Ledger Nano X Was Offline for Over Six Months — Yet My BTC Was Still Transferred Out Ledger Could Not Tell Me Which Device Signed the Transaction
0
0
**⚠️ Quick Summary — For Those Who Don’t Want to Read the Full St**ory
I originally moved my Bitcoin to a Ledger Nano X because I wanted a long-term, offline storage solution.
My 24-word Secret Recovery Phrase:
Was never photographed
Was never stored on my phone
Was never stored on my computer
Was never saved in iCloud, Notes, or a password manager
Was never entered into any website
Was never shared with anyone
Was kept in a private physical location known only to me — not even my family knew where it was
The last time I used my Ledger was around **December 2025**.
After that, it remained disconnected and unused for more than six months.
However, on **May 27, 2026 at 22:35**, my Bitcoin account made an outgoing transaction that I never authorized:
**0.02894506 BTC**
I had trusted that long-term cold storage meant I could simply leave the wallet alone.
I did not discover what had happened until **September 22, 2026**, when I opened Ledger Wallet again and found that my Bitcoin balance was zero.
After contacting Ledger Support, they confirmed that the transaction had been validly signed with the private keys controlling my Bitcoin account.
However, they also explicitly told me that:
**Ledger cannot determine whether the transaction was signed by my physical Nano X, or by another device or wallet using the same private keys.**
They also cannot prove the actual cause of the incident.
So far, I have:
Opened Ledger Support Case **#00281295**
Formally filed a police report in Taiwan
Received blockchain tracing information from Ledger
Been told by Ledger that the destination address has blockchain connections to **HitBTC** and **Bridgers DEX**
I am **not claiming that Ledger itself was definitely hacked**.
But this incident has changed the way I think about cold wallets.
A cold wallet does not eliminate risk.
It concentrates almost all security responsibility on the user.
And once an unauthorized transaction happens, you may not even be able to determine **which device actually signed it**.
For me personally, after this experience, the practical sense of security I get from Ledger is now lower than what I experienced during more than three years of using a Binance exchange account without any abnormal asset loss.
**Full Story**
I want to publicly document what happened to me, and hopefully encourage other people who hold Bitcoin as a long-term asset to reconsider the idea that:
**“Cold wallet = absolute safety.”**
I was using a **Ledger Nano X**.
The reason I bought a hardware wallet was simple:
I did not want to leave my long-term Bitcoin holdings on an exchange forever.
Everyone says:
**Not your keys, not your coins.**
So I decided to take full control of my own private keys.
My plan was simple:
**Buy → Move to cold storage → Leave it untouched for the long term.**
**How Did I Store My 24-Word Recovery Phrase?**
This is one of the most important parts of the story.
My 24-word Secret Recovery Phrase:
Was never photographed.
Was never typed into my phone.
Was never entered into a computer.
Was never stored in iCloud.
Was never stored in Notes.
Was never stored in any password manager.
Was never entered into any website.
And was never given to another person.
It was stored in a private physical location that only I knew about.
Even my family did not know where it was.
So based on everything I currently know, **I have found no evidence that my Recovery Phrase was ever exposed.**
**My Ledger Had Not Been Used for More Than Six Months**
The last time I normally used my Nano X was around:
**December 2025.**
After that, I did not connect it to my phone.
I did not connect it to a computer.
I did not make any Bitcoin transactions.
My thinking was simple:
If this was a long-term investment, I did not need to keep checking it.
In fact, I intentionally tried to forget about the Bitcoin and just let it sit.
**But on May 27, 2026, My BTC Was Transferred Out**
When I later opened Ledger Wallet again, I discovered this transaction:
**Date:** May 27, 2026
**Time:** 22:35
Amount transferred:
**0.02894506 BTC**
I did not initiate this transaction.
I did not authorize it.
I did not approve it on my Nano X.
TXID:
9185765197466aaa778ad5c5003f96b1c23aee4233fccbace5f117e1608c6563
I did not discover the loss until:
**September 22, 2026**
when I opened Ledger Wallet again and found that the Bitcoin account balance was zero.
**My First Thought: Could This Be a Ledger Wallet Display Error?**
So I took out my Nano X again.
I reconnected it.
Updated the firmware.
Re-synchronized the wallet.
Re-scanned the Bitcoin account.
I also followed Ledger Support’s instructions and used:
**Ledger Wallet → Bitcoin 1 → Receive**
I compared the Bitcoin receiving address displayed in Ledger Wallet with the address displayed directly on the physical Nano X.
The addresses matched exactly.
In other words:
**The Nano X currently in my possession does correspond to this Bitcoin account.**
But the balance was still zero.
And the May 27 transaction was unquestionably present on the Bitcoin blockchain.
**What Truly Concerned Me Was Ledger Support’s Response**
I repeatedly asked Ledger one very specific question:
Was this transaction actually signed by the physical Nano X that I still have in my possession?
Ledger’s final answer was:
**They cannot determine that.**
They explicitly told me:
“It is impossible to say whether the transaction was signed by your Nano X.”
In other words:
**Ledger has no technical record that can identify which physical device performed the signing.**
I then asked them whether they could distinguish between:
**Scenario A**
My physical Nano X signed the transaction.
**Scenario B**
Another device or wallet used the same Recovery Phrase / private keys to sign the transaction.
Ledger responded:
“No, this is impossible to determine.”
