Ledger is investigating reports of lost funds from customers in Southeast Asia who bought devices through reseller CryptoBilis. It has asked the reseller to pause sales and shipments. Customers who bought there in the past 90 days are being told not to set up unused devices; those who already did are being advised to consider moving their assets to a new signer with a new seed. An on-chain analyst estimates losses above $86 million, though Ledger has not confirmed that amount or the cause.
The mechanism matters. A compromised device, a seed placed in the box before purchase and a seed generated badly by the device are different problems. We do not yet know which, if any, explains these losses. But this incident follows the Coldcard seed-generation failure and puts the same decision in focus: who do you trust to create the secret that controls your bitcoin?
For serious self-custody, I am increasingly uncomfortable outsourcing entropy generation to a device and simply accepting the words it displays. That is an enormous amount of trust to place in hardware, firmware and the path the device took to reach you. SeedSigner and other methods of generating your own entropy look more and more like the right approach. You still have to execute carefully and verify your setup; rolling dice does not save you from mishandling the seed afterward. But I want to own the randomness at the beginning, because everything else depends on it.
Happy Friday.