Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Event Contracts
New
Predict price moves and seize opportunities
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
Stock CFD Derivatives
US Stocks
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Korean Stocks
SK Hynix
Real Korean stocks and top assets
JP Stocks
Top Japanese stocks, all in one place
Stock Futures
High leverage, 24/7 trading
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Pre-IPOs
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
#Ledger事件损失近9000万
1. The $90M Ledger Supply Chain Compromise: How Much Security Work Remains?
The reported losses serve as a major wake-up call for the entire crypto industry. On October 9, 2026, a blockchain analytics firm estimated that approximately $92.9 million had been drained from 311 wallets associated with purchased Ledger devices. This figure is an estimate for research purposes, not a final, independently verified total loss.
The recent $90M+ exploit involving tampered Ledger hardware wallets—linked to third-party reseller distribution and hardware implants—highlights a fundamental shift in crypto threat vectors. As on-chain smart contracts and cryptographic signing standards have matured, attackers are increasingly targeting physical distribution pipelines, supply chains, and client-side dependencies rather than attempting to crack open core cryptography.
Where crypto security still falls short:
* Physical Supply-Chain Integrity: Hardware wallets are sold through complex global reseller networks. Guaranteeing cryptographic "Genuine Checks" on devices that pass through unauthorized or compromised intermediate vendors remains an unsolved physical attack surface.
* Blind Signing & Verification Gaps: Users frequently approve transactions without full visibility into exact parameters on-screen, exposing them to phishing and malicious payload injections.
* Over-Reliance on Single-Point Self-Custody: Multi-signature setups (Multi-Sig), Account Abstraction and Threshold Signature Schemes are still underutilized by average retail users, leaving seed phrase extraction or single device compromises catastrophic.
This incident represents one of the most critical security events in the hardware wallet space. While Ledger’s core infrastructure remains uncompromised, the scale of the drain (~$90–$93M across 300+ wallets) exposes severe structural risks in physical supply chains and distribution networks.
Areas where the industry still needs to strengthen defenses:
Supply chain verification: Tamper-evident packaging, device authentication, and more rigorous reseller vetting.
Safer wallet setup: Clear warnings and verification steps before users transfer significant funds.
Transaction protection: Multi-signature wallets, spending limits, and independent transaction checks for larger assets.
Incident response: Faster coordination among wallet manufacturers, exchanges, blockchain researchers, and stablecoin issuers.
What users should do: Anyone who purchased a Ledger from the vendor mentioned in the reports should follow Ledger's current security guidelines. If the device has already been initialized, it may be necessary to transfer funds to a trusted, verified signer using a newly generated recovery phrase. Never enter your existing recovery phrase into a website or share it with support staff.
The broader lesson is that self-custody requires more than just owning a hardware wallet. Security must encompass the entire process, from production to final processing.
1. Key Analysis of the Incident
* Supply Chain Interception: The evidence—specifically automated drains acting on pre-established private keys across hundreds of wallets—strongly points to pre-tampered devices or intercepted supply chains. Reports indicating custom hardware implants or modified firmware capable of covertly exfiltrating seed phrases bypass traditional software-level checks (like Ledger’s "Genuine Check").
auditing.
3. Actionable Recommendations for Users
If you or anyone in your network purchased a device through localized third-party vendors recently:
1. Immediate Asset Migration: If you activated a device purchased through this distributor within the past 90–120 days, immediately transfer all funds to a safe, trusted location (e.g., a non-custodial software wallet set up on a secure, clean machine, or a separate factory-direct hardware wallet).
2. Do Not Activate Unused Devices: If you received a device from this distributor that has not yet been set up, do not unbox or power it on.
3. Verify Generation of Seed Phrases: Never use pre-printed recovery phrases or cards provided inside packaging. Ensure the device itself generates a completely new seed phrase upon initial setup.
4. Source Directly: Purchase self-custody hardware directly from the manufacturer whenever possible to shorten the supply chain logistics chain.
* Single Point of Failure in Authorized Resellers: Buying from authorized resellers was previously considered equivalent to buying direct. This attack demonstrates that localized third-party distributors can become compromised hubs, whether through internal bad actors or intercepted transit logistics.
* Automated Exploitation: On-chain forensic data shows the attacker conducted multi-chain test runs weeks in advance. Once initialized, automated scripts executed sweeping batch transactions within seconds, proving the attacker held full seed phrase access before users even funded their wallets.
2. Practical Security Assessment
Tampered Hardware Devices Severe (Direct key exposure) Reseller sales halted; users advised to migrate.
Ledger Hardware/Firmware Core Low (No global breach) No direct evidence of core Ledger system breach.
Centralized Secondary Sales High Third-party distribution models require tighter cryptographic
My take: this is a serious warning that hardware-wallet security depends on the entire supply chain, not just the device manufacturer. If the reported losses are linked to tampered devices, the incident exposes a major weakness in the idea that buying a hardware wallet automatically makes your crypto safe.
$MU $NVDA $TSLA $SPCX