Cybersecurity · Sunday, 11 October 2026
Ledger finds a hidden chip in a crypto wallet sold by a reseller, as reports say thieves took more than $86m from hundreds of wallets
Ledger, which makes small devices for keeping crypto coins safe, says one customer's wallet held a chip it never put there. The wallets came through a reseller, CryptoBillis, and Ledger has asked it to pause sales.
$86m+
in crypto reported taken from hundreds of wallets
the figure comes from reports gathered by The Verge, not from Ledger
1
device Ledger has confirmed held a chip it did not put there
Ledger has asked the reseller CryptoBillis to pause all sales
The lead story — what happened
-
Ledger, a company that makes small devices for keeping crypto coins safe, has confirmed that one customer's device held a hidden chip it did not put there.
[1] -
The wallets in question appear to have been sold by CryptoBillis, a reseller, and not by Ledger itself.
[1] -
Ledger has asked CryptoBillis to pause all sales of its wallets while Ledger investigates.
[1] -
Photos and videos posted on X and Threads appear to show a small circuit board tucked under the device's screen.
[1] -
The chip is said to copy whatever the screen shows, including the secret recovery words displayed when the wallet is first set up.
[1] -
A SIM card built into the chip is said to send those words to the attacker over the mobile phone network.
[1] -
With the recovery words, the attacker can then drain the wallet.
[1] -
Reports say more than $86 million in crypto has been taken from hundreds of wallets. Ledger has not given its own figure.
[1] -
Most of the people hit appear to be in Southeast Asia.
[1] -
The Verge reports no sign that Ledger's own systems were broken into, or that wallets bought straight from Ledger are affected.
[1] -
Ledger has published guidance on how owners can check whether their device has been tampered with.
[1]
Who is involved
-
Ledger
a company that makes hardware wallets, small devices that hold the keys to crypto coins away from the internet; it confirmed the hidden chip
-
CryptoBillis
a reseller of Ledger wallets; Ledger asked it to pause all sales
-
Wallet owners in Southeast Asia
the people most of the reported thefts came from
-
The attacker
not yet named; reports say more than $86m has been taken
Where this points
Watch whether Ledger says how many wallets passed through CryptoBillis and how the chips got inside them, which would show whether this is one reseller's stock or something wider.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
A hidden chip in some Ledger wallets is said to copy the secret recovery words shown at setup.
DarkSword's operators rent it out through agents and resellers, Censys found.
An attacker used AI models with the ARTEX tool to break into South Korean banks.
Fake meeting invites now appear in people's calendars beside real appointments.
The rest of the day
7 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
A hacking kit for older iPhones now takes crypto
iVerify, a US phone-security company, reported on Thursday a new version of DarkSword, a hacking kit for iPhones, which it calls P7.
[2] DarkSword was first described in March by Google, iVerify and Lookout.[2] It attacks iPhones running iOS 18.4 to 18.7 through booby-trapped web pages, and it leaked soon after it was made public.[2] P7 copies saved passwords, notes, photos and crypto wallet apps, and asks its operator for new orders every 15 seconds.[2] Why it matters — Censys, a company that scans the internet, found a copy of one operator's server holding the recovery words of 11 victims.
[2] The kit is aimed at iPhones still on older systems, though one operator's server shows work on attacks for iOS 26, the newest.[2] -
03
Fake meetings land straight in calendars
Scammers are sending fake meeting invitations that appear in people's online calendars, such as Google Calendar, the Guardian reports.
[3] Sublime Security, an email-security company, says the scam is still new but growing fast.[3] Calendar apps can add an invitation on their own, so the entry appears even if the email went to spam.[3] The entry holds a link to a fake login page, or a number to ring to cancel a charge that never happened.[3] Why it matters — Some scammers send the invites through real services such as Zoom, so blocking them would also block real meetings, says Max Gannon of Cofense, a security firm.
[3] Luke Wescott of Sublime Security advises setting calendars to accept invites only from known senders.[3] He also advises deleting a suspicious invite rather than declining it, because declining tells the sender the address is in use.[3] -
04
AI bots keep phone scammers talking
Apate, an Australian company, runs about 350,000 AI bots that answer scam calls and messages while pretending to be possible victims, Wired reports.
