Ledger Investigates $86M Theft Linked to Reseller
Ledger investigates over $86M in suspected crypto theft linked to Southeast Asian reseller CryptoBilis, raising hardware wallet supply-chain security concerns.
Hardware wallet manufacturer Ledger is investigating reports of cryptocurrency losses potentially exceeding $86 million, involving customers who purchased devices from authorized Southeast Asian reseller CryptoBilis. The company has instructed the reseller to suspend sales and shipments while investigators examine allegations of compromised devices and a possible supply-chain attack.
The incident came to public attention on October 9, 2026, after blockchain investigators identified suspicious fund movements across Bitcoin, Ethereum, and TRON. Although researchers have connected the activity to potentially compromised hardware wallets, Ledger has not confirmed the total losses or established the attack mechanism.
Ledger Investigates CryptoBilis After Reports of Missing Funds
Ledger confirmed that it was investigating reports of missing cryptocurrency involving customers who purchased hardware wallets from CryptoBilis, a reseller operating across Southeast Asia. In an official statement on X, Ledger Support said the company had asked CryptoBilis to immediately pause sales and shipments of Ledger products pending the outcome of its investigation.
The company also warned customers who purchased devices from the reseller within the previous 90 days against initializing them until further notice. For users who had already configured their wallets, Ledger recommended considering a transfer of funds to a new Ledger signer initialized with a fresh recovery phrase.
These precautions suggest that investigators are examining whether the security of certain devices could have been compromised before reaching customers. However, the company has not publicly established that compromised hardware caused the reported losses.
A similar concern emerged when Trezor disclosed a third-party shipping provider data breach that exposed customer information without compromising the manufacturer's hardware wallets or private keys. Subsequent reporting revealed that the Trezor breach had expanded to additional customers, highlighting how security incidents involving external service providers can expose cryptocurrency users to risks beyond the hardware itself.
Researchers Trace Over $86M as Hardware Tampering Allegations Emerge
Independent blockchain researchers have identified potentially significant cryptocurrency losses linked to the incident, although the exact amount remains unconfirmed. Onchain investigator tanuki42 initially reported identifying suspected theft addresses holding or receiving more than $72 million in cryptocurrency.
Another investigator, Specter, subsequently estimated that the total suspected losses exceeded $86 million after tracing transactions across Bitcoin, Ethereum, and TRON. The estimates have not been independently verified, and it remains unclear whether both researchers examined overlapping transactions or separate groups of victims.
⚠️ Beware if you use a Ledger hardware wallet, especially if you bought one recently.
Based on information so far, it seems to be localized to a supply chain attack with one vendor. A small number of people probably bought fake (or tampered) Ledgers.
Ledger is one of the most secure and oldest hardware wallets in the industry. Stood the test of time. But these things happen.
I expect and know all BNB ecosystem players (and all industry) to help trace and recover the funds.
— CZ 🔶 BNB (@cz_binance) October 9, 2026
Specter initially suggested that hundreds of wallets could be involved but later clarified that the exact number of affected wallets was unknown. Former Mt. Gox CEO Mark Karpelès added another dimension to the investigation by sharing images of a Ledger Nano X device allegedly purchased through CryptoBilis.
Karpelès claimed that the device contained a suspicious implant concealed beneath the screen padding. He described the wallet's packaging as professionally assembled, making the suspected modification difficult to identify during an ordinary inspection.
Binance co-founder Changpeng Zhao, commonly known as CZ, also responded to the reports, suggesting that the available information pointed toward a localized supply-chain attack involving a single vendor. Zhao cautioned hardware wallet buyers and expressed support for tracing and recovering potentially stolen funds.
EtherWorld previously covered how ZachXBT exposed an alleged $5 million cryptocurrency scam involving hardware wallet impersonation, social engineering, and stolen funds. Similarly, the exploitation of legacy Ethereum wallets illustrated how compromised private keys can enable attackers to drain cryptocurrency without exploiting the underlying Ethereum protocol.
Supply-Chain Risks Raise Questions About Hardware Wallet Security
Hardware wallets are designed to protect cryptocurrency private keys by isolating them from internet-connected computers and smartphones. Unlike software wallets, which operate on general-purpose devices, hardware wallets typically require transactions to be approved using dedicated signing hardware.
However, these protections assume that the device itself is authentic, its firmware is trustworthy, and sensitive information has not been compromised during setup or distribution. A supply-chain attack can undermine these assumptions before the customer even begins using the wallet.
Earlier this year, EtherWorld reported how hardware wallet owners received fraudulent security letters containing malicious QR codes, designed to trick users into revealing recovery phrases. A separate Trezor phishing campaign following a third-party email compromise demonstrated how attackers could exploit trusted communication channels to distribute convincing security warnings.
Holy shit...
A random Chinese company purchased CryptoBilis (the authorised Ledger reseller that issued the spy-implanted Ledgers) from its Malaysian ex-owner, then put him under a confidentiality agreement preventing him from disclosing the sale publicly.
What a wild attack. https://t.co/KR8Jh0Kgbp
— FatMan (@FatManTerra) October 9, 2026
EtherWorld also examined a crypto RAT malware campaign linked to $235,000 in suspected losses, where attackers allegedly hijacked active sessions to access cryptocurrency wallets. Meanwhile, the $7.73 million rsETH Safe exploit highlighted risks associated with authorized wallet modules and transaction execution.
Together, these incidents demonstrate that wallet security depends on more than private-key storage. Distribution integrity, device authentication, user behavior, and transaction authorization all contribute to protecting digital assets.
Ledger Issues Emergency Guidance as Investigation Continues
Ledger has urged customers who purchased devices from CryptoBilis during the previous 90 days to take immediate precautions while the investigation remains ongoing. Users who have not initialized their hardware wallets have been advised to postpone setup.
Those who have already initialized their devices should consider transferring cryptocurrency to a new, trusted Ledger signer configured with a newly generated recovery phrase. Importantly, customers should not reuse a recovery phrase associated with a potentially compromised device, as doing so could preserve the original security exposure.
Users should also avoid entering recovery phrases into websites, support forms, or applications claiming to offer device verification. Any migration should be conducted using trusted hardware and official instructions, preferably after confirming that the receiving wallet has been initialized independently.
EtherWorld reported how India's cybercrime authorities warned about rising Trust Wallet scams, including fraudulent websites designed to steal cryptocurrency credentials. EtherWorld's August 2026 DeFi security report documented multiple incidents involving vulnerable infrastructure, compromised wallets, and protocol-level weaknesses.
It is also unclear whether affected customers will receive compensation or whether additional reseller restrictions will follow. The reported $86 million figure remains an investigative estimate rather than a confirmed loss total.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- Researchers Crack Google’s Hidden Shor Optimization
- Ethereum’s Roadmap Just Changed. Here’s What’s Next
- Vitalik Buterin Outlines Ethereum's Lean Vision
- Vitalik’s Bitcoin-Inspired Plan for Ethereum
- Vitalik Buterin Explains Cryptography’s “Final Boss”
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.