- Blockchain intelligence firm Bitquery estimates that roughly $92.9 million was drained across 311 unique wallet addresses, aligning closely with findings from on-chain analyst Kamal.
- Former Mt Gox CEO Mark Karpelès highlighted that altered Ledger devices bought via third-party sellers could contain hidden surveillance hardware capable of capturing seed phrases during initialization.
- While an offline hardware supply chain attack remains the prevailing theory, neither Ledger nor independent researchers have officially verified a direct link between modified devices and the recent multimillion-dollar exploit.
Multimillion-Dollar Exploit Probed Across Hundreds of Addresses
Blockchain data infrastructure and intelligence firm Bitquery has revealed an extensive scope of losses following an on-chain draining incident, aligning closely with an earlier assessment by investigator Kamal. According to Bitquery’s findings, illicit withdrawals reached approximately $92.9 million distributed across 311 unique addresses. Summarizing the concentrated nature of the breach, Bitquery’s analysis explains that One thief had all the keys,
emphasizing that the perpetrator possessed direct signing control over the compromised portfolios.
The unauthorized transactions spanned multiple major networks, illustrating a sophisticated cross-chain liquidation campaign. According to Kamal’s report published in Yfarmx, at least seven distinct blockchain ecosystems were leveraged to extract and route the funds, including Tron, Bitcoin, Ethereum, BNB Chain, Polygon, Base, and Arbitrum. In addition to multi-chain transfers, decentralized routing solutions and privacy protocols such as Thorchain and Tornado Cash were utilized to conceal the movement of stolen capital. Notably, the recorded transactions appeared to be legitimate transfers executed with the victims’ authentic signing credentials. On the Bitcoin network, affected addresses were wiped completely, leaving behind no change unspent transaction outputs (UTXOs) in the initial sender balances.
Suspicions Mount Over Third-Party Supply Chain Tampering
As the cryptocurrency ecosystem searches for the root cause of the drained wallets, former Mt Gox CEO Mark Karpelès provided crucial insights into potential hardware vulnerabilities. Karpelès documented modified Ledger hardware wallets embedded with covert surveillance hardware that can capture recovery phrases at the exact moment a user sets up the device. This finding indicates that hardware devices sourced through unauthorized or third-party resellers might have been physically manipulated before buyers ever received the packaging or loaded their private funds.
Despite the plausibility of this vector, researchers have yet to establish an airtight evidentiary link. Hardware specialists and Ledger have not verified whether the specific victims of Friday’s drain operated altered units or if modified physical components successfully exfiltrated their recovery phrases. Security analysts have largely dismissed other potential vectors, observing that the current pattern bears no resemblance to the historical Coldcard firmware issue and shows no signs of an exploited remote zero-day flaw. Instead, the leading hypothesis among specialists remains an isolated supply chain compromise that impacted a specific batch of Ledger devices.
Security Vulnerabilities and Reseller Concerns
The ongoing mystery unfolds amid heightened anxiety surrounding hardware wallet logistics and consumer data protection. Competitors Trezor and Safepal recently suffered distinct data breaches that exposed the personal shipping and purchase information of tens of thousands of buyers, illustrating the persistent risks associated with distribution pipelines. Expanding on potential merchant exposure, Kamal’s investigation noted that third-party vendor CryptoBillis had distributed hardware from numerous prominent brands, having sold Trezor, Safepal, Tangem, [and] Onekey
models alongside other devices.
At present, Ledger has neither authenticated the estimated total loss nor validated any of the operating hypotheses circulating across social media platforms. With definitive answers still pending, users across the crypto industry remain on alert, awaiting a formal technical postmortem from Ledger to clarify whether the breach stems from malicious reseller tampering or an alternative vulnerability.
Why This Matters
This incident directly challenges the core premise of non-custodial cold storage: physical isolation from online threats. If confirmed, a supply chain exploit proves that hardware wallets remain acutely susceptible to offline interception before reaching the consumer. For the broader industry, it underscores the systemic risks posed by unofficial distributors and third-party e-commerce platforms, likely driving manufacturers to implement stricter cryptographic tamper-proofing, proprietary supply chains, and mandatory verification procedures during initial device setup.
Frequently Asked Questions
Did a remote zero-day flaw cause the Ledger wallet drains?
Current technical consensus suggests this was not caused by a remote zero-day exploit or a firmware flaw similar to previous Coldcard vulnerabilities. Industry analysts and investigators currently view a localized supply chain tampering attack as the most probable explanation, though official verification remains pending.
What total value of crypto assets was stolen in the exploit?
According to an analysis conducted by blockchain data infrastructure provider Bitquery, approximately $92.9 million was taken across 311 unique wallet addresses, corroborating independent analysis from on-chain researcher Kamal.
Has Ledger confirmed that compromised devices caused the losses?
No. Ledger has not confirmed the aggregate financial losses, nor has the company or independent security researchers found definitive proof directly tying modified hardware implants to the unauthorized transactions reported on Friday.