[4] The bots never fall for the scam, but give the caller enough hope to stay on the line, sometimes for more than two hours.[4] Banks use the system and phone companies support it.[4] Apate says it has gathered more than 250,000 details about fraudsters, such as scam web addresses and the bank accounts used to move stolen money.[4] Why it matters — A minute a scammer spends on a bot is a minute not spent on a real person, says Apate's founder, Dali Kaafar.
[4] Researchers at ETH Zurich, a Swiss university, found that AI-run decoy computers also keep attacking AI programs busy for longer than simpler decoys.[4] -
05
Japan tells ministries and firms to tighten up
Japan's National Cybersecurity Office, set up last year, warned on Friday that attacks on computer systems are rising in number and growing more advanced, AP reports.
[5] Its instructions go to ministries, which pass them to local governments and companies.[5] They cover basics such as updating software, using strong passwords and checking suppliers.[5] A study by the Yomiuri newspaper and Trend Micro, a Tokyo security firm, counts more than 500 attacks so far this year, against 473 last year and 503 in 2024.[5] 202450320254732026 so far500Attacks counted by the Yomiuri newspaper and Trend Micro. This year's bar shows the floor of 'more than 500', and the year is not over. Why it matters — Customers of the Lawson shop chain, the Daiwa Securities brokerage and the BookOff second-hand chain have all had data leaked, and last month a break-in at Times Car reached 6.6 million accounts.
[5] AP says this year is almost certain to set a record.[5] The office also warned that some attackers pretend to be people offering protection against attacks.[5] -
06
Tool used on Korean banks is closed
The Chinese developer of ARTEX, a free AI program built to test a company's defences, said on GitHub on Thursday that it will stop updating it and close its code to the public.
[6] CrowdStrike, a US security company, says ARTEX was used with AI models, including Anthropic's Claude, in recent break-ins at South Korean banks.[7] At least nine Korean banks have reported attacks since late September.[6] The developer, who uses the name Autumn-27, said they oppose illegal use and bear no responsibility for it.[6] Why it matters — Copies made before the change remain, including English and Korean versions built from its code, BleepingComputer reports.
[7] So the tool is still available in the form the attacker used.[7] -
07
Britain's cyber agency turns ten
King Charles III wrote to Britain's National Cyber Security Centre to mark its tenth year, in a letter the centre published on Saturday, the BBC reports.
[8] The centre was set up in 2016 as part of GCHQ, the UK's signals intelligence agency, to defend the country against online attacks.[8] The King wrote that hostile actors keep changing their methods and now use automated tools.[8] The BBC also understands the centre offered help this week to ASOS, the online clothes shop whose app was used to send customers a hackers' message.[8] Why it matters — The ASOS offer is one example of the centre stepping in when a big British company is hit.
[8] The King noted that much of the centre's work cannot be praised in public.[8] -
08
Dubai Police warns AI fakes are harder to spot
Dubai Police has warned that AI is making fake videos and fake voices harder to tell from real ones, The National, a UAE newspaper, reported on Saturday.
[9] The warning comes from a study by the force's Future Foresight Centre.[9] It says these fakes, known as deepfakes, could help criminals pretend to be real people, steal identities and fool the public.[9] Its key finding goes further: people may start to doubt photos, videos and recordings that are real.[9] Why it matters — Police use recordings as evidence in their investigations, so a fake nobody can spot makes that evidence harder to trust, the study says.
[9] It says technology alone will not fix this.[9] It asks for wider public awareness, skills to check where a picture or clip came from, and security agencies that look for new criminal tricks before they spread.[9]
Pulling a tool back cannot reach the copies already out
When a maker stops selling or sharing something, the copies people already hold keep working until each one is found.
The twist
Closing the source stops the next copy. The copies already out there keep working until someone finds each one.
