Ledger Users Lose $86M in Multi-Blockchain Exploit
More than $86 million in cryptocurrency has been drained from wallets linked to Ledger users across Ethereum, TRON, and Bitcoin, marking one of the largest hardware wallet security incidents on record.
More than $86 million in cryptocurrency has been drained from wallets linked to Ledger users across Ethereum, TRON, and Bitcoin, marking one of the largest hardware wallet security incidents on record. Blockchain security firm Specter traced theft addresses across the three chains, while the Security Alliance directed affected users to contact SEAL 911, its emergency response service for crypto victims.
The attack's method remains unknown. No official disclosure from Ledger or any security researcher has confirmed how funds were extracted, and that ambiguity is itself significant. A simultaneous drain across three architecturally distinct blockchains points toward either a compromised seed phrase recovery mechanism or a vulnerability in a shared software layer, rather than a flaw in any single chain's protocol. Seed phrases, the 12- or 24-word recovery strings that underpin nearly all hardware wallets, would give an attacker complete access to a victim's funds on every chain simultaneously.
Specter's cross-chain tracing and the Security Alliance's public call for victims to report through SEAL 911 suggest the incident may still be unfolding or that the full scope of losses has not yet been determined. The $86 million figure is what has been traced so far; the actual total could be higher.
Ledger has not released a public statement identifying the root cause or confirming the scale of the losses as of publication. That silence will amplify pressure on the company. Ledger serves millions of users globally and is the dominant hardware wallet manufacturer by market share. Its devices are widely treated as the gold standard for self-custody, the practice of holding private keys without relying on an exchange or custodian.
The incident echoes past Ledger security failures. In 2020, a data breach exposed the personal information of roughly 270,000 customers, including names, phone numbers, and physical addresses. That breach did not directly compromise private keys, but it fueled targeted phishing campaigns that caused real financial losses for affected users. The critical question now is whether this week's $86 million drain reflects a similar social-engineering campaign, a supply chain compromise, or something more technically severe.
Hardware wallets do remain meaningfully safer than hot wallets or centralized exchange accounts for long-term storage. Private keys never leave the device in plaintext, and most attack vectors require physical access or user interaction. But that security model depends entirely on the integrity of the seed phrase backup process. If users were deceived into entering their seed phrases on a fake Ledger interface, or if a malicious firmware update was pushed to devices, the hardware security guarantee collapses regardless of how well the chip itself is designed.
The multi-chain nature of this exploit warrants the most scrutiny. Bitcoin, Ethereum, and TRON use different cryptographic implementations and signing schemes. Draining all three simultaneously is not something a chain-specific vulnerability could accomplish. That scope narrows the plausible attack vectors considerably and raises the stakes for whatever technical post-mortem eventually emerges.
For Ledger users who have not been affected, security researchers generally advise against moving funds or entering seed phrases anywhere until the attack vector is confirmed. Interacting with a compromised interface while trying to secure funds has historically been how phishing campaigns capture additional victims in the aftermath of a high-profile incident.
The Security Alliance's SEAL 911 service, reachable via the organization's official channels, is coordinating victim response. Users who believe their wallets have been drained should document transaction hashes and affected addresses before taking any further action.





