I wrote an article a few weeks ago about buying a hardware wallet, and the central image was a stranger fastening a collar on your cat that was already adjusted to her size. The question that image is designed to provoke is: how did it fit before you ever handed her over?
This week that stopped being a metaphor.
1. What Is Actually Alleged
Being precise, because the story is still moving as I write this (10 October 2026):
Hundreds of wallets have reportedly been drained, with losses estimated in the region of $86 million and climbing across several chains. Ledger has said it is investigating potential device tampering linked to a reseller in Southeast Asia, and has paused sales through resellers while it looks. Tether has moved to freeze some of the stolen USDT.
What has not been established: any break in Ledger's cryptography, firmware or secure element. There is no confirmed device-wide exploit. The leading explanation is a supply-chain attack on devices that passed through one distribution channel.
Treat all of that as an ongoing investigation rather than a settled account — including anything I say about it here.
2. A Supply-Chain Attack Breaks Nothing
Here's what makes this category of attack so effective, and why it deserves understanding rather than panic.
The attacker does not need to defeat any security. They need to know the seed before you do.
Generate a recovery phrase yourself. Set up the device with it. Repackage it so it looks untouched. Sell it, ideally slightly below the normal price. Then wait — weeks, months — while the buyer does everything right: strong PIN, careful backup, no phishing links, never types the phrase anywhere. None of it matters, because the secret was never theirs. When the balance is worth taking, it gets taken, all at once.
No cryptography was broken. The device worked perfectly. It just wasn't working only for you.
3. The Nuance Everyone Gets Wrong
This is the part worth sharing with anyone who owns a hardware wallet.
The "genuine device" check does not protect against this. Cryptographic attestation proves the hardware is a real, factory-made device from that manufacturer. It says nothing whatsoever about whether somebody else has already seen a seed on it.
A genuine Ledger, set up by a thief, passes the genuine check. Of course it does — it is genuine.
What protects you is not authenticity. It's freshness of the secret: the device must arrive with no wallet on it, and the phrase must be generated by that device, in front of you, and written down by you. If a phrase existed before you created it, every other protection in the stack is decoration.
4. If You Bought From a Reseller
Not advice about this specific case, which is still unfolding — general procedure for anyone with a device of uncertain provenance:
- Assume the seed is compromised. Not "probably fine". Assume.
- Move the funds now, to a wallet whose seed was generated on a device you bought direct from the manufacturer, or on a reputable software wallet in the meantime. Speed matters more than elegance here.
- Never reuse that seed for anything, ever, including small amounts.
- Keep the device and the packaging. It's evidence.
- Report it — to the manufacturer, to the marketplace, and to your local authorities. Patterns matter even when recovery doesn't.
- Assume anyone contacting you to "help recover" is a second thief. Without exception.
5. Two Uncomfortable Observations
The freeze cuts both ways. Part of the stolen value was in USDT, and the issuer can freeze it. That's genuinely good for these victims and it's also a clear demonstration of what a centrally-issued asset is: someone can edit your balance. Bitcoin offers no such rescue, by design. You cannot have both properties, and this week shows exactly what each one costs.
Self-custody moved the risk, it didn't remove it. Everything I've written in this series about holding your own keys remains true, and this is the honest other half: taking custody means taking the provenance problem too. An exchange has a compliance department and an insurance policy. You have the discipline to buy direct and verify your own setup. Both are real work. Only one of them is yours.
The Point
The collar fit before you handed her over. That's the whole story — not a lock being picked, not a clever exploit, just somebody who had the measurements first and was willing to wait.
The rule hasn't changed and didn't need this week to be true. Buy direct from the manufacturer. Never used, never a reseller, never a bargain. Generate the phrase yourself, on the device, with nobody watching.
Authenticity isn't the test. Being the first person to see the secret is. 🐾⚡