# No hack, no code exploit, Ledger reseller CryptoBilis silently bought for scam Source: https://x.com/BalaiBB/status/2108847529919980021 ## Summary A Chinese company that secretly bought CryptoBilis, an authorized Ledger reseller in Southeast Asia, reportedly soldered spy chips into devices before shipping them, causing $86 million in losses without any hack or code exploit. The chips captured users' private keys during setup, draining hundreds of wallets across Ethereum, Tron and Bitcoin. Ledger has told CryptoBilis to stop sales and told recent buyers not to set up their devices, and Mark Karpelès posted photos of the implant. ## Article they didn’t hack ledger. they didn’t exploit the code. they BOUGHT the company selling you the device. $86 million gone a company called CryptoBilis was an authorized ledger reseller in southeast asia. trusted. legit. sold ledgers for years a random chinese company quietly bought CryptoBilis from its malaysian owner made the original owner sign a confidentiality agreement. he couldn’t tell anyone the company was sold same brand name. same website. same “authorized reseller” badge. but different people behind it now the new owners started opening every ledger device before shipping soldered a tiny spy chip onto the board inside. repackaged it. sealed the box. shipped it the device looked normal. felt normal. worked normal but the spy chip was silently capturing your private keys the moment you set it up your seed phrase was sent to the attacker before you even finished writing it down hundreds of wallets across ethereum tron and bitcoin. all drained the guy who lost $5.3 million said “i did everything right. no leverage. no memecoins. i stored my funds on a hardware wallet like we’re all told to” he was right. he did everything right except his device had a parasite inside it that he couldn’t see ledger has now told CryptoBilis to stop all sales. told recent buyers NOT to set up their devices mark karpelès posted photos of the implant. normal board on top. spy chip below the most dangerous attack in crypto this year wasn’t a line of code it was a business acquisition