The picture
How it works
- A maker hands out a device or a program
- Copies spread to people the maker never meets
- Something goes wrong, and the maker pulls it back
- Pulling it back stops new copies only
- Each copy already out keeps working until its owner finds it
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
The ARTEX tool closed by its developer
The developer stopped sharing the code, but English and Korean copies built from it are still out there.
-
The DarkSword kit for older iPhones
The kit leaked soon after it was made public, and other criminals now build new versions of it, such as P7.
Where you've seen this
Food recalls
a recall takes a product off the shelves, but the packets already in kitchens stay until people check the label
Withdrawn medicines
a pill taken off the market can sit in home cabinets for years
Leaked photos
deleting the original does not delete the copies other people saved
The catch
It breaks when each copy still checks in with its maker. A phone that installs updates can be fixed from far away, which is why the DarkSword kit is aimed at iPhones still on older systems.
And the whole of it
A wallet bought from a reseller, a bank in Korea and an iPhone left on an old system all depend on a copy its maker can no longer reach. Most of us own a few things like that, such as an old phone or an app that stopped getting updates.
What is really going on
Thieves are going after the secret words that unlock crypto wallets. Reports say a chip hidden in Ledger wallets sold by the reseller CryptoBillis sent those words to an attacker, and a new version of the DarkSword kit copies wallet apps from iPhones on older systems.
Why it works on us — A figure like $86 million from hundreds of wallets travels on its size, though it comes from reports and not from Ledger or any published count.
Who gains
-
Whoever planted the chips in the Ledger wallets
— Reports say more than $86 million has been taken from hundreds of wallets.
[1] -
The operators selling DarkSword
— The control panel Censys found is set up for agents and resellers, so the kit is sold on to other criminals.
[2] -
Apate
— Banks use its system and phone companies support it, so every rise in scam calls is more work for its bots.
[4] -
The developer of ARTEX
— By closing the code, the developer says it bears no responsibility for illegal use.
[6] Copies built from the code stay available all the same.[7]
Who pays
-
CryptoBillis customers in Southeast Asia
— They bought Ledger wallets through a reseller, and most of the reported thefts are from them.
[1] -
Owners of iPhones on older systems
— The new DarkSword version copies their saved passwords, notes, photos and wallet apps.
[2] -
Customers of Korean banks
— The attacks using ARTEX exposed personal and card details at banks including Shinhan, KB Kookmin and Hana.
[7] -
Office workers who live by their calendars
— Blocking invites from services like Zoom would also block real meetings, says Max Gannon of Cofense.
[3]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
How many CryptoBillis wallets carry the hidden chip, and who put it there.
Ledger has confirmed one device and is still investigating. It has not said how many wallets the reseller sold.
[1] -
02
Whether the $86 million figure is right.
It comes from reports gathered by The Verge. Ledger has not given a number of its own.
[1] -
03
Whether wallets from other resellers are affected.
The reports so far point only at CryptoBillis, and Ledger's investigation is not finished.
[1] -
04
Who runs the new P7 version of DarkSword.
Censys describes a Chinese-speaking operation that rents the kit out. The Hacker News says exactly who is behind it is unknown.
[2] -
05
How many iPhones are still on systems the kit can attack.
None of the reports gives a count of phones still running iOS 18.4 to 18.7.
[2] -
06
Whether the leftover copies of ARTEX are being used now.
BleepingComputer says English and Korean copies remain, but the reports do not say whether any has been used since the developer closed it.
[7] -
07
How much Apate's bots actually cut scam losses.
The figures of 350,000 bots and 250,000 details come from the company. Wired tested a demo, not the results.
[4] -
08
How fast calendar scams are really growing.
Sublime Security calls the growth exponential but gave the Guardian no number.
[3] -
09
Whether Japan's attack count is complete.
The figure of more than 500 comes from a study by the Yomiuri newspaper and Trend Micro, not from Japan's government.
[5]
Apate, an Australian company, runs about 350,000 AI bots that answer scam calls and keep the scammers talking, sometimes for more than two hours. Its system has gathered more than 250,000 details about fraudsters, such as the bank accounts they use to move stolen money.
More from Cybersecurity
Across the beats