentially based on different scopes and methods. They cannot be added together, and wallet counts cannot be treated as counts of victims. Our checks as of October 10, 2026, found no official confirmation of a final loss total.[2][3]
The most important question remains unanswered: where were the keys exposed? From signatures and transfers concentrated across several blockchains, Bitquery inferred that the attacker may already have held the keys to a group of wallets. Onchain transaction records, however, cannot establish the forensic facts about a device. Tampered hardware, an altered setup process and exposed recovery phrases are among the possibilities that need investigation. The available material does not establish a widespread compromise of Ledger chips, nor does it prove that AI was used in these thefts.[3]

Illustration: Original AI concept artwork. The relationship between the device, customer data and communication channels illustrates the boundaries of risk. This is neither a photograph of an affected device nor evidence of an attack.
What the teardown clues on X tell us
The AB Kuai.Dong post brings together the losses linked to a reseller, changes in company control and a Ledger device fitted with a communications implant. These leads deserve investigation, but company control or a seller's location cannot, on their own, establish who took part in an attack. We have obtained no investigative finding that establishes the responsibility of the individuals concerned, and will not use nationality as a basis for judging security.[12]
FourVork's post explains a more specific mechanism: added hardware listens to communication between the Secure Element and the OLED display, captures the words when the recovery phrase is shown during setup, then sends them out through a mobile communications module. Mark Karpelès's subsequent replies also describe LTE, an eSIM, an antenna and a controller connected to the display bus. The danger here is someone observing the recovery phrase at the moment it must be shown to the user, rather than first breaking the encryption inside the Secure Element.[13][16]
This discussion is backed by more than imagined diagrams. Karpelès displayed an implanted sample he had obtained, saying that the packaging seal was intact and the additional circuitry was hidden where the display padding sits. Hardware researcher Joe Grand's official materials also document the reverse engineering of a real Ledger Nano X implant; his presentation materials were revised in May 2026. What can be confirmed is that such physical attacks have been studied. The origin of each sample and the affected batches still need to be checked separately.[15][18]
The existence of a sample does not, however, establish the cause of this case. When Karpelès quoted Ledger's CryptoBilis warning, he described a possible connection and asked affected users for photographs of circuit boards to help confirm it. Rewriting this stage as “all these thefts have been proved to result from implanted chips” would skip the most important step: forensic evidence connecting the affected devices, specific implants and onchain losses.[14]
Ledger Donjon's official threat model makes a point about Genuine Check that is worth remembering. It verifies the authenticity of the Secure Element. If the original chip remains intact, additional physical modifications or spying implants may escape detection, and the check does not attest to the device's distribution history. A passed check and the absence of a physical implant are therefore different conclusions.[17]
These posts move the discussion forward: the Secure Element, screen and supply chain before delivery need to be examined together. They also remind us that real photographs, an author's analysis, official warnings and final forensic findings each serve a purpose. The number of reposts does not turn one into another.
The word “breach” covers several different kinds of incident
When discussing Ledger, it is easy to blur its past incidents together. The 2020 breach of its e-commerce and marketing database involved around 1 million email addresses. A database later made public showed that approximately 272,000 records also contained names, postal addresses and phone numbers. Ledger's initial disclosure put the number of detailed records lower, and the company later corrected it. This incident exposed customers' identity data; it does not prove that private keys were read from their wallets.[4][5]
The Connect Kit incident on December 14, 2023, followed a different path. Ledger's report said a former employee's npm publishing access had not been revoked in time. The attacker gained access through phishing and published a malicious package. Decentralized applications using the component loaded the compromised code, steering users toward dangerous transactions. The hardware could still sign as designed, yet money could leave a wallet because its owner approved the wrong transaction.[6]
In January 2026, an incident involving Global-e's order system affected the names, contact details and order information of some Ledger buyers. In responses to the media, Ledger and Global-e said the incident did not involve payment information, account credentials or wallet recovery phrases. Such data may not let someone move assets directly, but it can help scammers select targets and invent stories that fit their actual experiences.[7]
The current CryptoBilis investigation concerns asset losses associated with a purchasing channel; the cause remains unconfirmed. Calling customer list leaks, compromised software supply chains and exposed keys all “Ledger hacks” makes for fast circulation, but leaves protection without a clear direction. An exposed address calls for precautions against impersonation and harassment in the physical world. Malicious signing calls for scrutiny of what is being authorized. An exposed recovery phrase requires a new set of keys. Changing an email address will not solve the latter two problems.
