News On-chain

Ledger Probes $86M in Wallet Drains Tied to Reseller CryptoBilis

Ledger on Oct. 9 opened a probe into missing funds among buyers of Southeast Asian reseller CryptoBilis. Analyst Specter puts losses above $86M in BTC, ETH and USDT.

Ledger Probes $86M in Wallet Drains Tied to Reseller CryptoBilis

Hardware wallet maker Ledger said on Friday, October 9, 2026, at 9:32 AM ET that it is investigating reports of lost funds from users in Southeast Asia who bought devices through reseller CryptoBilis. On-chain analyst Specter estimates that more than $86 million has moved to suspected theft addresses on the Bitcoin, Ethereum and Tron networks. Ledger asked the reseller to halt sales and shipments and told anyone who bought from it in the past 90 days not to set up a new device.

Details

The first reports came from Ledger owners on X and Reddit who said their wallets were emptied even though they had never exposed their seed phrase or signed a transaction. On-chain researcher tanuki42 initially counted more than $72 million flowing to a cluster of suspected attacker addresses; Specter later put known losses above $86 million. According to Bitcoin.com News, that total includes more than $42 million in ETH, $17.5 million in BTC and $16.5 million in USDT. Specter first described the victims as "hundreds" of wallets, then clarified that the real number is not yet known. Ledger has confirmed neither the amount nor the number of affected users.

In its statement, Ledger said it had "as a precaution" asked CryptoBilis to pause all sales and shipments of Ledger devices pending the investigation. Customers who bought from the reseller in the last 90 days and have not yet set up their device were told not to initiate setup; those already using one were advised to "consider moving assets to a new Ledger signer (with new seed)." CryptoBilis is listed on Ledger's official reseller page; The Block reports it operates in Indonesia, Malaysia and the Philippines.

No official cause has been given. CoinDesk describes a supply chain attack as the working theory: a buyer receives a device whose recovery phrase is already known to the attacker, and the funds are drained once deposited. Binance co-founder Changpeng Zhao wrote that the available information points to an attack through a single vendor, with a small number of users receiving fake or tampered devices. Former Mt. Gox CEO Mark Karpeles asked affected users to send photos of their device's circuit board so it could be checked for tampering. Nobody has presented evidence that Ledger's own systems were compromised.

What it means for the market

If the tampered-device theory holds, it is a notable blow to the reputation of hardware wallets, but the weak point is the sales channel rather than the technology itself: Ledger's guidance boils down to buying from trusted sellers and generating the seed phrase yourself. Coming days after the debate over exposed keys and "bunker mode", the episode gives more ammunition to those urging holders to audit where and how their coins are stored.

The news had no visible effect on bitcoin: per our data, BTC traded near $82,700 as of 1:00 PM ET on October 9, up 2.2% in 24 hours after rebounding from $80,400 the day before.

Morning brief and news on TelegramEvery morning: price, scenario of the day, squeeze risk. Key news during the day.
Category
Tags
#Ledger#hardware wallets#hack#supply chain attack#self-custody
Ryan Mitchell
On-chain and mining

Breaks down blockchain and mining data: hashrate, difficulty, holder and whale behavior.

Read next