So:
**They cannot distinguish between the two.**
**Ledger Initially Suggested a Compromised Recovery Phrase**
At first, Ledger Support suggested that the most likely explanation was:
**Recovery Phrase compromise**
meaning that someone may have obtained my 24 words.
But I kept asking them to separate:
**what is technically proven**
from
**what is only an assumption.**
Because I have found no evidence that my 24 words were exposed.
And Ledger itself cannot prove that anyone ever obtained them.
Eventually, in an email dated September 23, Ledger wrote:
“it is also not possible for Ledger to ascertain or prove which of those scenarios happened.”
In other words:
**Ledger cannot determine or prove which scenario actually occurred.**
**So What Can Actually Be Confirmed?**
What can be confirmed is:
**The Bitcoin transaction was validly signed using the private keys controlling the account.**
What cannot be confirmed is:
Which device signed it
Whether it was my Nano X
Whether it was another device
How the private keys were obtained
Whether my Recovery Phrase was ever actually exposed
What the true root cause of the incident was
This is the part I find most difficult to accept.
**I Bought a Cold Wallet to Solve a Security Problem**
For many people, the whole point of a cold wallet is:
Private keys stay offline.
Transactions require hardware signing.
Physical confirmation is required.
The attack surface is reduced.
That is exactly why I felt comfortable moving my BTC into cold storage and leaving it untouched for months.
But after this incident, I realized something:
**There is almost no second line of defense for the user.**
There is no exchange-level abnormal login alert.
No withdrawal verification system.
No risk-control pause.
No human review.
No central authority that can stop or reverse the transaction.
And even after the event:
**Ledger itself cannot tell me which device signed it.**
**Why This Changed the Way I Think About Binance**
I am not saying:
**Binance is definitely safer than Ledger.**
Centralized exchanges obviously have their own risks:
Platform risk
Account takeover risk
Withdrawal freezes
Business / solvency risk
Regulatory risk
But my own experience is this:
I kept crypto on Binance for more than three years.
I never experienced an abnormal loss of assets.
Later, because I wanted to improve security, I moved assets into Ledger cold storage.
And that is where this incident happened.
So if you ask me:
“After this experience, which option gives you more practical peace of mind?”
My answer is:
**At this point, a large centralized exchange gives me more practical peace of mind than my experience with Ledger cold storage.**
That is my personal experience.
It is not a universal conclusion.
**Did Ledger Help Me?**
Yes.
And I think it is important to be fair about that.
Ledger Support opened:
**Case #00281295**
They also performed an initial blockchain analysis.
They found that the destination address had blockchain connections to:
**HitBTC**
and
**Bridgers DEX**
Ledger indicated that HitBTC may be one of the more useful investigative leads because a centralized exchange may have access to:
KYC information
Account information
Login records
IP records
Withdrawal records
However, Ledger also made it clear that:
**They will not proactively continue participating in the criminal investigation.**
If law enforcement needs further information, they can contact Ledger and reference:
**Case #00281295**
**I Have Now Formally Reported the Case to Police**
I have officially filed a police report in Taiwan.
The investigation may include:
Tracing the BTC further
Contacting HitBTC
Requesting KYC information
Requesting IP logs
Requesting account records
Requesting withdrawal records
Investigating the Bridgers DEX path
At this point, I am waiting for further action from law enforcement.
**I Am Not Publicly Claiming That Ledger Was Hacked**
I want to be very clear about this.
There is currently no evidence proving that:
**The Ledger Nano X itself was hacked.**
So I am not saying:
“Ledger was hacked.”
But at the same time, there is also no evidence proving that:
**My 24-word Recovery Phrase was compromised.**
The actual technical conclusion is:
**A valid private key signed the transaction, but the true signing source cannot be identified.**
**What I Really Want Ledger to Answer**
If the main selling point of a hardware wallet is:
**Private key security**
then when an unauthorized transaction happens:
**Why is there no way to identify which Ledger device signed it?**
**Why is there no forensic signing record available on the device?**
**Why can’t the user determine which signer originated a transaction?**
**Why, when something goes wrong, does the explanation often fall back to “your Recovery Phrase may have been compromised”?**
**Should Ledger provide a more robust Security Incident investigation process for cases like this?**
I believe these are questions that every hardware-wallet user should seriously think about.
**Final Thoughts**
This incident changed the way I understand the phrase:
**Not your keys, not your coins.**
I still believe that statement has value.
But now I think it is missing a second sentence:
**Your keys, your responsibility — and sometimes, your problem alone.**
When you control your own private keys, you gain independence.
But at the same time, you also give up:
Exchange risk controls.
Withdrawal interception.
Account-level login records.
Human review.
And some of the investigative tools that exist in centralized systems.
I am not telling people:
**Do not use Ledger.**
I am simply saying:
Do not automatically assume:
**“Cold wallet”**
means:
**“Nothing can go wrong.”**
Because my experience shows that things can still go wrong.
And perhaps the most frustrating part is not even the financial loss itself.
It is this:
**After the incident happens, you may still be unable to get a provable answer to the most basic question:**
**How did this happen?**
The case is still under investigation.
If Ledger, HitBTC, or Taiwanese law enforcement provides any meaningful new information, I will continue updating this case publicly.
[link] [comments]
0
0
Securely connect the portfolio you’re using to start.







