• Bitcoin$82,475▼ 0.10%
  • Ethereum$2,488▲ 0.09%
  • XRP$1.40▲ 0.28%
  • KOSPI6,625.93▼ 2.62%
  • Nasdaq27,366.17▲ 0.64%
  • S&P 5007,811.54▲ 0.59%
  • USD/KRW1,340.02▼ 0.19%
  • Brent Oil$104.43▲ 0.14%
  • Samsung Elec.$195.52▼ 2.42%
  • SK hynix$1,254▼ 2.44%
  • Apple$336.64▼ 1.11%
  • Microsoft$535.07▲ 2.38%
  • Alphabet$351.66▲ 0.97%
  • Amazon$262.43▲ 3.29%
  • Nvidia$229.28▼ 0.52%
  • Meta$718.67▼ 0.31%
  • Tesla$382.70▲ 2.05%
Powered by TickTurn

가장 안전하다는 코인 지갑에서, 왜 1,150억 원이 사라졌을까

2026-10-10
osc_bitpress_ledger-reseller-wallet-theft-recovery-phrase

On Oct. 9 (local time), Ledger, a company that makes crypto wallet devices (small gadgets that keep the keys to coins like Bitcoin offline), told people who had bought a device from the Southeast Asian store CryptoBilis in the last 90 days: "If you haven't set it up yet, don't start." The same day, blockchain investigator Specter estimated that more than $86 million (about 115 billion won) in crypto had flowed to suspected theft addresses.

The common reading is "another crypto wallet got hacked." But Ledger has not named a cause, and what it acted on was not the device's hardware but the sales route the device took. Ledger makes it → a store sells it → the buyer switches it on and creates the key. In that chain, the store step is now under investigation.


  1. What exactly did Ledger tell people to do?

Ledger said three things through its customer support account on X (formerly Twitter). It asked CryptoBilis to pause all sales and shipments of Ledger devices, and told anyone who bought there in the last 90 days not to start setting the device up. If they had already set it up and were using it, Ledger advised them to consider moving their coins to a new device with a new recovery phrase.

The cause is still under investigation. Ledger has not confirmed the size of the losses, and there is no confirmation that devices were tampered with. It is also not yet known whether every theft is linked to this store.


  1. What does a hardware wallet actually protect?

The heart of a hardware wallet is the recovery phrase. It is the master backup that can regenerate the wallet's private keys at any time. Anyone who knows the phrase can move the coins even without the device.

Think of it like the door lock on a new home. However strong the lock is, it's useless if the installer already knows the code. The difference is that a door lock guards one door, while a recovery phrase opens every coin in that wallet. If you put 10 million won (about $7,500) of crypto in it, someone who knows the phrase could move all of it without ever touching the device.

Crypto media pointed to one possible scenario: devices tampered with before delivery and sold with a recovery phrase the attacker already knew. That is a possibility, not a confirmed cause. Ledger's advice of "new device, new phrase" reads as a sign that the existing keys can no longer be fully trusted.


  1. How big is the money that disappeared?

Specter traced suspected theft addresses across three blockchains, Bitcoin, Ethereum and Tron, and put the losses at more than $86 million. Arkham (a blockchain analytics firm) data he shared showed about $87 million at the theft addresses. That included about $42 million in Ether, $17.6 million in Bitcoin and $16.5 million in Tether (USDT), a coin designed to keep the same value as the dollar.

Another researcher, Tanuki42, said more than $72 million had moved to suspected theft addresses. It is unclear whether the two estimates count the same transactions. Specter first said "hundreds of wallets," then corrected himself to say the number of affected wallets is not yet known.

Put simply, the losses are still estimates, the biggest share is Ether, and no one knows how many people were hit.


  1. Why is a store at the center of this?

CryptoBilis appears on Ledger's list of official resellers in Indonesia, Malaysia and the Philippines. That means people who believed they were buying genuine devices through an official channel may have been hit.

