Ledger has confirmed a hardware implant as it investigates losses estimated above $86 million tied to reseller CryptoBilis, and is urging affected users to re-seed, as security researchers warn that a fake Ledger website and application are appearing prominently in Google search results. The Crypto Times reported the confirmation on Sunday. Crypto.news reported that the fake site and app are built to collect 24-word recovery phrases, the master backup that can regenerate a wallet without the physical device. The warning follows a September investigation by cybersecurity firm Zscaler that documented a separate campaign using fraudulent Google ads for the same purpose.
What affected users should do now
Ledger's guidance splits users in two groups. Customers who bought a device through CryptoBilis in the 90 days before the warning and have not set it up should not start setup. Those who already set up such a device should consider moving assets to a new Ledger signer with a newly generated recovery seed, following Ledger's official instructions. The on-chain picture keeps growing. Bitquery counts $92.9 million drained from 311 wallets across TRON, Bitcoin, Ethereum, BNB Chain and Polygon, with dozens of wallets signing the same request within seconds after two weeks of test runs, a pattern that points to one thief holding the keys. Tether froze about $10 million of stolen USDT across 37 addresses within two hours of the first public post, while about 1,254 ETH moved into Tornado Cash in three batches of roughly 400 ETH. A freeze stops coins moving; it does not return them to victims, though Tether can later destroy blocked coins and reissue them. For victims, the practical steps are unchanged: file a police report, preserve transaction IDs, wallet addresses, screenshots and communications, and treat anyone offering recovery for an upfront fee, or anyone asking for a seed phrase, as a scammer. Ledger will never ask for a recovery phrase. See our earlier report on the CryptoBilis drains for the full timeline.