Back
Hot right now
Money

Are people really being drained through Ledger wallets? What we can and cannot confirm

The device people buy to escape exchange hacks is under fire. The loudest replies point at the same two weak spots, and past cases back them up.

By Daniel Hayes

A Ledger Nano S hardware wallet, a small USB device used to store crypto keys offline

Photo: Motokoka / Wikimedia Commons, CC BY-SA 4.0

Key points
  • A viral post says Ledger wallets are being drained
  • Readers blame fake resellers and phishing, not the device
  • A five-step check takes two minutes

Update, 10 October 2026: A thread now ties the losses to a Malaysian reseller sold in secret and a Ledger with a hidden modem inside. Read the full timeline.

A hardware wallet is meant to be the vault. Not a bank, not an exchange, just a small device in your drawer that holds the keys to your coins.

Now a post by the news account Watcher.Guru has people asking whether the vault leaks. The replies came fast. "This is actually terrifying if true," wrote one reader. Another wrote: "Literally let's just stop using Ledger."

Here is what we can say. We found no confirmed new breach of Ledger on 9 October 2026. There is no Ledger statement, no report from a major crypto news outlet and no on-chain investigator confirming a new mass drain. Treat the claim as a claim.

Is Ledger hacked right now?

Not as far as anyone has proven. Searches for a new Ledger statement returned nothing dated this week. In its worst past incidents, Ledger said the devices themselves were not the weak point.

That does not mean the reports are made up. People lose coins from wallets every week. The question is how.

Readers under the post have a theory, and it repeats. One asked for "the rest of the story" and wrote that people buy Ledger hardware from unauthorised sources. Another wrote: "Its a reseller, not Ledger itself." A third said it is a phishing link sent by email.

These are reader guesses, not findings. But they match how earlier drains happened.

How do crypto wallets get drained?

A hardware wallet keeps your private keys offline. A thief cannot just break in from the internet. So thieves go after the person instead.

Security reports and Ledger itself have described three routes:

  • Fake or tampered devices. In April 2025, a crypto wallet reseller told reporters that some users had received fake devices built to install malware.
  • Phishing. Fake emails, fake websites and even printed letters ask for your 24-word recovery phrase. Anyone who has that phrase owns your coins.
  • Poisoned software. In December 2023, attackers slipped bad code into a tool that websites used to connect Ledger wallets.

In each case the user or a connected tool was the door, not the chip inside the device.

A Ledger Nano S next to its box, the seal and packaging are what buyers should inspect
A Ledger Nano S and its packaging. Buyers are told to inspect the seal on arrival

Photo: Motokoka / Wikimedia Commons, CC BY-SA 4.0

Every Ledger incident so far, with dates

Ledger has had a rough run. One reader said this is "like the 8th strike." We could not match that exact count, but here is the list we could confirm from news reports.

Date What happened Scale Source
July 2020 Customer data leaked via the Shopify store About 270,000 customers' details The Block, Decrypt
Oct 2020 Phishing campaign hit Ledger owners Ledger said it was investigating The Block, 26 Oct 2020
Dec 2020 Wider data dump published online About 1 million emails Forklog
14 Dec 2023 Connect Kit library poisoned after a former employee was phished Over $500,000 drained, per press reports Fortune, The Block
Apr 2025 Printed letters asking for recovery phrases Ledger confirmed the scam Cryptopolitan
5 Jan 2026 Payment partner Global-e breached, order data exposed Names, contacts, orders. Ledger says no funds touched BleepingComputer, Decrypt

Notice what is missing. In none of these did a thief crack open the device itself, going by Ledger's statements and the press reports above.

The data leaks matter for another reason. Leaked names and addresses make later phishing look real. A letter with your name, your address and Ledger's logo is hard to ignore.

Is self-custody still safe?

This is the argument raging in the replies. One reader wrote that the only time they were drained was from a wallet. Another said "self custody has trust issues." Some joked about buying theirs at a garage sale.

The joke lands because it is close to the truth. A second-hand or odd-source device is the riskiest way to start.

Self-custody moves the risk from a company to you. Exchanges get hacked. Wallets get tricked. We are not telling anyone where to keep their money.

One reader asked, "So-called Lazarus Group again?" We found nothing linking the North Korean hacking group to this claim. It is a guess.

A hardware wallet screen showing a transaction to check before approving
The device screen is the one place that shows what you are really signing

Photo: FlippyFlink / Wikimedia Commons, CC0

How do you tell if your hardware wallet is safe?

Here is the checklist. It takes two minutes and every step maps to a past incident.

  1. Buy direct. Order from the maker's own site or a retailer the maker lists. Never from a marketplace seller, a garage sale or a stranger.
  2. Check the packaging. The box should arrive sealed. A device that arrives already set up, or with a pre-written recovery card, is a red flag.
  3. Write your own 24 words. The device should generate them in front of you. Never type them into a computer, phone, website, email or support chat.
  4. Ignore any message asking for them. Ledger says it will never ask for your recovery phrase by email, QR code, phone or post.
  5. Read the device screen. Confirm the address and amount on the hardware itself before you approve anything.

Add one more habit. Get Ledger Live only from the official site, and type the web address yourself instead of clicking an email link.

What happens next?

Three things to watch. Whether Ledger answers the claim. Whether on-chain trackers tie any drains to one source. And whether the post names real amounts or victims.

Until then, the vault in your drawer is only as strong as your habits. The thieves need your 24 words, and now you know nobody legitimate will ever ask for them.

Sources8
  1. Watcher.Guru on X (9 Oct 2026)
  2. The Block, Ledger investigates phishing scam (26 Oct 2020)
  3. Forklog, Ledger data leak (Dec 2020)
  4. Fortune, Ledger wallets drained (15 Dec 2023)
  5. The Block, Tether freezes exploiter wallet, Ledger gives details (Dec 2023)
  6. Cryptopolitan, physical phishing letters (Apr 2025)
  7. BleepingComputer, Global-e breach (Jan 2026)
  8. Decrypt, Ledger confirms Global-e data breach (Jan 2026)
The Big Fuss Weekly

The week's biggest stories, every Monday

One email. The stories everyone will be talking about, before they do.

Free. One email a week. Unsubscribe anytime.

Keep reading

MoneyBanks are financing a flood of Chinese cars. Here is the riskWorldThree oil shocks at once, and why diesel is the one to fearWorldA bleeding captain opened the cockpit door and saved his plane