Binance co-founder Changpeng Zhao said available information suggested a supply chain attack (tampering at a middle step before a product reaches the buyer) involving one vendor, and that a small number of users may have bought fake or tampered devices. Former Mt. Gox (a former crypto exchange) CEO Mark Karpelès asked victims to send photos of their devices' circuit boards, since tampering could show up there.

Something similar has happened before. In December 2020, data on 272,853 Ledger buyers was published on a hacking forum, and in June 2021 tampered Ledger devices arrived by mail. Those devices asked users to enter their recovery phrase and sent it to the attackers. That time it was an unexpected package; this time, a store on the official list is being named.


  1. BITPRESS Insight

People who keep their own crypto instead of leaving it on an exchange buy hardware wallets to stop worrying about exchanges getting hacked. This case shows they take on a new worry in exchange: whose hands the device passed through before it reached them.

So there is something to check before the price or the chip. It is whether the recovery phrase, the key itself, was created for the first time, in front of you. The fake devices in 2021 also took people's money with a single instruction to enter an existing phrase.

What protects your coins is not how good the device is, but whether you can be sure that no one but you has ever seen the key it made.


Sources
https://www.coindesk.com/business/2026/10/09/ledger-investigates-potential-wallet-tampering-after-reports-of-usd86-million-in-crypto-stolen
https://decrypt.co/380582/ledger-probes-87m-theft-crypto-wallet-reseller
https://www.theblock.co/news/business/2026-10-09-ledger-cryptobilis-fund-losses-418163
https://www.bleepingcomputer.com/news/cryptocurrency/criminals-are-mailing-altered-ledger-devices-to-steal-cryptocurrency/
https://www.mt.co.kr/economy/2026/10/08/2026100815360412966


Glossary
hardware wallet — A device that keeps the secret keys used to spend crypto on a small gadget kept off the internet.
recovery phrase (seed phrase) — A set of words that can regenerate a wallet's secret keys; anyone who knows it can move the coins without the device.
supply chain attack — An attack that secretly tampers with a product at a middle step between the maker and the buyer.
official reseller — An outside sales company that a maker lists as authorized to sell its products.
Tether (USDT) — A coin designed to keep a value of one dollar per coin.

BITPRESS articles are information to help your investment decisions, not a recommendation to buy or sell any stock or coin. Investment decisions and their results are your own responsibility.

Trending now

Latest news

Why did Korea's fixed mortgage rates rise more than the Bank of Korea's hikes?

Korea's fixed mortgage rate rose 0.91 percentage points, from 3.97% last October to 4.88% this August, nearly twice the base-rate increase over the same period (0.50 points). Fixed rates track what...

France can collect taxes. So why does it pay more to borrow than many French companies?

On Oct. 7, 38% of France's high-grade corporate bonds, about €215 billion ($241 billion) worth, traded at lower yields than French government bonds. It means investors trust many French companies more...

Apple stock as a crypto token pays dividends, but your name isn't on the shareholder register

The tokens for 12 US stocks, including Apple and Nvidia, that Securitize announced on Oct. 8 are, by the company's account, issued one per real share and designed to carry dividends and voting...

Why the Nasdaq fell on a report that OpenAI's sales grew

A report said OpenAI's end-of-September revenue (stretched to a full year) was about $50 billion, $20 billion below the $70 billion the market expected. But sales...

Samsung said it earned KRW 107 trillion in a single quarter. Why did its stock fall that day?

Samsung Electronics' third-quarter operating profit of KRW 107.4 trillion was only about 0.7% above the analyst estimate compiled by FnGuide, and on the same day selling tied to a chip ETF...

Binance vs. Coinbase

83% of the bitcoin Binance holds sits at addresses whose public keys are already exposed; at Coinbase it is 10% (Glassnode data, Oct. 8). The two exchanges, one first in trading volume and the other first in an...