Key takeaways
- Ledger is investigating reports that roughly $86 to $87 million was drained from customer wallets, with the cases tied to devices obtained through a reseller rather than the manufacturer.
- A hardware wallet's entire security model rests on the recovery phrase being generated on the device, by you, and never existing anywhere else.
- A device supplied with a recovery phrase already written down is not a faulty device. It is an attacker's wallet that you are funding.
- Tamper-evident packaging is weak evidence, because seals, shrink wrap and holograms can be reproduced far more cheaply than the funds being targeted.
- Self-custody does not eliminate trust. It moves it from an exchange to the device's supply chain, and that is a different risk rather than no risk.
Ledger is investigating reports that roughly $86 million was drained from customer wallets. The cases reported so far appear to share a common factor: devices obtained through a reseller rather than directly from the manufacturer, and Ledger has asked that reseller to stop selling.
The investigation is ongoing and the details may change. The mechanism, though, is one of the most important things a self-custody holder can understand, because it defeats the protection people believe they have bought.
What a hardware wallet actually guarantees
The security model is narrower than most people assume, and knowing its exact shape is what makes the attack obvious.
A hardware wallet generates a private key inside a chip, using randomness produced on the device, and that key is designed never to leave it. When you sign a transaction, the unsigned transaction goes in, a signature comes out, and the key stays put. That is the whole promise: the secret is created in one place and never travels.
The recovery phrase is the human-readable form of that secret. It is generated on the device at setup, displayed on the device's own screen, and written down by you. Every part of that sequence matters.
The attack is to break the first step
If the key is created on the device and never leaves, the only way to get it is to be there when it is created — or to decide what it will be in advance.
That is what a tampered or pre-configured device does. It arrives with a recovery phrase already determined, and frequently with that phrase printed on a card in the box, presented as your recovery phrase, sometimes with instructions to enter it to activate the device.
A genuine device never does this. There is no legitimate circumstance in which a hardware wallet is supplied with a recovery phrase already generated. If one arrives that way, the phrase is known to whoever prepared it, and every deposit is being sent to an address they can spend from.
The cruel part is the delay. Nothing happens at setup. The device works, the balance shows, transactions sign normally. The funds leave at a moment the attacker chooses, which is usually once enough has accumulated to be worth taking.
Why the sealed box proves nothing
People reasonably check that packaging looks untouched. It is weak evidence, and it is worth understanding why rather than simply being told.
Tamper-evident packaging is a cost barrier, not a cryptographic one. Shrink wrap, seals and holographic stickers can be sourced or reproduced for a trivial amount compared with the sums in play here. An attacker willing to prepare devices holding millions is not deterred by a sticker.
The provenance of the device is doing the real work, not the state of the box. A device that came from the manufacturer or an authorised channel has a supply chain you can reason about. One bought from a marketplace listing, a reseller you cannot verify, or second hand does not, however convincing the packaging.
Manufacturers also provide a genuineness check through their own software, which verifies the device cryptographically rather than visually. It is a real control and it is routinely skipped because the box looked fine.
The part that reframes self-custody
Self-custody is usually described as removing trust. Not your keys, not your coins. The reasoning is sound as far as it goes: holding your own keys removes an exchange's solvency, its competence and its permission from the equation.
What it does not do is remove trust from the system. It relocates it.
Instead of trusting a custodian, you are now trusting the device manufacturer, the firmware, the randomness the chip produced, the supply chain the unit travelled through, and your own handling of a phrase that cannot be changed once funds exist. Those are different dependencies with different failure modes, and several of them are harder to assess than an exchange's published accounts.
This is not an argument against self-custody. It is an argument for knowing precisely what you have taken on, because the people who lost money here had done the thing they were repeatedly advised to do.
What happened to the stolen funds
Part of the story illustrates something covered here before. Tether reportedly froze USDT associated with the thefts, which is possible because issuer blocklisting is a function built into the token contract.
It also showed the bluntness of that instrument: several THORChain vaults were blacklisted and then unfrozen a few hours later. Freeze powers operate on addresses, and addresses used by protocols are shared rather than personal, so action against a thief can briefly immobilise unrelated users.
Assets without an issuer have no such mechanism at all. Where a stablecoin issuer can act, nobody can freeze Bitcoin or Ether, and that cuts both ways depending on which side of a theft you are on.
The practical reading
A short list, and none of it is novel — which is rather the point, because it is the advice that was already standard.
Obtain a hardware wallet from the manufacturer or an authorised seller, never from a marketplace reseller and never second hand. Generate the recovery phrase yourself, on the device, at setup. If a phrase arrives with the device, the device is compromised and no part of it should be used. Run the manufacturer's genuineness check. Treat a sealed box as meaning nothing on its own. And send a small amount first, then wait, before moving anything significant.
The holders least exposed to this were not the most sophisticated. They were the ones who bought from the manufacturer and typed down a phrase the device showed them.
Education, not investment advice.
Frequently asked questions
Were the hardware wallets hacked?
Not in the sense of their security being broken. The reported cases point to devices supplied through a reseller with the recovery phrase already determined, so whoever prepared them knew the secret from the start. The device then functions normally while the attacker can spend from the same addresses.
How can I tell if a device is compromised?
The clearest signal is a recovery phrase supplied with the device, on a card or in the instructions. A genuine hardware wallet always generates the phrase on the device at setup and displays it on its own screen. There is no legitimate reason for one to arrive pre-filled.
Doesn't sealed packaging prove a device is untampered?
Very little. Seals, shrink wrap and holograms are a cost barrier rather than a cryptographic one, and can be reproduced cheaply relative to the sums targeted. Provenance matters far more than packaging, along with the manufacturer's own cryptographic genuineness check.
Why is buying from a reseller risky?
Because the security depends on the device being exactly as the manufacturer built it. A reseller adds a step in the supply chain that you cannot verify. Buying direct or from an authorised channel is the one control that addresses this class of attack at the source.
Does this mean self-custody is a mistake?
No, but it clarifies what self-custody does. It removes an exchange's solvency, competence and permission from the equation, and replaces those with trust in the manufacturer, the firmware, the supply chain and your own handling of the recovery phrase. Different dependencies, not an absence of them.
Can stolen funds be recovered?
Sometimes partly. A stablecoin issuer can blocklist addresses, and Tether reportedly froze USDT linked to these thefts. That power is blunt — several protocol vaults were blacklisted and unfrozen hours later. Assets with no issuer, such as Bitcoin or Ether, have no equivalent mechanism.
Not financial advice. Crypto assets are volatile and unregulated in many jurisdictions. In India, gains are taxed at 30% with 1% TDS on transfers. Do your own research and never invest money you cannot afford to lose.
Editorial note: Crypto Shakti uses an AI-assisted research and drafting workflow. Every article is grounded in the linked primary sources and live market data captured at publication time.
