Check where it came from, inspect it closely when it arrives, and never use a recovery phrase you did not generate on the device yourself. If you have any doubt, move your funds to a new wallet set up on a device you trust.
What has been reported about Ledger wallets and CryptoBillis?
The Verge reports that a growing number of Ledger users say their crypto accounts have been emptied. The thefts appear to be linked to tampered hardware sold by CryptoBillis, a company that sells Ledger wallets. According to the publication, Ledger has asked CryptoBillis to stop selling its wallets while it investigates. Ledger has also confirmed that a device belonging to one of the affected users contained something it should not have. The available report does not say exactly what was found. It is also not yet known how many people are affected, how much has been taken, or how the devices were altered. This guide does not try to fill in those gaps. It explains how tampering works in general and what buyers can do to protect themselves.
What is a hardware wallet, and why does tampering matter?
A hardware wallet is a small physical device that stores the private keys controlling your cryptocurrency. Its job is to keep those keys away from internet-connected computers and phones, which are easier to attack. You approve a transaction on the device, and the keys never leave it. That design only works if the device itself can be trusted. If someone has changed it before it reaches you, whether through its hardware, its software or the materials packed with it, the protection disappears. You could believe your funds are safe offline when someone else already has the means to move them. This is why where a device comes from matters as much as how well it is built. A product with a strong design can still be compromised somewhere between the factory and the buyer.
How could a tampered device lead to stolen funds?
There are several general ways tampering can work. It is not known which, if any, applies to the reported Ledger cases. One common scam involves a scratch card or printed sheet included in the box that shows a “pre-set” recovery phrase. The attacker already has a copy of that phrase, so any funds sent to the wallet can be taken. Another possibility is physical modification, where extra components are added to capture or send out secret information. A third is altered software that behaves differently from the genuine version. In every case, the result is the same: someone other than the owner gets the information needed to control the wallet. Thefts like this can happen long after setup, once enough money has built up to make them worthwhile.
Does this mean Ledger devices are unsafe?
The report points to devices sold through one particular seller, not to a flaw in every Ledger product. Supply-chain tampering is a risk for hardware wallets in general, whatever the brand, because each device passes through several hands before it reaches the buyer. That said, the investigation is not finished and its results have not been published, so firm conclusions would be premature. If you own a Ledger device bought directly from the manufacturer, nothing in the available reporting suggests that it has been affected. If you bought one from a third party, especially the seller named in the reports, it makes sense to check it carefully. Watch for official updates from Ledger rather than relying on social media posts, which may be inaccurate or even part of a scam.
Where should I buy a hardware wallet?
The safest option is usually to buy directly from the manufacturer’s official website. The next best is a reseller the manufacturer lists as authorised on its own site. Even authorised channels are not a guarantee, as this case shows, but they reduce the number of people who handle the device. Avoid second-hand devices, auction listings and marketplace sellers you cannot verify, however good the price looks. A discount is not worth the risk when the device will guard your savings. Type the manufacturer’s address into your browser yourself rather than clicking links in adverts or emails, because phishing sites often copy official shops. Keep your order confirmation and packaging until you have finished setting up and checking the device, in case you need to report a problem.
What warning signs should I look for when a device arrives?
Look over the packaging before you open it. Damaged seals, signs of resealing, or a box that looks already opened deserve suspicion. Inside, the most important red flag is any card, leaflet or sticker that gives you a recovery phrase or PIN. A genuine hardware wallet generates its recovery phrase on the device during setup, and the manufacturer never supplies one in advance. Be wary of printed instructions telling you to visit an unfamiliar website or install unusual software. Note anything strange about the device itself, such as loose casing, visible tool marks or a device that appears to be set up already. If something feels wrong, stop. Do not send funds to it, and contact the manufacturer’s official support through its website.
How do I check that a Ledger device is genuine?
Ledger’s official companion app includes a check designed to confirm that the device is authentic when you connect it. Install the app only from Ledger’s official website or a trusted app store, then follow its setup steps and make sure the check completes. Set the device up as new and write down the recovery phrase it displays. If the device asks you to restore from a phrase you did not create, or appears to have been initialised already, treat that as a serious warning. Keep in mind that a software check cannot rule out every kind of physical alteration, and it is not yet known whether the reported tampering would pass such a check. For that reason, buying from a trusted source is still the first line of defence.
I bought from the named reseller. What should I do now?
Act early rather than waiting for the investigation to finish. Get a replacement device from a source you trust, ideally directly from the manufacturer. Set it up as a new wallet, generate a fresh recovery phrase on the device and record it securely. Then transfer your funds from the old wallet to addresses created by the new one. Restoring your existing recovery phrase on the new device does not help, because if that phrase has been exposed, the attacker can still use it. Once the transfer is complete, stop using the old device. Contact Ledger’s official support to report your purchase, and keep your receipts and packaging. Be careful of anyone who contacts you offering to “recover” or “secure” your funds. Real support staff will never ask for your recovery phrase.
How should I store my recovery phrase safely?
Your recovery phrase is the master key to your wallet. Anyone who has it can take your funds without the device. Write it down by hand on paper or a durable backup made for this purpose, and keep it somewhere private and protected from fire and water. Never photograph it, type it into a phone or computer, store it in cloud notes or email it to yourself. Never enter it on a website or give it to someone claiming to be from support. Some people keep copies in two separate secure places to guard against loss. Whatever you choose, the phrase should exist only in a form you physically control. This habit protects you against many threats besides tampered hardware, including phishing and malware.
What is still not known about this case?
Many details are still unclear. Based on the available report, it is not known exactly what was found inside the affected device, how many devices may have been tampered with, or over what period. It is also unclear whether the seller was involved, was deceived itself or was used without its knowledge. Ledger has not published the results of its investigation, and nothing here should be read as a finding of fault against any company. As more details come out, the practical advice may change, for example if specific batches or warning signs are identified. Until then, the general principles still apply. Buy from trusted sources, inspect what arrives, generate your own recovery phrase and move your funds if you have any reason to doubt your device.
Sources and further reading
- The Verge: the original report on suspected tampering and the request to pause sales
- Ledger: official support pages and security guidance for device owners
- General consumer guidance on cryptocurrency security from financial regulators
- Independent security research on hardware wallet supply-chain risks
Surfaced from the rss:verge signal “crypto wallet tampering reports”. AI-assisted draft, editorially reviewed.