What a hardware wallet actually does for you
A hardware wallet does not hold coins inside the machine. Assets are recorded on the blockchain; the device holds the keys that authorize spending them. A recovery phrase can recreate those keys. Once someone else has it, they may be able to sign on another device. The original hardware wallet cannot stop them, even if it is still locked in a drawer.
An ordinary transfer broadly works like this: an application on a computer or phone constructs the transaction, the hardware device displays information the user can check, and after approval the transaction is signed inside the device. The application then broadcasts the signed transaction to the network. Under normal design and use conditions, the outside application receives the signature, not the private key used to make it. The device's screen gives the user a chance to check independently of the computer's interface.[20]
A recovery phrase usually consists of a series of words; Ledger's common setup process uses 24. It restores the whole wallet and gives far more control than an account login password. A PIN mainly restricts direct use of that particular device. Losing the device, exposing the recovery phrase and approving the wrong action are different problems and cannot all be addressed by the same measure.[20]
“Cold” does not mean that a device never interacts with the outside world. Hardware wallets exchange transaction data through USB, Bluetooth, QR codes or other methods, depending on the product's design. Their value lies in minimizing the opportunities for keys to come into contact with computers and phones. The processes around key generation, backup, display and signing still need to be trusted.
A hardware wallet also usually differs from an exchange's custodial account. With a custodial account, the platform holds and uses the relevant keys; self-custody returns that control and the responsibility for recovery to the user. Greater freedom means no customer service representative can undo a confirmed onchain transfer for you. If you lose every usable backup or willingly hand over the recovery phrase, changing brands will not automatically restore that control.
This is also where “switch to a new device” is most easily misunderstood. Importing an old recovery phrase into a new device usually changes only the container for the keys. If the old phrase has been exposed, the risk moves with it. What needs to be established afresh is a new recovery phrase generated by a trusted device, together with the process of transferring assets to new addresses.

Diagram: The signing process. The application constructs a transaction, the user checks and authorizes it on the device, the device returns a signature, and the application broadcasts it to the blockchain. Private keys, PINs, recovery phrases and authenticity checks serve different purposes. Drawn from Ledger Academy and Donjon materials, this is neither a teardown diagram nor a reconstruction of the attack path in this case.
AI makes a scam look more like ordinary customer service
There is no evidence that AI caused these thefts. In the wider security landscape, however, its effect is clear: attackers can more easily turn scattered clues into a convincing conversation, and can afford more repeated attempts.
In the past, a badly spelled email or a clumsy translation might have made someone stop in time. Those clues are becoming less reliable. In a December 2024 alert, the FBI listed uses of generative AI that included polishing scam messages, translating, creating false identities, cloning voices and producing deceptive videos. In May 2025, it disclosed an actual campaign impersonating senior U.S. officials, using text messages and AI-generated voices to establish trust.[8][9]
Customer data becomes especially useful in this setting. Knowing which device you bought, where it was delivered and which phone number you left can make a call from a stranger sound like a follow-up from customer service. With public information and automation tools added, an attacker can try tailoring scripts to different languages, time zones and occupations. This describes a possible method of attack, not a process confirmed to have occurred in this case.
The most dangerous scripts often borrow real security news. The investigation is real, the suspension of shipments is real, and the advice to migrate is real. A scammer only needs to replace “verify this through official channels” at the final step with their own download link, or ask you to “verify your recovery phrase.” The more afraid users are of missing the window to act, the more likely they are to skip checks they would otherwise make.
Security researcher Taylor Monahan specifically warned on X that people moving funds in a hurry could become targets for fake search ads, fake applications and phishing links. This is a warning about the response process, not advice for users genuinely covered by the official warning to disregard it. Acting and checking the entry point for that action both matter, so that escaping one incident does not lead into another.[19]
The hardware itself may be genuine while the instructions around it are false. A card inside the package, a download page in search results, a customer service voice or an “all security checks passed” message on a website can all shape what the user does next. If the recovery phrase was generated or recorded through an untrusted process, carefully protecting the device afterward is already too late.
