律动BlockBeats
律动BlockBeats|Oct 09, 2026 15:55
Ledger historical security incident inventory: Fake applications once caused $9.5 million to be stolen, and today's theft event is the largest scale BlockBeats reported that on October 9th, hardware wallet manufacturer Ledger was once again embroiled in a security storm today, with third-party security agencies estimating a loss of approximately $90 million. At present, the official is investigating the financial losses related to the sale of equipment by authorized distributor CryptoBilis in Southeast Asia, and has requested it to suspend sales and shipments. It is recommended that users who purchase equipment from this channel operate cautiously or transfer assets within the next 90 days. The cause of the incident has not been finally confirmed, and there is a suspected risk of supply chain/equipment tampering. Looking back at the major incidents in Ledger's history related to attacks and financial losses: 2018: Early hardware and supply chain research vulnerabilities erupted in a concentrated manner. Security researchers demonstrate the possibility of Nano S being tampered with before leaving the factory, as well as issues such as MCU bootloader bypass, isolation vulnerabilities, and Bitcoin change address injection. Ledger has successively released security notices and fixes, mostly for research level or physical contact scenarios. 2020: Large scale customer data breach. The attacker obtained e-commerce and marketing databases through third-party API keys and Shopify related vulnerabilities, revealing over 1 million email addresses and detailed records of approximately 272000 to 292000 customers (names, addresses, phone numbers, etc.). The hardware and private keys were not affected, but it directly gave rise to long-term phishing, social work, and forging official letter fraud. December 2023: Ledger Connect Kit supply chain attack. Former employee was phishing, leading to the prosecution of NPMJS account. The attacker released a malicious version of Connect Kit, injected DApps that depend on the library, and induced users to sign coin stealing transactions. Within the active window of about 2 hours, the loss is in the range of approximately 480000-600000 US dollars. The hardware and Ledger Live itself have not been directly compromised. January 2026: Third party Global-e order data breach. Unauthorized access to the payment logistics partner system has exposed some order related information (name, address, contact information, etc.) on Ledger.com. Ledger's own system and private key have not been affected, but the risk of phishing has once again increased. April 2026: App Store counterfeit Ledger Live app fraud. The counterfeit application was launched for about a week, deceiving users into entering mnemonic words. Over 50 victims lost about 9.5 million US dollars, involving multiple links. Apple subsequently removed it, and Ledger emphasized that he would never ask for 24 word mnemonic words. August 2026: Ethereum application signature related vulnerabilities (LSB-023, etc.). This includes issues such as command interleaving causing display and signature parameters to be out of sync, and clear marking bypassing. Malicious hosts need to cooperate. Ledger stated that there is no actual evidence of user exploitation and has fixed it in the new version. On October 9, 2026 (latest): A large-scale wallet clearing event related to CryptoBilis distributors. The estimated loss is close to $90 million, and Ledger is investigating suspected supply chain or device tampering attacks targeting a single channel. The official has taken measures such as suspending sales and recommending users to migrate assets.
+6
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads