
泥伏雷闯关记
泥伏雷闯关记
从普通到不凡,资金永不眠。
4Following
91followers
Feed
Feed
How to distinguish official direct shipments from third-party channels for Ledger, Trezor, and OneKey?
Recently, the Ledger incident has attracted a lot of attention. Based on my own purchase records, I’d like to share the shipping situations of several mainstream cold wallets.
▸ Ledger: shipped from France
▸ Trezor: shipped from the Czech Republic
▸ Tangem: I remember it ships from Switzerland,
▸ OneKey: generally shipped from mainland China
⚠️ Note: The shipping location can only be used as a reference and cannot solely determine whether the device is officially shipped. The safest way is to order from the brand’s official website, keep the order and shipping records, and complete device inspection and initialization according to the official guide.
▸ Official purchase channels for mainstream cold wallets
🛒 Ledger:
🛒 Trezor:
🛒 OneKey:
🛒 Tangem:
Purchasing directly from official channels can reduce intermediaries but does not guarantee zero risk; third-party shipments do not necessarily mean counterfeit products.
The key is that the purchase channel is traceable, device initialization is trustworthy, and the mnemonic phrase is generated and securely kept by yourself.
DYOR.






The sky is falling! Overnight, what exactly happened to Ledger, the world's top cold wallet?
▍Ledger $86 million suspected theft incident, latest developments
This is no longer just an ordinary crypto asset theft; it is a major event potentially involving hardware wallet supply chains, dealer equity changes, and device security.
🚨 On October 9, hardware wallet manufacturer Ledger is investigating user asset losses related to Southeast Asian dealer CryptoBilis and has requested the dealer to suspend all sales and shipments of Ledger devices.
On-chain investigators initially tracked over $86 million in suspected stolen funds involving BTC, ETH, TRON, and other networks.
Blockchain data analytics firm Bitquery further tracked and counted losses of about $92.9 million across 311 wallets on 5 blockchains. The two data sets cover different scopes; Ledger has yet to confirm the final loss amount, number of affected users, and specific attack causes.
▍1. Sudden ownership change of the involved dealer raises concerns
CryptoBilis is a dealer registered in Malaysia, selling hardware wallets to the Southeast Asian market, previously listed as an authorized sales channel for brands like Ledger, Trezor, OneKey, and SafePal.
Recent company records show that as of August 3, 2026, a person named Jiaming, registered in Heilongjiang Province, China, holds 100% of CryptoBilis shares.
The company's former co-founder confirmed that CryptoBilis was acquired in March this year, with the original owner subsequently stepping down from operations, management, and administrative roles. The former co-founder stated that after the handover, they no longer have control over the company's actual operations but are still assisting in coordinating related activities.
This means the dealer involved had completed ownership transfer before the suspected asset theft incident occurred.
However, there is currently no conclusive evidence proving a direct link between this equity change and the wallet theft, nor reliable proof confirming online speculation about the acquirer's identity and their behind-the-scenes connections.
▍2. The real concern is supply chain security
An important suspicion has emerged in the market: some users' purchased hardware wallets may have been tampered with before reaching consumers.
Related discussions, including by @MagicalTux, specifically mention the Ledger Nano X and possible hidden implants in the device.
According to security researchers, one possible attack vector is modifying device hardware or implanting additional components to steal sensitive information when users initialize wallets or generate/view mnemonic phrases, then transmitting that information to attackers.
Once the mnemonic phrase is leaked, attackers can restore the wallet on another device and directly transfer assets. This process may not require physical access to the victim's wallet.
But it must be clarified here: whether the Nano X was implanted with specific modules, how such implants work, and whether this incident was indeed carried out this way still require further investigation. Ledger has not released conclusive evidence confirming this attack chain.
▍3. Why official authenticity verification might not be enough?
Hardware wallet security depends not only on brand, firmware, and secure chips but also on whether the device is protected during production, transportation, storage, and sales.
If attackers can swap devices, modify hardware, or implant extra components during the supply chain, packaging, appearance, and even some routine verification processes may not sufficiently identify risks.
It should be noted that this does not mean Ledger's verification mechanisms have been proven ineffective. It remains unclear what kind of tampering the involved devices underwent and whether official inspections can detect these devices.
However, this incident raises a question all crypto users should be wary of: if cold wallet devices are untrustworthy before reaching your hands, then even the strictest self-custody procedures afterward may be based on a flawed security premise.
