Ledger Investigating Theft of Millions from Reseller, Personal Data Compromised
Ledger, the hardware wallet manufacturer, is investigating reports that millions of dollars in cryptocurrency were stolen through a compromised reseller. The breach also exposed personal data belonging to customers who purchased through the affected channel.
The attack vector appears to be a malicious actor who gained access to a reseller's systems and used that access to intercept or redirect customer transactions. Ledger has not disclosed the exact mechanism but confirmed that the breach did not involve its own infrastructure.
Customers who purchased hardware wallets through third-party resellers are being advised to verify that their devices were not tampered with before use. A compromised device can silently redirect transactions to an attacker-controlled address.
The incident highlights the supply chain risk inherent in hardware wallet distribution. A device is only as secure as the supply chain that delivered it, and a single compromised reseller can undermine the security of every customer who bought through that channel.
Ledger has stated that its own direct sales channel was not affected and that customers who purchased directly from Ledger do not need to take action.
The investigation is ongoing, and the company has not yet disclosed the total number of affected customers or the full scope of the personal data that was exposed.