The UK's NCSC assessment of AI cyber threats places these changes in reconnaissance, social engineering, vulnerability exploitation and analysis of stolen data. AI improves efficiency and gives more people capabilities that previously required experience. That does not mean AI can now break cryptography at will. Explaining every wallet theft as “AI calculated the private key” obscures the more common entry points that need examination.[10]
The change in the AI era therefore goes beyond faster attacks. Deciding whether a message can be trusted requires checking more parts of the process: the brand may be real, but the sender may not be; the software name may be real, but the downloaded file may not be; the security advice may be real, but the route to carrying it out may not be. Flaws that spelling and tone once revealed increasingly require independent verification.
AI also makes protection more complicated
AI can help defenders. It can organize large volumes of logs into a readable timeline, group similar phishing domains, help examine unusual authorizations and explain technical risks in language users understand. These tasks are valuable for teams with limited resources. But flagging a possible anomaly and confirming an attack are still different things. Any response requires the evidence to be checked.[10]
The difficulty is that once a protection tool connects to email, a browser, a code repository or a financial system, it becomes an entry point that also needs protection. A malicious web page can hide instructions in its content, encouraging an agent to treat outside text as a command. Compromised software dependencies can also enter a defensive workflow. Giving AI more information to read and more actions to perform must come with answers about what it can access, what it can change and where a person needs to review its work.
For a wallet, letting AI explain a transaction and giving AI the keys are entirely different permissions. The former can support judgment within a limited set of information; the latter creates another place where secrets might leak. Recovery phrases, private keys and complete backups should not be uploaded to a chat window, remote support service or online scanner for a “security check.” Handing wallet information to a model that claims to understand security does not automatically add protection.
Likewise, an AI answer that says “safe to sign” cannot replace checking the device. A model may miss conditions, and transaction simulation has its own limits. The receiving address, network, amount, party being authorized and readable contract permissions need to be confirmed before execution. If their essential meaning remains unclear, pausing the transaction is more reliable than proceeding on the strength of a fluent explanation.
Make the checks you can verify independently count
Buyers within the scope of the CryptoBilis warning should first use their own saved official website entry point to check the latest notice, preserve order, device and transaction records, and then follow official guidance. Do not click an unexpected private message, search advertisement or fund recovery service in a rush to “change wallets.” If key exposure is suspected, the focus should be trusted new keys and asset migration. The panic of moving can itself create an opening for another scam.
Other users have more to gain from reviewing the entire purchase and setup process. Ledger's purchasing guide warns against using a device supplied with a prefilled recovery phrase or preset PIN. Authenticity checks should be run in a genuine application obtained from official sources; a fake application can display a false pass result. These checks reduce known risks. They cannot be promoted as a guarantee of safety under every circumstance.[11]
A caller who knows order details has shown only that those details may have been obtained, not that the caller's identity is genuine. A familiar voice is not enough either. When a request involves moving assets, installing software or changing security settings, ending the call and initiating contact through an independently saved official channel is more useful than continuing to question the caller in the same conversation.
Long-term storage and everyday interaction should also be separated as needed. An account that frequently connects to new applications can hold only the assets currently needed, while an account holding the main savings should minimize unrelated authorizations. Individuals and institutions with larger holdings can assess multisignature arrangements, separate custody and divided review responsibilities. These arrangements add recovery and operating burdens, so emergency procedures need to be rehearsed first.

Illustration: Original AI concept artwork. Automated analysis can help organize information. Clear boundaries of responsibility are still needed for critical identity checks and transaction authorization.
Businesses cannot explain risk with a single sentence saying that a third party had a problem. Users buy a complete service. Who receives an order, how long data is retained, when a departing employee's publishing access is revoked and how buyers are notified after a reseller shows signs of trouble all affect security in the end. Passing chip tests does not replace management of these parts of the service.
Much effective protection is familiar: retain less unnecessary data, revoke access promptly, obtain software through trusted entry points, require separate confirmation for high-risk actions and keep records that can be reviewed later. AI gives these often overlooked details greater weight, and makes it easier for a single lapse to travel through the whole service chain.
The Ledger episode still needs device forensics, supply chain investigation and continued onchain verification. We can say that the security boundary now extends across purchasing, setup and signing; we cannot supply the investigation's conclusion about the cause. Protecting assets takes more effort today because attackers can more easily connect technical weaknesses, real personal data and human judgment. Protection must be just as continuous, with checks that can be independently verified.