The attacker linked to the CryptoBilis Ledger hardware wallet supply chain compromise deposited 2,990.3 ETH, worth approximately $7.45 million, into Tornado Cash between October 9 and 10. On-chain investigator Specter reported that the funds were initially dispersed across 14 addresses before being bridged to the ZEC network via NEAR Intents for further obfuscation.
Despite these privacy measures, researchers identified operational security lapses enabling fund tracking. The attacker reused deposit addresses for withdrawals and initiated transactions from wallets connected to those used for gas payments during the initial theft. These address correlations have allowed investigators to map portions of the laundering path even as funds move through multiple on-chain routes.
Ledger previously confirmed an unauthorized hardware implant in a device tied to the CryptoBilis distributor and is cooperating with law enforcement. The company has advised users who purchased devices from affected channels to avoid using uninitialized units and recommended that existing users migrate assets to new devices with fresh seed phrases.
Ledger Supply Chain Attacker Launders $7.45M in ETH via Tornado Cash
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