▍4. Former co-founder mentions NDA, controversy escalates
There are online reports that CryptoBilis's former owner signed a non-disclosure agreement (NDA), prohibiting disclosure of related information for a certain period.
This claim has sparked greater controversy: if a dealer undergoes control changes and the new management might affect device security, should the brand, partners, and consumers be promptly informed of the risks?
Currently, there is insufficient independent evidence about the NDA's specific terms, signing time, confidentiality scope, or whether it delayed the brand's awareness of related information.
Therefore, it cannot be directly concluded that the former owner or any brand knowingly concealed device issues.
But if further investigations confirm that relevant personnel were aware of clear supply chain security risks but failed to act timely, responsibility would extend beyond device theft to risk disclosure, dealer management, and consumer protection.
▍5. Not just Ledger: other hardware wallet brands deserve attention
CryptoBilis was listed as an authorized dealer for multiple hardware wallet brands, including:
• Ledger
• Trezor
• OneKey
• CoolWallet
• Tangem
• ELLIPAL
• SafePal
This does not mean the products of these brands have all been affected, nor is there evidence proving similar vulnerabilities in their official products.
What truly needs attention is: if the risk source lies in the dealer's warehousing, logistics, or sales, the investigation scope cannot be limited to a single brand.
It is also necessary to clarify which batches of devices the dealer sold, which users received them, and whether other brands face similar supply chain risks.
▍6. Ledger has issued temporary security recommendations
Ledger currently advises:
• Users who purchased devices from CryptoBilis within the past 90 days but have not initialized them should temporarily refrain from setting them up.
• Users who have already set up devices should consider migrating assets to another trusted Ledger signing device and generate entirely new mnemonic phrases.
• If devices might have been tampered with, do not import existing mnemonic phrases into suspicious devices or disclose mnemonic phrases to anyone.
It is important to emphasize that simply replacing devices does not equal completing a secure migration. New mnemonic phrases must be generated on trusted devices and old possibly compromised mnemonics must not be reused.
These recommendations apply to purchase records related to CryptoBilis and do not imply all Ledger users are affected.
▍Nifu Lei's perspective
The most alarming aspect of this incident is not negative news about the Ledger brand itself but that it reminds the entire industry: the security boundary of hardware wallets may be longer than many imagine.
We always emphasize self-custody of private keys, offline storage of mnemonic phrases, and avoiding phishing links, but often overlook an earlier step—what exactly has your device gone through before reaching your hands?
If supply chain attack suspicions are confirmed, this incident will be more than a theft; it will be a security wake-up call for the hardware wallet industry.
The safest approach remains to purchase through official brand channels and confirm device status and initialize wallets in trusted environments, ensuring mnemonic phrases are generated by yourself on trusted devices.
▸ Official Ledger purchase link ⬇️
🛒
▸ Nifu Lei's curated cold wallet official website navigation 🛒
But it must also be acknowledged that official channels do not guarantee zero risk, and authorized dealers should not be trusted unconditionally based solely on authorization.
For self-custody users, true security is not trusting a brand but minimizing risks you cannot verify or control.
DYOR, not investment advice.
The sky is falling! Overnight, what exactly happened to Ledger, the world's top cold wallet?
▍Ledger $86 million suspected theft incident, latest developments
This is no longer just an ordinary crypto asset theft; it is a major event potentially involving hardware wallet supply chains, dealer equity changes, and device security.
🚨 On October 9, hardware wallet manufacturer Ledger is investigating user asset losses related to Southeast Asian dealer CryptoBilis and has requested the dealer to suspend all sales and shipments of Ledger devices.
On-chain investigators initially tracked over $86 million in suspected stolen funds involving BTC, ETH, TRON, and other networks.
Blockchain data analytics firm Bitquery further tracked and counted losses of about $92.9 million across 311 wallets on 5 blockchains. The two data sets cover different scopes; Ledger has yet to confirm the final loss amount, number of affected users, and specific attack causes.
▍1. Sudden ownership change of the involved dealer raises concerns
CryptoBilis is a dealer registered in Malaysia, selling hardware wallets to the Southeast Asian market, previously listed as an authorized sales channel for brands like Ledger, Trezor, OneKey, and SafePal.
Recent company records show that as of August 3, 2026, a person named Jiaming, registered in Heilongjiang Province, China, holds 100% of CryptoBilis shares.
The company's former co-founder confirmed that CryptoBilis was acquired in March this year, with the original owner subsequently stepping down from operations, management, and administrative roles. The former co-founder stated that after the handover, they no longer have control over the company's actual operations but are still assisting in coordinating related activities.
