Ledger nearly 90 million loss: Tether steps in

CN
1 hour ago

On October 9, 2026, the on-chain security tracking platform MistTrack announced an on-chain security incident related to the hardware wallet provider Ledger, with preliminary estimates of losses approaching $90 million. This figure currently comes from a single source's preliminary assessment and has not yet been officially confirmed. More shockingly, MistTrack pointed out that Tether has begun freezing substantial amounts of USDT from multiple addresses related to the incident on chains such as Ethereum. The issuer intervened almost simultaneously after the incident, directly locking some tokens that were originally considered "self-custodied assets" on-chain. This incident, which has not disclosed specific attack vectors, the scale of affected users, or asset composition, coincides with a time when the entire industry is highly sensitive to self-custody security, with Ledger—once regarded as a symbol of security—once again embroiled in a security controversy, and Tether's freezing action highlighting the reality of intervention rights. The combination of both leads to a rare trust shock against the long-cherished narrative that "only you can move your coins."

The Myth of Hardware Wallets Shattered

In the narrative where self-custody is revered as "the only correct answer," Ledger has consistently stood in the most prominent position. As a leading hardware wallet provider, it is seen as a key tool to avoid the risks of centralized custody, and for many years it has been the default option for "keeping assets in your own custody." However, the briefings have cautioned that Ledger has previously become the focus of security incidents and controversies multiple times. These cracks have not destroyed its brand, but they have planted an implicit premise in the minds of users—that so-called offline devices and physical separation do not inherently mean absolute security.

This time, MistTrack directly marked an on-chain security incident related to Ledger, with preliminary statistics estimating losses close to $90 million. Although this is initial data from a single source and has not been officially confirmed, the attack vector, vulnerability type, number of affected users, and specific asset composition are completely unknown. The number itself is enough to rewrite risk perception: users do not care whether the problem lies with software, hardware, or peripheral processes; they will juxtapose "Ledger once again involved in a security incident" and "$90 million loss," thereby questioning the reliability of the hardware wallet myth. In the absence of technical details, this incident with losses nearing $90 million primarily shakes the collective belief that "self-custody equals security" built around Ledger.

The Double-Edged Sword of Tether Freezing Addresses

As the figure of "$90 million loss" began to shake user confidence, the issuer was already taking action on-chain. According to MistTrack, Tether is freezing large amounts of USDT from multiple addresses related to the Ledger incident. As a leading issuer of a dollar-pegged token, Tether has reserved the right to freeze specific addresses in its contracts on chains like Ethereum. Once it identifies addresses suspected of harboring stolen funds, it can directly mark the USDT within them as non-transferable and unusable. In recent years, Tether has repeatedly employed similar operations in coordination with recovery efforts during hack and theft incidents, forming a habitual path of "technical means + on-chain blacklists."

From the victims' perspective, this is a sharp tool: in the early stages where the attack method and fund path have not been fully clarified, freezing the USDT in the involved addresses can immediately weaken the attacker’s usable chips and buy time for subsequent negotiations for returns or judicial intervention. However, while swinging this sword against the attacker, it also exacerbates the debate over the intervenability of centralized dollar tokens—this same set of powers can be viewed as a "safety net" in hacker incidents, while in other scenarios, it may be understood as a capacity for scrutiny over on-chain assets. Tether's rapid intervention in the Ledger incident brings this tension to the forefront: users want a "last line of defense" on one hand but must also accept the reality that their on-chain assets are not absolutely beyond the influence of the issuer under any circumstances.

On-Chain Tracking Comes into Play

On October 9, 2026, the first to bring this incident to the public eye was the on-chain security tracking platform MistTrack. It published a disclosure that it had monitored abnormal fund flows related to Ledger, with current on-chain statistics indicating losses close to $90 million. This number, along with the list of involved addresses, has so far come almost entirely from MistTrack’s single source, representing preliminary statistics based on on-chain indications, rather than any official confirmation. Some affected users proactively contacted the MistTrack team upon seeing the disclosure, hoping to leverage its tracking capabilities to clarify the flow of funds; the team is also following up on a case-by-case basis.

MistTrack’s involvement provided this event, which was originally shrouded in the fog of technical details, with at least observable transparency at the level of fund movement—which addresses concentrated receiving funds over a short period, which assets were rapidly split or transferred across addresses, all can be marked and continuously tracked. However, this on-chain tracking naturally has boundaries: it can reconstruct the transfer map between addresses, but not the real identity of the attacker, specific attack vectors, or legal determinations of responsibility. More importantly, with no other authoritative channels publicly quantifying losses or attack paths aside from MistTrack, all judgments regarding the scale of losses and scope of involvement can only be regarded as work hypotheses in progress, rather than conclusions.

Collision of Self-Custody Belief and Centralized Scrutiny

In recent years, the cryptocurrency industry has repeatedly reinforced a simple slogan: as long as you hold the private key, the assets truly belong to you. Hardware wallets like Ledger are thus regarded as physical totems of the self-custody narrative—they reclaim the keys from exchanges and software service providers, allowing users to sign on local devices. However, the on-chain security incident related to Ledger disclosed by MistTrack on October 9 reminds the market that self-custody does not guarantee security simply by staying away from centralized platforms; the tools that carry the private keys can also become new sources of risk in the trust chain if they suffer from design flaws, supply chain issues, or code vulnerabilities. Currently, there is no evidence pointing to specific attack links, meaning discussions can only remain at the structural level: when self-custody practices heavily rely on a few hardware and software manufacturers, "decentralized control" itself carries centralized technical premises.

Parallel to this is Tether's actions on freezing addresses. MistTrack disclosed that substantial amounts of USDT are being frozen by the issuer from multiple addresses related to this incident. This clearly demonstrates on a technical level that even if users possess private keys, as long as the assets are issued by some centralized institution as accounting tokens, the right to dispose of these assets is always partially held by the issuer. In the past, Tether’s practice of freezing addresses to aid recovery has become a routine. This time, it once again brings the issue of "intervenability" to the center of public opinion. On one side lies the reality risk that self-custody tools may fail, while on the other side is the technical capability of the issuer to directly alter the status of assets on-chain. The combination of both forces users to reassess their so-called "control over assets": are they truly trusting a decentralized protocol, or are they simultaneously betting on hardware manufacturers, issuing institutions, and on-chain scrutiny standards? This incident is transforming this originally abstract inquiry into a concrete choice facing every user.

What Signals to Watch After This Incident

What truly deserves attention next are several public signals. First is Ledger itself: whether it provides investigative conclusions in the short term, explains the attack vector, publicly discloses the scale of affected users and asset composition, and rolls out targeted security rectification plans will directly determine whether the entire hardware wallet sector can repair the trust gap. Second is Tether’s actions on-chain: at present, it is only known that Tether is freezing several addresses related to this case; the specifics of the frozen amounts, number of addresses, duration of freezing, and whether subsequent announcements will clarify cooperation with law enforcement will all affect the potential recovery of stolen assets, as well as shape the market's understanding of the boundaries of such centralized intervention tools. Finally, continuous attention should be paid to whether the subsequent on-chain data disclosed by MistTrack and the official responses form a closed loop; in a phase where key details are still largely missing, any conclusions regarding hardware self-custody security or the scrutiny risks associated with dollar-pegged tokens must be dynamically adjusted in line with new on-chain evidence and explanations from the project parties.

Join our community to discuss together and become stronger together!
Exclusive Hyperliquid benefits for AiCoin: https://app.hyperliquid.xyz/join/AICOIN88
Exclusive Aster benefits for AiCoin: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink