Sun. Oct 11th, 2026

8-Year-Old Wallet Drained Only After Move to New Ledger, Adding Clue to CryptoBilis Probe

ByJohan Shamshad

October 10, 2026 #Ledger
Crypto Hack

A cryptocurrency wallet that had remained secure for roughly eight years lost all 59 ETH after its owner moved the assets to a newly created Ledger wallet about one month ago, providing investigators with another potentially useful timing marker in the growing CryptoBilis wallet-drain investigation.

Lookonchain identified the victim on October 10 and valued the stolen 59 ETH at approximately $146,800. The original address had existed for around eight years and had been inactive for more than four years before the holder transferred the ETH to the newer wallet.

The funds survived in the old address throughout that period. They were drained only after the move.

That sequence does not establish how the attacker obtained access to the new wallet, but it gives researchers something particularly valuable in a supply-chain investigation: a relatively narrow period in which the security assumptions around the holder changed.

The case comes one day after Ledger began investigating fund losses linked to customers of authorized Southeast Asian reseller CryptoBilis.

The Old Keys Apparently Worked for Years

The most interesting feature of the 59 ETH case is not the size of the loss.

It is the before-and-after comparison.

According to the on-chain history highlighted by Lookonchain, the holder’s previous wallet remained intact for approximately eight years. More than four years passed without activity before the owner finally moved the ETH about one month before the theft.

If the same individual controlled both wallets, the transfer effectively creates two different security environments for the same assets.

The old environment protected the ETH for years. The new environment did not.

That does not prove the Ledger hardware itself was modified. The new recovery phrase could theoretically have been exposed through another route, including compromised setup instructions, malicious software, physical observation or some other operational failure.

But in an investigation already centered on reports involving Ledger devices sold through CryptoBilis, the timing strengthens the case for examining exactly how and when the new wallet’s seed material was generated.

Lookonchain’s tracing identifies the affected address and attributes the drain to the CryptoBilis Ledger Drainer cluster.

This Is the Kind of Victim History Investigators Need

Blockchain investigators can easily establish when cryptocurrency moved. Determining when a private key became compromised is much harder.

If an attacker obtains a seed phrase and waits for weeks or months before using it, there may be no suspicious blockchain activity during the compromise itself.

The eventual theft merely proves that the attacker possessed valid signing authority by the time the funds moved.

That makes victim histories important.

If several CryptoBilis customers report old wallets remaining secure until funds were transferred to newly initialized devices, investigators can compare device purchase dates, initialization dates, shipping batches and the first funding dates of the new wallets.

A repeated pattern could help narrow the likely exposure window.

The opposite evidence would matter just as much. If investigators find victims whose recovery phrases were created long before they purchased anything from CryptoBilis, or wallets drained without any connection to newly initialized hardware, that would weaken a simple reseller-supply-chain explanation.

Ledger Still Has Not Confirmed the Root Cause

Ledger has acknowledged reports of losses involving customers who bought products through CryptoBilis and has asked the reseller to stop sales and shipments while the investigation continues.

The company has also said it has no indication that Ledger’s own infrastructure, systems or services were compromised.

For customers who bought devices from CryptoBilis during the previous 90 days but had not yet initialized them, Ledger advised against completing setup. Customers who already initialized affected devices were told to consider moving assets to a new signer created with an entirely new recovery phrase.

That recommendation is significant because replacing a device while restoring the same seed would not solve a compromised-recovery-phrase problem.

The situation resembles the earlier D’CENT XRP investigation, where wallets remained vulnerable because the same compromised signing credentials continued working. In that incident, some wallets were funded again after being emptied and were subsequently drained again.

In both cases, the crucial asset is not the physical device. It is the key material controlling the blockchain addresses.

Independent Estimates Have Continued to Rise

The broader CryptoBilis loss estimate is also still evolving.

DaveFinances reported on October 9 that independent researchers had traced more than $72 million and later more than $86 million in suspected losses across Bitcoin, Ethereum and Tron, while stressing that Ledger had not independently verified those totals.

Bitquery has since expanded the tracing and says it identified approximately $92.9 million taken from 311 wallets across five networks, including Tron, Bitcoin, Ethereum, BNB Chain and Polygon.

That figure should still be treated as an independent on-chain estimate rather than Ledger’s confirmed victim tally.

The distinction is essential because an address appearing in an investigator’s cluster does not, by itself, prove that its owner bought a Ledger from CryptoBilis.

The new 59 ETH case is more useful if the victim’s purchase and device history can be tied directly to the reseller.

Moving to a New Wallet Can Increase Security — Unless the New Seed Is the Problem

Crypto investors are routinely told to move assets from old wallets into fresh addresses when security improves.

Normally that makes sense.

A fresh seed generated on a trustworthy hardware wallet removes dependence on old software environments, old backups and previously exposed addresses.

But a migration reverses that logic if the destination’s key-generation process is compromised.

Instead of moving assets away from risk, the holder moves them directly into the attacker’s visibility.

This is why the CryptoBilis investigation is potentially more serious than ordinary wallet phishing. In conventional phishing, a user usually has to make a visible mistake: visit a fake site, approve a transaction or enter a seed phrase somewhere it does not belong.

A supply-chain compromise could undermine someone who believes they are improving security by purchasing a hardware wallet from an authorized sales channel.

DaveFinances recently examined a different version of that trust problem when a fake Zano wallet distributed malware capable of stealing wallet credentials. There, the compromised layer was software provenance. With CryptoBilis, investigators are trying to determine whether the weak point occurred even earlier in the physical distribution or initialization chain.

The One-Month Gap May Matter as Much as the Theft

The attacker apparently did not need to drain the 59 ETH immediately after it entered the new wallet.

The assets reportedly sat there for roughly a month.

If the key had already been compromised when the wallet was initialized, that delay would suggest the attacker may have been collecting credentials and waiting before executing a coordinated theft rather than opportunistically stealing funds the moment they arrived.

That would fit a broader pattern investigators are now examining across the CryptoBilis-linked addresses, but it remains an inference rather than a confirmed attack timeline.

Delayed execution is particularly important because it can make compromised hardware look safe.

A customer initializes a device, transfers a small test amount, waits several days and sees nothing suspicious. Confidence increases. A larger balance then arrives weeks later.

If an attacker already possesses the recovery phrase and is simply waiting, none of those precautions establishes that the wallet is secure.

The Next Breakthrough Will Probably Come From Comparing Victims

The 59 ETH wallet does not independently explain the CryptoBilis incident.

What it provides is another point on the timeline.

Investigators now need to compare it with other victims: when the devices were ordered, when they were delivered, when they generated their recovery phrases, when their new addresses first received funds and how long the attacker waited before draining them.

The approach is similar to the work needed in the COLDCARD investigation, where victim counts and wallet histories became more useful as researchers assembled a larger common dataset.

If CryptoBilis-linked victims consistently show old assets remaining safe until they were transferred to newly initialized devices from the reseller, investigators will have a much stronger forensic pattern.

If not, the theory will need to expand.

For now, one user’s eight-year history provides a simple but unusually informative contrast: the 59 ETH survived years in the old wallet and disappeared only after the security setup changed.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape. You can reach out to him via his social media accounts:

Linkedin: https://www.linkedin.com/in/johan-shamshad-742851262/

X: https://x.com/Yasmine_FX

Investing: https://www.investing.com/members/contributors/279781574

Leave a Reply

Your email address will not be published. Required fields are marked *