This means the dealer involved had completed ownership transfer before the suspected asset theft incident occurred.
However, there is currently no conclusive evidence proving a direct link between this equity change and the wallet theft, nor reliable proof confirming online speculation about the acquirer's identity and their behind-the-scenes connections.
▍2. The real concern is supply chain security
An important suspicion has emerged in the market: some users' purchased hardware wallets may have been tampered with before reaching consumers.
Related discussions, including by @MagicalTux, specifically mention the Ledger Nano X and possible hidden implants in the device.
According to security researchers, one possible attack vector is modifying device hardware or implanting additional components to steal sensitive information when users initialize wallets or generate/view mnemonic phrases, then transmitting that information to attackers.
Once the mnemonic phrase is leaked, attackers can restore the wallet on another device and directly transfer assets. This process may not require physical access to the victim's wallet.
But it must be clarified here: whether the Nano X was implanted with specific modules, how such implants work, and whether this incident was indeed carried out this way still require further investigation. Ledger has not released conclusive evidence confirming this attack chain.
▍3. Why official authenticity verification might not be enough?
Hardware wallet security depends not only on brand, firmware, and secure chips but also on whether the device is protected during production, transportation, storage, and sales.
If attackers can swap devices, modify hardware, or implant extra components during the supply chain, packaging, appearance, and even some routine verification processes may not sufficiently identify risks.
It should be noted that this does not mean Ledger's verification mechanisms have been proven ineffective. It remains unclear what kind of tampering the involved devices underwent and whether official inspections can detect these devices.
However, this incident raises a question all crypto users should be wary of: if cold wallet devices are untrustworthy before reaching your hands, then even the strictest self-custody procedures afterward may be based on a flawed security premise.
▍4. Former co-founder mentions NDA, controversy escalates
There are online reports that CryptoBilis's former owner signed a non-disclosure agreement (NDA), prohibiting disclosure of related information for a certain period.
This claim has sparked greater controversy: if a dealer undergoes control changes and the new management might affect device security, should the brand, partners, and consumers be promptly informed of the risks?
Currently, there is insufficient independent evidence about the NDA's specific terms, signing time, confidentiality scope, or whether it delayed the brand's awareness of related information.
Therefore, it cannot be directly concluded that the former owner or any brand knowingly concealed device issues.
But if further investigations confirm that relevant personnel were aware of clear supply chain security risks but failed to act timely, responsibility would extend beyond device theft to risk disclosure, dealer management, and consumer protection.
▍5. Not just Ledger: other hardware wallet brands deserve attention
CryptoBilis was listed as an authorized dealer for multiple hardware wallet brands, including:
• Ledger
• Trezor
• OneKey
• CoolWallet
• Tangem
• ELLIPAL
• SafePal
This does not mean the products of these brands have all been affected, nor is there evidence proving similar vulnerabilities in their official products.
What truly needs attention is: if the risk source lies in the dealer's warehousing, logistics, or sales, the investigation scope cannot be limited to a single brand.
It is also necessary to clarify which batches of devices the dealer sold, which users received them, and whether other brands face similar supply chain risks.
▍6. Ledger has issued temporary security recommendations
Ledger currently advises:
• Users who purchased devices from CryptoBilis within the past 90 days but have not initialized them should temporarily refrain from setting them up.
• Users who have already set up devices should consider migrating assets to another trusted Ledger signing device and generate entirely new mnemonic phrases.
• If devices might have been tampered with, do not import existing mnemonic phrases into suspicious devices or disclose mnemonic phrases to anyone.
It is important to emphasize that simply replacing devices does not equal completing a secure migration. New mnemonic phrases must be generated on trusted devices and old possibly compromised mnemonics must not be reused.
These recommendations apply to purchase records related to CryptoBilis and do not imply all Ledger users are affected.
▍Nifu Lei's perspective
The most alarming aspect of this incident is not negative news about the Ledger brand itself but that it reminds the entire industry: the security boundary of hardware wallets may be longer than many imagine.
We always emphasize self-custody of private keys, offline storage of mnemonic phrases, and avoiding phishing links, but often overlook an earlier step—what exactly has your device gone through before reaching your hands?
If supply chain attack suspicions are confirmed, this incident will be more than a theft; it will be a security wake-up call for the hardware wallet industry.
