Fri. Oct 9th, 2026

Ledger Investigates CryptoBilis Wallet Losses as Researchers Trace Up to $86M

ByJohan Shamshad

October 9, 2026 #Ledger

Hardware wallet maker Ledger is investigating reports of cryptocurrency losses involving customers who purchased devices from Southeast Asian reseller CryptoBilis, while independent on-chain researchers have linked tens of millions of dollars in suspected thefts to addresses across Bitcoin, Ethereum and Tron.

Ledger said on October 9 that it had asked CryptoBilis to suspend sales and shipments of Ledger devices as a precaution while the investigation continues.

The company advised customers who purchased a device from the reseller during the past 90 days but have not yet initialized it to avoid setting it up. Customers who already configured their devices were told to consider moving their assets to a new Ledger signer using an entirely new recovery phrase.

The warning is unusually significant because CryptoBilis is not an unknown marketplace seller. Ledger’s official reseller directory lists CryptoBilis among authorized sellers serving Indonesia, Malaysia and the Philippines.

Ledger has not disclosed how many customers are affected, the value of confirmed losses or the technical cause of the incidents. It has also not confirmed that any Ledger devices were modified, counterfeited or otherwise compromised before reaching customers.

In a statement provided to Cointelegraph, Ledger said the reports appeared isolated to the reseller and affected market. The company said it had received no corresponding reports involving devices purchased directly from Ledger and said its own infrastructure, systems and services had not been compromised.

Researchers Are Tracking More Than $72 Million in Suspected Losses

The scale of the possible thefts remains much less certain than Ledger’s reseller warning.

On-chain researcher tanuki42 identified eight addresses allegedly connected to more than $72 million in losses and encouraged potential victims whose funds reached those addresses to contact crypto incident-response organization Security Alliance, or SEAL.

SEAL subsequently amplified the findings and asked affected users to contact its response team, but it did not independently confirm the $72 million estimate or attribute the thefts to CryptoBilis devices.

Another researcher, Specter, later estimated more than $86 million in suspected stolen assets after tracing transfers across Bitcoin, Ethereum and Tron.

Those figures should not yet be treated as the financial impact of the CryptoBilis incident.

Ledger has not verified either estimate, and researchers have not demonstrated publicly that every address or transaction in their datasets originated from a customer who bought a device from CryptoBilis. It is also unclear how much overlap exists between the $72 million and $86 million datasets.

The distinction is important. Blockchain analysis can show where assets moved, but connecting individual transfers to a particular compromised device supply chain requires additional evidence linking victims, purchases and wallet creation histories.

A Hardware-Wallet Supply-Chain Compromise Would Be a Different Kind of Attack

If investigators eventually establish that some devices were compromised before customers received them, the incident would represent a fundamentally different risk from ordinary wallet phishing.

Most crypto theft campaigns try to convince users to reveal their recovery phrase, install malicious software or approve an attacker-controlled transaction. Dave Finances recently examined a fake Zano wallet campaign in which malicious software impersonated legitimate wallet infrastructure.

A supply-chain attack moves the compromise earlier.

The user may believe they are following security best practices: buying a hardware wallet, generating a recovery phrase offline and storing it securely. But if the device, packaging, firmware or initialization process has already been manipulated before delivery, those practices may not protect the assets.

There is currently no confirmation that this is what happened with CryptoBilis-supplied devices.

Former Mt. Gox CEO Mark Karpelès has publicly asked CryptoBilis to open devices from its remaining inventory so investigators can examine circuit boards for potential modifications. Binance co-founder Changpeng Zhao has also suggested that the available evidence points toward a localized supply-chain problem, but those remain external assessments rather than Ledger’s final conclusion.

Ledger’s Advice Suggests the Recovery Phrase Is Central to the Risk

Ledger’s recommended response provides an important clue about the risk model it is considering.

The company is not simply telling affected users to install a software update or reset an application. It is telling customers who already initialized CryptoBilis-purchased devices to consider moving funds to a different signer using a newly generated recovery phrase.

That matters because the recovery phrase ultimately controls the private keys associated with a wallet.

