In early October, attackers abused several channels people use to choose, set up, and manage wallets. Bitquery counted $92.9 million drained from 311 wallets linked to Ledger devices bought through Southeast Asian reseller CryptoBilis. Ledger said it found an unauthorized hardware implant in one affected Nano X. A hijacked Coldcard X account posted a fake warning to move funds, and 16 Firefox add-ons imitated Rabby and OKX wallets to capture recovery phrases.
The common failure was the trust path around a wallet. The available findings do not show a secure-element break. They show why a device's source, the sender of a message, and the software around a wallet all matter.
The CryptoBilis drain
On October 9, Ledger said it was investigating reports of losses from customers in Indonesia, Malaysia, and the Philippines who bought devices through CryptoBilis. Ledger asked the reseller to pause sales and shipments while the investigation continued. The losses remain under investigation.
Bitquery's on-chain analysis counted $92.9 million across 311 wallets and five chains. That is Bitquery's measured total, not a figure confirmed by Ledger. Bitquery also reported that Tether froze $10 million in USDT linked to the drain and traced some funds into Tornado Cash. A freeze does not return funds to victims.
On October 10, Ledger reported that an affected user's Nano X contained an unauthorized hardware implant. The implant's exact operation and its relationship to the wider losses remain under investigation. Reporting on the examined unit says the implant may have captured recovery words while they appeared on the device screen. That is not evidence that every drained wallet used an implanted device. Ledger advised recent CryptoBilis buyers not to set up unused devices and to consider moving assets to a new signer with a newly generated recovery phrase if they had already initialized one.
Trusted channels can carry the lure
The Brevo incident happened on September 9, before the October drain. Trezor said an attacker abused its third-party email provider to send phishing from Trezor's real mailing infrastructure. Trezor later confirmed that 347,149 marketing contacts were exported. The message used the subject “Critical Security Alert: STM32 Entropy Vulnerability” and asked recipients to enter their wallet backup into an app. Trezor said it disabled the sending path and removed the phishing domain. The incident affected contact data and email delivery; Trezor said its wallet and account systems were not accessed. See Trezor's incident notice.
On October 11, Coldcard's X account was reportedly hijacked to publish a fake firmware vulnerability warning telling users to move funds immediately. The post named real patched firmware versions, which made the warning look plausible. Treat this account takeover as reported. It did not establish a new Coldcard firmware vulnerability. The July entropy incident is a separate issue covered in our Coldcard entropy report and safe migration guide.
The lesson is specific: sender identity alone is not verification. A real mailing domain or brand account can be under an attacker's control. Do not follow a recovery link or move funds because a message says the clock is ticking. Open a second official channel yourself and check for the same notice.
The extension-store version
Socket reported 16 malicious Firefox extensions: four imitated Rabby and 12 imitated OKX. Their wallet import screens collected recovery phrases or private keys and sent them to attacker-controlled Cloudflare Workers. Socket linked the operation to its previously reported “Offside Wallet Theft Factory” campaign. Mozilla had unpublished the extensions by October 5, according to Socket. The extensions targeted secrets entered by users; the report does not say that they extracted secrets from hardware devices. Read Socket's technical analysis.
A browser store listing and a familiar wallet interface do not prove that an extension is genuine. Install wallets through links from the project's official site, and never enter a hardware wallet's recovery phrase into a browser extension.
What to do
- Buy from official channels. Order directly from the manufacturer or use its official store locator. See Ledger's official store and Trezor's official store. If a device came from a reseller now under investigation, follow the manufacturer's current instructions before setting it up or using it.
- Never type a recovery phrase into a site, app, email, or browser extension. A legitimate wallet setup asks you to write the words down and confirm them on the device. It does not ask you to paste them into a web form.
- Treat urgent “move funds now” messages as phishing until independently verified. Do not use the link or contact details in the message.
- Verify through a second official channel. Type the known domain yourself, open the vendor's app, or check a separately reached official account. A familiar sender address or verified social account can still be compromised.
- Review transaction details on the hardware screen. On-device review helps against a compromised computer; it cannot make a tampered supply chain or a stolen recovery phrase safe. Our Trezor Clear Signing guide explains what readable transaction data can and cannot show.
October context
- OneKey Pro 2: OneKey announced it on October 8 at $299, according to the launch information. This is product context only.
- Ledger announced Wallet features including Crypto Loan through Morpho, and Telegram opened its Money wallet. These launches do not change the rules above.
WalletLab take
These incidents crossed hardware distribution, marketing email, social media, and browser extensions. They did not demonstrate that a secure element had been broken. In the Ledger case, a reported physical implant in one examined device is still under investigation, and Bitquery's $92.9 million count describes on-chain losses rather than a confirmed root cause for every wallet.
A hardware wallet protects keys when its setup and recovery process remain trustworthy. Buy through official channels, keep the recovery phrase offline, and treat urgent migration messages as hostile until you verify them independently. For software-wallet selection, start with our software wallets guide.