The safest approach remains to purchase through official brand channels and confirm device status and initialize wallets in trusted environments, ensuring mnemonic phrases are generated by yourself on trusted devices.
▸ Official Ledger purchase link ⬇️
🛒
▸ Nifu Lei's curated cold wallet official website navigation 🛒
But it must also be acknowledged that official channels do not guarantee zero risk, and authorized dealers should not be trusted unconditionally based solely on authorization.
For self-custody users, true security is not trusting a brand but minimizing risks you cannot verify or control.
DYOR, not investment advice.




🚨 Ledger Genuine Check passed, so why is it still possible for dealers to "tamper"???
The key point is: Genuine verification ≠ supply chain security verification
Ledger's Genuine Check verifies the cryptographic identity of the secure element, confirming it is a genuine chip with keys injected by the Ledger factory. But this does not mean the entire device has never been tampered with, nor does it mean the recovery phrase is only known by you.
▍Where could the problem be?
1️⃣ Pre-set recovery phrase: Someone initializes a genuine device in advance, copies the 24 recovery words, then sells the device to you. The chip is genuine, and verification may pass, but the other party already controls your wallet.
2️⃣ Physical implantation: If someone implants a listening module in parts like the screen or buttons, while the secure element remains intact, the Genuine Check may still pass. Ledger officially states that genuine verification cannot detect all unauthorized physical modifications.
3️⃣ Software substitution: The device is genuine, but you downloaded a fake Ledger Wallet; attackers may steal the recovery phrase through a forged setup process.
4️⃣ Entire device counterfeit: Such devices usually cannot pass the official Genuine Check. Using the official client for verification is very important.
▍Progress on this incident
According to reports, Southeast Asia Ledger dealer CryptoBilis is involved in multiple user fund theft cases. Ledger Support has requested them to suspend sales and shipments, and advises users who purchased devices from this channel within the past 90 days to delay initialization; users who have already initialized should generate a new recovery phrase with a new device and transfer assets.
The exact attack vector is still under investigation; pre-set recovery phrases, hardware implants, etc., are only possibilities and should not be considered confirmed methods.
On-chain loss estimates have not yet been confirmed by Ledger.
▍How can ordinary users protect themselves?
▪️ Prioritize purchasing cold wallets through official channels.
▪️ Recovery cards must be blank; devices should be initialized starting from the welcome screen; if a pre-set recovery phrase or abnormal PIN is found, stop using immediately.
▪️ Only use the official client to complete the Genuine Check.
▪️ Recovery phrases must be generated by the device during the first setup; never use recovery phrases provided by others, nor enter them on websites or give them to customer service.
Official Ledger address⬇️
Nifu Lei Selected | Direct navigation to cold wallet official website🛒
Remember: A genuine chip only proves the chip's identity, it cannot prove the entire supply chain is secure. Cold wallet security requires vigilance at every step, from purchase channel to recovery phrase generation.
#ledger #trezor #onekey
Wtf @Ledger 发生什么事了哦
There have been a reports on X and Reddit of wallet-draining by Ledger users.
I traced the theft addresses and identified inflows from more hundreds of victim wallets across several major blockchains, including Ethereum, TRON, and Bitcoin.
Total losses $86M+
bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl
TK6DWNpNe1w2iJRNFpU8aHdrPTATxvXT6C
TBkcUMYC7CkTK99tkTnaStQVBastfrs9d9
TCGE3xp6YGRKXxDZiLfysgJW3f22KfMNsW
0x69c8f401cfc6cd40ac94691d6d7c48e3b7a47841
0x033636e45d519bebb7b5c2520ca6ce56fbdb4f7a
0x83aeac166f6832ae3500000a24510a95a052a599
bc1qqnkwurxs99xkx5t4yffqhq3u6qwy0qpjyujtm9
bc1qgqheemzla77pesl227hdtgf5ykz62d0zvld26n
TSDWtuZ2pARUVz4v3PkL2hi3iXPjowAr5a


🇲🇳 Mongolia reports plague outbreak in Russia; sounds quite serious
The Mongolian Minister of Health announced at a press conference that a pneumonic plague outbreak has occurred in Irkutsk Oblast, Russia. Pneumonic plague is the most severe form of plague, with a very high fatality rate, and it can be transmitted through droplets, making it highly likely to cause a large-scale outbreak.
Mongolia has activated its emergency response plan, strengthening quarantine inspections at border crossings to strictly prevent the epidemic from entering the country.
A country with over 3 million people cannot afford such turmoil.



