Binance co-founder Changpeng Zhao (CZ) urged crypto investors to impose a strict "quarantine" period on new hardware wallets. The warning came amid an incident in Southeast Asia in which users lost more than $86 million after a local Ledger distributor was compromised.
Events this fall have exposed a new vulnerability in the industry: hackers have shifted their focus from exploiting digital bugs to physically intercepting devices during delivery.

Commenting on the risks, Changpeng Zhao recommended against transferring large amounts of assets to new addresses immediately after purchasing a device or downloading software.
In his view, the wallet should remain unused for at least a couple of weeks. During this period, investors should closely monitor relevant news for reports of potential hacking attacks.
CZ reminded users that self-custody of digital assets always carries additional responsibility that cannot be ignored. He emphasized that, in today's environment, physical devices can be modified before they reach the end customer, while the official website of any software can be hacked.
Such a preventive timeout gives users a window of opportunity: if a batch of devices arrives at a reseller already compromised, on-chain analysts will have two weeks to detect the first thefts and raise the alarm in the media, protecting other buyers.
"Live with the wallet for a couple of weeks." The logic behind CZ's advice
The immediate trigger for the strict recommendations was an emergency announcement by Ledger on October 9 regarding the suspension of sales through its reseller CryptoBilis. Earlier, on-chain researchers had tracked approximately $86.9 million in outflows across the Bitcoin, Ethereum, and Tron networks from hundreds of wallets belonging to investors in Malaysia, Indonesia, and the Philippines.
The attackers physically opened packages at the reseller's intermediate warehouses and replaced the original instructions with pre-generated seed phrases. Ledger separately emphasized that its factory production, firmware, and Ledger Live application had not been compromised — the attack affected only CryptoBilis as a logistics link.
All customers who purchased devices within the past 90 days were advised not to activate them and, if there was any risk of compromise, to urgently move their assets to new addresses.
The Ledger incident confirmed a broader trend: over the past three months, physical delivery has become the main weak point in "cold" storage, affecting all major players in the market. In August, Coldcard maker Coinkite reported that the systems of its third-party distributors had been compromised.
In September, Trezor acknowledged a data breach affecting 80,000 US customers after its logistics contractor, ShipMonk, was hacked, exposing buyers' real names, phone numbers, and home addresses.
Purchasing wallets through local marketplaces or distributors is now effectively considered unsafe. For large holders, the emerging standard is to order hardware directly from manufacturers, arrange delivery to neutral addresses such as PO boxes, and implement a mandatory "quarantine" period following CZ's method.






