Skip to content
Bitcoin

Update for XRP Holders: How $91 Million Was Drained From Ledger Wallets

Investigator Exsiway reveals how $91 million was drained from Ledger wallets in Southeast Asia following the covert sale of an authorized Malaysian reseller to a new owner who inserted malicious hardware.

Update for XRP Holders: How $91 Million Was Drained From Ledger Wallets

Investigator Exsiway (@exsiway) believes he has uncovered the precise mechanism behind the overnight theft of $91 million from Ledger hardware wallets. His conclusions, drawn from an examination of company filings, on-chain data, and a hardware teardown, suggest a calculated operation that goes far beyond a typical security breach.

Ledger manufactures physical hardware wallets designed to store private keys offline, protecting assets from internet-connected vulnerabilities and maintaining a reputation as one of the most secure methods for holding cryptocurrency.

On October 9, numerous Ledger users across Southeast Asia discovered their wallets had been completely drained, resulting in aggregate losses of roughly $91 million.

A Legitimate Shop With a Hidden New Owner

CryptoBilis is a Malaysian hardware wallet vendor that Ledger recognized as an official authorized reseller starting in at least 2022, serving customers in Malaysia, Indonesia, and the Philippines. The store functioned normally for years, providing authentic devices to legitimate buyers.

Earlier this spring, the original founders sold the enterprise under a non-disclosure agreement that barred them from disclosing the sale until October 19. By August, official corporate registry documents indicated that 100% of the company had been transferred to a single individual located in Heilongjiang, China.

While the storefront remained operational and kept the “authorized by Ledger” seal displayed on its website, Ledger was never formally notified of the ownership transfer.

The Tampered Device

On October 8, Mark Karpelès (@MagicalTux) physically disassembled a Ledger unit sourced from Malaysia and discovered an unexpected modification: a secondary circuit board containing an LTE modem and an eSIM positioned beneath the screen.

This internal component passively monitored the display, impacting even those investors who never exposed their seed phrases. When users initialized the device and the 24-word recovery phrase appeared on the display, the hidden board intercepted and broadcast the information via cellular data.

Because the internal Ledger chip itself was authentic, the hardware’s standard verification checks failed to flag the device. Although financial experts frequently recommend hardware wallets for security, the vulnerability stemmed from external hardware layered on top of the authentic parts. Exsiway pointed out that his post regarding this discovery garnered 120,000 views.

The Drain

The attack was carried out 22 hours after Karpelès published his findings. A single block processed 203 BTC sent to two separate addresses, while approximately $58 million in Tron-based USDT was transferred within that same hour. Overall losses across the compromised wallets totaled about $91 million.

Seven hours after the thefts occurred, Ledger issued a public statement announcing an investigation and instructing CryptoBilis to halt all sales and deliveries. At that exact moment, CryptoBilis was still listed as an authorized reseller on Ledger’s platform.

The Bigger Problem Exsiway Identified

Exsiway highlights a major vulnerability concerning the definition of an “authorized reseller.” Ledger originally bestowed that designation in 2022 based on confidence in the shop’s previous operators, which provided no safeguards regarding future owners. Furthermore, the confidentiality agreement tied to the sale prohibited the original founders from disclosing the change in ownership while the attack was being set up.

He maps out a potential timeline: a vendor gains official reseller approval and builds trust over years of legitimate operation. The founders then quietly sell the business under a strict NDA. The new proprietor inherits the trusted badge and history, allowing them to distribute modified devices until enough users set them up for a coordinated, simultaneous drainage of funds.

Additionally, Exsiway points out that Ledger’s authentication tool cannot detect this type of compromise because the core Ledger chip is genuine. Since the malicious element consists entirely of added hardware inside the casing, Ledger’s verification process does not scan for it.

The Issue of Trust

Coming on the heels of the September Bitget breach, which saw more than $350 million stolen, he concludes with a query regarding responsibility. He questions whether the blame lies with the new owner, the original vendors, or Ledger for its inability to track changes in authorized reseller status.

Leave a Reply

Your email address will not be published. Required fields are marked *