Ledger implant exploit reportedly spreads to Europe after $93.4 million in losses from Asian reseller
A tampered Ledger attack that has already seen an estimated $93.4 million taken from Asian hardware wallet users, has reportedly spread to Europe.
X user Johannes has presented photographs of a tampered Ledger he said he purchased two weeks ago from the European consumer electronics chain MediaMarkt. The implant inside appears to be an earlier version of the one found linked to CryptoBilis shipped devices in Asia, and no funds have been taken.
“Either the device didn’t work, or they were waiting for a more widespread usage of the compromised devices,” he said. Former Mt Gox CEO Mark Karpeles, whose investigations into the tampered Asian Ledgers helped bring the problem to light, said the antenna in the device says it is the “Eurasian version” suggesting separate versions of the implant have been sent to regions that use different mobile frequencies. Ledger has not confirmed the reported European device is part of the same attack.

“PSA the ledger incident isn’t limited to Asia,” wrote European X user Johannes. Source: Johannes.
The sophisticated attack hit Ledger devices in Asia late last week, after devices from the official reseller CryptoBilis — which had recently been sold to a new owner — were found to be modified in a way that apparently enable attackers to read the seed phrase and steal funds even as though the device is still able to pass authenticity checks.
Ledger has asked CryptoBilis to suspend sales and shipments of its devices as a precaution and advised customers who had purchased devices from the reseller within the past 90 days to consider transferring their assets to a new Ledger. “The volume of impacted devices is limited,” it said in its most recent update today.
CryptoBilis is listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines. Cybersecurity outlet Yfarmx estimated the losses at $93.4 million across 471 addresses, but this figure has not been confirmed by Ledger.
Security firm uncovers XRP minting bug
Security firm Veria Labs has been paid a $250,000 bug bounty for uncovering an overflow bug hidden in XRP’s code since 2015. It claims that a single transaction could have printed trillions of XRP out of thin air.
The bug has been patched and there is no evidence it had ever been exploited.
Cayden Liao, Veria Labs security co-founder, wrote on X that its AI agent had combed through rippled, the software that runs the XRP Ledger and found two low severity bugs. It worked out how to create a much larger exploit by using them in conjunction. Liao said that just one exploit transaction could have created more than 18 trillion XRP, which is 184 times greater than the total supply.
“This puts the full $94B at risk, more than 60 times the largest crypto hack on record,” he wrote, referring to XRP’s entire market cap. “We suspect one reason nobody caught this vulnerability is that it chains together two bugs that would be low severity on their own.” The bugs were reported on September 22 and RippleX patched them three days later.

Source: Cayden Liao
Vitalik Buterin backs crypto ‘bunker mode’ amid rapid AI math advances
Ethereum co-founder Vitalik Buterin has backed researcher Justin Drake’s warning that advances in artificial intelligence could undermine the cryptography used in today’s blockchains before quantum computers do.
“I don’t recommend anyone scramble to move their funds to new wallets today,” Buterin wrote. “But we should take the risks to cryptography from AI-accelerated math seriously.”
Drake urged the industry to prepare for “bunker mode” in light of OpenAI releasing hundreds of new mathematical findings that humans have been unable to solve. None of the findings related to cryptography, but the potential for AI agents to uncover new insights into the mathematical structure behind elliptic curve cryptography or lattice based cryptography has the core Ethereum team worried.
The concerns have been criticized by other projects and analysts as fear mongering, with critics saying there is no evidence AI agents are anywhere near breaking cryptography. But then again, there wasn’t a lot of evidence a new AI model was about to one shot the solution to hundreds of other unsolvable problems either.

Samsung Wallet to add USDC transfers for US Galaxy users in October
Samsung plans to introduce USDC transfers to the Samsung Wallet payment app for 82 million eligible US Galaxy users in the last week of October.
The feature will let users send USDC to compatible crypto wallets internationally and transfer money to eligible bank accounts in more than 60 countries, where recipients can receive funds in their local currency. Users must complete identity verification to access the service.
Bastion will provide stablecoin account and payment infrastructure, with Coinbase serving as a…
cointelegraph.com
