Join the CryptoPress Newsletter

Get exclusive market insights, Web3 alpha, and curated crypto intelligence delivered directly to your inbox.

No spam. Unsubscribe at any time.

Skip to main content

Ledger Investigates Potential $86M+ Wallet Drains Tied to CryptoBilis Reseller

Ledger probes fund losses for Southeast Asia buyers of CryptoBilis hardware wallets, with on-chain estimates exceeding $86 million.

By CryptoPress
October 10, 2026

Hardware wallet maker Ledger is investigating reports of fund losses involving customers in Southeast Asia who bought devices from authorized reseller CryptoBilis, according to a statement posted by Ledger Support on X on October 9. The company said it had asked CryptoBilis to pause all sales and shipments of Ledger devices as a precaution while the probe continues.

In the same post, Ledger recommended that users who purchased from the reseller in the last 90 days not initiate setup if they have not already done so. Those who have set up their devices should consider moving assets to a new Ledger signer generated with a fresh seed phrase. The firm directed affected customers to official support channels and noted it would provide further updates as the investigation progresses. CryptoBilis is listed as an official Ledger reseller operating in Indonesia, Malaysia, and the Philippines.

On-Chain Investigations and Estimated Losses

Separately, pseudonymous on-chain investigator Specter reported tracing theft addresses that received inflows from hundreds of victim wallets across Ethereum, Tron, and Bitcoin, estimating total losses above $86 million. Arkham data cited in coverage showed holdings of roughly $42 million in ETH, $17.6 million in BTC, and $16.5 million in USDT at the traced addresses. Ledger has not confirmed the loss figure, the number of affected customers, or whether every traced theft is linked to CryptoBilis buyers.

The cause of the reported drains remains unclear. No confirmed tampering of devices or compromise of Ledger’s own hardware, firmware, or infrastructure has been announced. Hardware wallets are designed to keep private keys offline, but pre-delivery compromise—such as a device shipped with a known recovery phrase—could expose funds without requiring the owner’s signature. Independent researchers, including Bitquery, have published higher estimates exceeding $90 million across additional chains, though these remain third-party assessments.

Supply Chain Risks in Focus

The incident has drawn attention across crypto media and social platforms, highlighting ongoing risks in the hardware wallet supply chain. Users who purchased Ledger devices directly from the manufacturer or other authorized channels outside the specified reseller and timeframe have not been advised to take action based on available information. Ledger has previously faced scrutiny over past security incidents, though this case appears localized pending further findings.

Related

© Cryptopress. All rights reserved.