Warning from Binance Co-Founder
Changpeng Zhao, the co-founder of Binance, has issued a critical warning to cryptocurrency enthusiasts regarding new hardware wallets. His advice comes in light of a significant security breach affecting a vendor in Southeast Asia, which led to an astonishing loss of over $86 million for users. This situation has highlighted an alarming trend where hackers have shifted their tactics from exploiting vulnerabilities in software to physically tampering with devices during shipment.
Advice on Hardware Wallets
Zhao, often referred to as CZ, strongly recommends that users avoid quickly transferring large amounts of cryptocurrency to new wallets or software immediately upon acquisition. He suggests implementing a waiting period of at least two weeks before activating or transferring significant assets to these devices. This interim phase allows investors to stay vigilant and informed about potential cyber threats.
Recent Security Breach
The urgency of this advice was prompted by a recent announcement from Ledger on October 9, which revealed the suspension of sales through its reseller, CryptoBilis. Investigations by on-chain analysts indicated that nearly $87 million was withdrawn from various wallets connected to investors across Southeast Asia, including Malaysia, Indonesia, and the Philippines. The breach involved cybercriminals physically tampering with packages at resellers’ warehouses, exchanging the original setup instructions for fraudulent seed phrases.
Despite the incident, Ledger reassured customers that its core systems — including factory production and its Ledger Live application software — remained secure. The breach was localized to CryptoBilis as a distribution point.
Ledger advised all consumers who purchased devices in the past three months to refrain from activating them. Those with concerns regarding their devices were strongly encouraged to transfer their funds to new wallets without delay.
Growing Vulnerabilities in Cold Storage Security
This incident underscores a growing vulnerability in the sector: as recent months have shown, physical delivery systems have emerged as a critical weakness in cold storage security. In August, Coinkite, the maker of Coldcard wallets, reported that its third-party distributors faced similar breaches. The following month, Trezor disclosed a data breach affecting 80,000 customers in the United States due to a hack of its logistics partner, ShipMonk, which exposed sensitive personal information.
Recommendations for Cryptocurrency Holders
Given these alarming developments, relying on local vendors or marketplaces for hardware wallets is increasingly seen as risky. For significant cryptocurrency holders, it’s advisable to purchase devices directly from manufacturers, have them sent to secure addresses (like PO boxes), and adhere to Zhao’s suggested waiting period before use. This new approach aims to enhance security and minimize risks associated with compromised hardware wallets.