OneKey Announces Five Security Upgrades After $92.9M Ledger–CryptoBilis Theft
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- OneKey announces five security upgrades after reports of a $92.9 million theft involving Ledger hardware wallet users.
- The company plans stronger packaging, safer recovery phrase backups, improved hardware protection, and stricter reseller controls.
- Bitquery estimates 311 wallets were affected, while Ledger continues investigating the thefts and their exact cause.
Hardware wallet maker OneKey has announced five security improvements following reports of a $92.9 million cryptocurrency theft involving Ledger devices sold through reseller CryptoBilis. The company plans to strengthen wallet packaging, protect recovery phrases, improve hardware security and tighten reseller controls to prevent similar attacks.
OneKey founder Yishi outlined the changes in an X statement on October 10. His announcement came one day after Ledger publicly confirmed reports of stolen cryptocurrency involving customers who purchased hardware wallets from CryptoBilis in Southeast Asia. Ledger acknowledged the incident on October 9 and asked CryptoBilis to suspend device sales and shipments while it investigated the thefts. However, the company has not confirmed when the unauthorized withdrawals began or how attackers accessed the wallets.
After the recent Ledger incident, I wrote about how hardware implants can steal a recovery phrase without breaking the secure chip, what remains unconfirmed, and the changes we're making at OneKey. https://t.co/e8kfEYbeFa
— Yishi (@ohyishi) October 10, 2026
OneKey Plans Five Security Changes to Protect Hardware Wallet
Yishi explained that hardware wallets can face security risks before reaching customers. Devices pass through factories, warehouses, shipping companies and resellers, creating opportunities for unauthorized modifications. As a result, OneKey plans to introduce stronger packaging protections that customers can verify against factory records. The proposed system will use a unique physical seal to help users identify suspicious packaging.
The company also plans to change how users back up their wallet recovery phrases. Under the new setup process, recovery words will transfer directly to a backup card through an encrypted connection instead of appearing on the wallet screen.
In addition, OneKey wants to encrypt sensitive communications between internal hardware components. The company is also reviewing physical protections that could make unauthorized modifications harder. Meanwhile, OneKey will introduce stricter requirements for authorized resellers. Sellers must report ownership or management changes in advance, or their authorization will become invalid.
Finally, the company plans to publish internal hardware reference photos to help customers and researchers identify unusual modifications. Yishi said OneKey had received no reports of users losing funds in connection with the Ledger incident as of October 10.
Researchers Raise Concerns About Modified Ledger Devices
Yishi also discussed research showing how attackers could secretly modify hardware wallets to capture recovery phrases. Researchers previously examined modified Ledger Nano X devices containing hidden electronic components. These implants could intercept information sent to the screen and transmit sensitive data without the owner’s knowledge.
However, Yishi stressed that researchers had not connected those devices to the CryptoBilis incident. He considers hardware tampering a possible explanation, but the investigation has not established it as the cause. Ledger has also said it has found no indication that its own systems or infrastructure were compromised.
Bitquery Estimates $92.9M Stolen From 311 Crypto Wallets
Meanwhile, blockchain analytics firm Bitquery reported that the suspected theft affected 311 wallets across Tron, Bitcoin, Ethereum, BNB Chain and Polygon. The firm estimated total losses at $92.9 million, up from earlier reports of approximately $86 million. Most losses involved USDT on Tron, followed by Bitcoin holdings. Bitquery also reported that Tether froze around $10 million in stolen USDT. Investigators traced another 1,254 ETH transferred through Tornado Cash, a service used to obscure cryptocurrency transactions.
But Ledger has not independently verified the figures regarding losses or how the hackers gained access to the system. As per OneKey, the consumer should purchase the hardware wallets from the manufacturer itself and also authenticate them.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







