Key Highlights:
- Blockchain intelligence firm Bitquery tracked 5.2 million Tether (USDT) transferred to three Binance deposit addresses via suspected over-the-counter intermediaries following a major crypto theft.
- The illicit flows do not indicate recovered assets, as funds were commingled with third-party capital, while previous conversion maneuvers through USDD were aimed at bypassing Tether freeze mechanisms.
- Hardware wallet maker Ledger confirmed an “unauthorized hardware implant” in an affected user’s device, prompting distributor CryptoBilis to temporarily halt all hardware wallet sales.
Tracing the Flow: Stolen Assets Routed Through Intermediaries to Binance
Blockchain analytics firm Bitquery has identified significant on-chain movements tracing back to a high-profile cryptocurrency theft, revealing that millions in digital assets were routed toward the Binance exchange. According to Bitquery’s investigation, five digital wallets exhibiting trading behaviors consistent with over-the-counter (OTC) services received Tether (USDT) after 5.1 million USDD connected to the incident was swapped back into USDT on Oct. 10. By the morning of Oct. 11, Bitquery tracked 5.2 million USDT in follow-up transfers from these intermediary wallets into three specific Binance deposit addresses.
Investigators cautioned that the observed transfers represent gross transaction volume flowing through intermediary accounts rather than the definitive retrieval or recovery of the stolen capital. Addressing the complexity of tracing these mixed assets, Bitquery wrote: “The $USDT they sent to Binance includes other people’s money, so the thief’s exact share there cannot be fixed.”
Consequently, analysts noted that Bitquery’s totals should not be combined with external loss calculations, such as estimates compiled by blockchain security outfit PeckShield.
Evasion Tactics and Freezing Efforts Across Stablecoins and Mixers
The routing through OTC-style services highlights active evasion tactics designed to shield the stolen proceeds from centralized intervention. Tether, the issuer of USDT, maintains contract-level freeze controls on its stablecoins, which do not apply to decentralized alternatives such as USDD. As previously reported by The Defiant, the perpetrator executed a 2 million USDT conversion into USDD via its peg stability module to avoid Tether’s administrative controls. Furthermore, blockchain tracking service MistTrack disclosed that approximately 463 ETH linked to an incident-associated address was funneled into the privacy mixer Tornado Cash on Oct. 10.
While Bitquery estimates that Tether has successfully blacklisted and frozen roughly $10 million in USDT across the broader theft cluster, those historical freezes do not automatically apply to the newly detected Binance transactions. As it stands, neither PeckShield’s alert nor Bitquery’s published findings confirm whether Binance has taken action to lock or freeze the inbound deposits identified at those three addresses.
Major Token Unlocks Coming for 18 Altcoins This Week: Full Day-by-Day, Hour-by-Hour Schedule
Hardware Investigation and Supply Chain Responses
The on-chain movements coincide with ongoing physical investigations by hardware wallet manufacturer Ledger. In an update published on Oct. 10, the company disclosed that a forensic review of an impacted user’s hardware unit revealed an “unauthorized hardware implant,”
indicating physical tampering rather than a digital exploit. Ledger emphasized that it found no indication that its core security infrastructure, internal systems, or online services had suffered a compromise.
In response to the discovery of hardware manipulation, regional distributor CryptoBilis suspended sales across its entire hardware-wallet inventory. Ledger noted that CryptoBilis will keep sales halted until the comprehensive investigation into the supply chain breach concludes.
Why This Matters
This incident underscores critical vulnerabilities that sit at the intersection of physical supply chains and decentralized finance tracking. While blockchain tracking firms can actively map the movement of stolen funds in near real-time, the commingling of assets through over-the-counter desks and mixers poses massive challenges for law enforcement and exchanges attempting to execute legal freezes without impacting legitimate user funds. Furthermore, the confirmation of physical hardware implants marks an escalated threat vector for self-custody security, showing that physical supply chain integrity is just as crucial as cryptographic code audits.
Frequently Asked Questions
Does the movement of 5.2 million USDT to Binance mean the stolen funds have been recovered?
No. Blockchain analytics firm Bitquery confirmed that these figures represent gross flows through intermediary wallets that handle third-party funds. Because the perpetrator’s assets were commingled with other individuals’ capital, the transfer to Binance is merely an investigative lead and does not signify an asset recovery.
Were the deposit addresses on Binance frozen?
As of the latest reports from Bitquery and PeckShield, there is no official confirmation that Binance has frozen the three deposit addresses that received the 5.2 million USDT.
How was Ledger impacted in this security incident?
Ledger stated that an impacted user’s device featured an unauthorized hardware implant, but confirmed there is no evidence suggesting its own corporate security systems, infrastructure, or services were compromised. In response, distributor CryptoBilis suspended all hardware-wallet sales pending the outcome of the investigation.