If an attacker already possesses or can reconstruct that phrase, replacing the physical device while restoring the same phrase does not remove the underlying compromise. The assets have to move to addresses generated from completely new secret material.

Recent wallet incidents have demonstrated how persistent compromised credentials can be. Dave Finances previously reported on a D’CENT-linked XRP theft investigation where researchers continued observing funds moving from wallets associated with the same compromised key material.

That is why Ledger’s recommendation to create a new seed is much more consequential than simply advising users to change a password.

Being an Authorized Reseller Does Not Eliminate Supply-Chain Risk

The uncomfortable part of the CryptoBilis investigation is that affected buyers may have done exactly what hardware-wallet manufacturers normally recommend: purchase through an officially recognized seller.

Consumers are often warned against second-hand devices, unfamiliar marketplace sellers and hardware that arrives with a recovery phrase already written down.

An authorized reseller is supposed to reduce that uncertainty.

If the investigation ultimately identifies tampering somewhere between manufacturing and the customer, the key question will become where custody of the devices broke down.

Possibilities could theoretically include reseller inventory, warehousing, fulfillment, logistics or counterfeit substitution. None has been established in this case.

Determining that point matters because the remediation would differ dramatically depending on whether a handful of individual devices were altered or an entire batch passed through a compromised distribution process.

This is similar to the security lesson from the COLDCARD loss investigation: the headline value of stolen cryptocurrency matters, but identifying the precise failure mechanism matters more for determining whether other users remain at risk.

The $86 Million Figure Could Become More Important — or Shrink Sharply

For now, the largest uncertainty is scope.

If researchers eventually demonstrate that most or all of the addresses they identified belong to CryptoBilis customers, the incident could become one of the largest hardware-wallet-related theft events in recent years.

If only a small fraction can be linked to the reseller, the current $72 million and $86 million estimates will have substantially overstated the impact of the specific incident Ledger is investigating.

That is why the addresses should currently be described as suspected theft clusters rather than confirmed CryptoBilis losses.

The cross-chain nature of the activity also complicates attribution. Funds moving across Bitcoin, Ethereum and Tron require investigators to correlate activity across different transaction models, addresses and potentially exchanges or bridges.

On-chain visibility helps after assets begin moving, but it does not necessarily reveal how the attacker obtained the keys in the first place.

The Incident Tests the Core Promise of Hardware Wallets

The broader reputational risk for Ledger is larger than the direct technical scope suggested so far.

Hardware wallets are sold on a simple proposition: private keys remain isolated from ordinary internet-connected devices.

That model is powerful, but it assumes users can trust the hardware and initialization process before those private keys are created.

If compromised hardware can enter legitimate retail channels, security moves beyond cryptography and firmware into ordinary supply-chain controls.

Crypto has seen similar trust failures elsewhere. The fake GIWA mainnet incident showed how attackers can build infrastructure convincing enough to pass as legitimate without compromising the genuine project’s systems at all.

The same conceptual problem applies here if tampering is eventually confirmed: the genuine Ledger infrastructure could remain secure while users still lose money because they interacted with something compromised elsewhere in the delivery chain.

What Ledger Needs to Establish Next

Three questions now matter most.

First, investigators need to establish whether the affected users actually purchased their devices from CryptoBilis and whether there is a common purchase period, batch, location or delivery route.

Second, Ledger needs to determine whether the physical devices or setup processes were altered in any way. That may require destructive inspection of unused inventory alongside comparison with authentic devices.

Third, on-chain investigators need to separate confirmed victims from unrelated transfers before attaching a reliable loss figure to the incident.

Until that work is complete, calling the episode an $86 million Ledger hack or a confirmed supply-chain attack would go beyond the available evidence.

What is confirmed is already serious enough: Ledger has identified reports of fund losses among customers of one authorized Southeast Asian reseller, asked that reseller to halt sales and shipments, and warned recent buyers not to initialize devices or to consider moving existing assets onto wallets generated with completely new recovery phrases.

If investigators ultimately find that compromised devices reached customers through an authorized sales channel, the lesson will extend far beyond Ledger.

Self-custody removes dependence on an exchange. It does not remove dependence on the integrity of the hardware supply chain that creates the keys.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *