A Genuine Ledger Can Still Be Tampered With

10 Oct 2026 News

I use a Ledger. Until this week, I took a successful Genuine Check to mean the device in my hands was safe to use. I suspect a lot of us did.

The image above is an illustration, not a photograph of a CryptoBilis device.

The CryptoBilis investigation has made me look at that little green light differently. The check answers a narrower question than its name suggests: is the Secure Element genuine? It does not answer: has anyone added something else to the device?

What we know about CryptoBilis

On 9 October 2026, Ledger said it was investigating reports of lost funds from customers in Southeast Asia who bought its devices through CryptoBilis, an authorised reseller in Indonesia, Malaysia and the Philippines. Ledger asked CryptoBilis to pause Ledger sales and shipments. It told people who bought from that reseller in the past 90 days not to set up an unused device, and those who had already set one up to consider moving funds to a new signer with a new recovery phrase.

Ledger has not established the exact cause, how many people are affected, or a confirmed loss total. Researchers have traced large clusters of suspicious transfers; those estimates aren’t proof that every transaction came from a CryptoBilis device. Cointelegraph’s report makes that distinction clear.

The X post that raised this alleges implanted devices. Ledger hasn’t confirmed that explanation.

What a “genuine” pass actually proves

Ledger’s own threat model explains the check. Its server sends a random challenge to the device’s Secure Element. That chip signs the challenge with a private key created during manufacturing, and Ledger verifies the response. A counterfeit chip should fail.

But an attacker does not necessarily need to replace the chip. A genuine Ledger can be opened, modified and closed again while its original Secure Element stays in place. The check still passes because the chip it tests is genuine.

Ledger states the limitation plainly: Genuine Check cannot detect unauthorised physical modifications, including spying implants, if the original Secure Element remains intact. Its buying guide says the same thing.

The cryptographic check works as designed. The problem is that “genuine” sounds like a verdict on the whole device, when it only verifies one component. Ledger should make that impossible to miss during setup.

How an added component could steal a seed

Hardware researcher Joe Grand documented an implant found inside a Ledger Nano X earlier this year. An added circuit can observe what the device shows on its screen, including recovery words during setup, while the original Secure Element continues to pass authentication.

The recovery phrase is the wallet. If an attacker gets those words, they can restore the wallet elsewhere and empty it later. They don’t have to break the Secure Element or persuade you to approve a transaction on your device.

Grand’s research shows that this attack is possible. It doesn’t establish how the CryptoBilis losses happened. That still needs physical evidence and Ledger’s findings.

Where I would buy one now

For a new device, I would order by typing ledger.com myself and keeping the order receipt. Buying direct removes a reseller from the chain. Ledger told Cointelegraph it had received no reports involving devices bought directly from the company as of 9 October, although its investigation was still open.

I wouldn’t call direct purchase a guarantee. A package still travels through warehouses, carriers and doorsteps. Ledger itself says no global supply chain is immune to interception or tampering. And an “authorised reseller” badge didn’t make this warning any less unsettling.

When the package arrives, I would check for signs it was opened or altered and refuse to use it if anything looks wrong. I would install Ledger Wallet only from Ledger’s official site, run Genuine Check, and generate a fresh recovery phrase on the device. A prewritten phrase, supplied PIN, or request to type the phrase into a website or app is a stop sign. These checks reduce different risks; none is a complete physical inspection. Ledger also warns that seals can be copied or a package reopened without visible damage.

If you already own a Ledger

First, look up your purchase record if you can. Buying directly from Ledger.com is different from buying from CryptoBilis, even if CryptoBilis was an authorised dealer. Don’t assume an order placed on Ledger’s website was routed through that reseller without evidence.

If your device came from CryptoBilis in the period Ledger identified, follow Ledger’s notice. Don’t set up an unused device. If you’ve used one, consider moving assets to a new device with a newly generated recovery phrase. Restoring the old phrase onto a new device would carry the same possible exposure with it.

For everyone else, a Genuine Check still has value. It makes a counterfeit Secure Element much harder to pass off as real. I just won’t read that pass as proof that nobody has ever opened the case.