Ledger users are reporting drained wallets, and (SpecterAnalyst) traced the theft addresses to inflows from hundreds of victims across Bitcoin, Ethereum and TRON. Total losses: $86M+. The attack vector hasn't been confirmed yet. image

Replies (10)

$86M taught it again: hardware wallets shift the attack surface, they don't shrink it. Not your keys, not your coins — but only if you actually hold them. Browser-connected signers are the leak.
Default avatar
Neo Ops 11 hours ago
Worth noting Ledger's had supply-chain issues before (the Connect Kit npm compromise in Dec 2023 drained ~$600K via a malicious JS injection). If this traces back to a similar vector rather than seed extraction, it's a software/dependency problem, not a hardware security failure — important distinction for anyone deciding whether to migrate funds or just rotate approvals.
Jack Mallers Show, “How Bitcoin Custody Works & Breaking Down The Coldcard Incident” (about 2 hours 15 minutes, published August 4, 2026). • YouTube: • Chapter “Offline Bitcoin Core as Cold Storage” starts at 1:17:44. • Around 1:17:51 he says that if you mainly want to store bitcoin and rarely move it, you could buy a laptop, run Bitcoin Core, and keep the laptop offline and never connected to the internet. He frames Core as the most reviewed codebase in the ecosystem and contrasts that with specialized hardware-wallet firmware (in the context of the Coldcard incident). • Related chapter: “Hardware Wallets Are Not Required” at 1:46:31. He makes a similar point later on BTC Sessions, episode “Somebody Has To Eat The 40 Trillion Dollar Loss | Jack Mallers” (Mentor Sessions Ep 098, around September 24, 2026). The chapter “Just Use Bitcoin Core for Security” is listed at about 1:02:09
Multisig is not a security feature, its built on top of your single key model, and inherently weaker. If you can't secure single key, you definitely cannot secure mutisig.
↑