Ledger Warns Buyers Not to Set Up Wallets From Reseller CryptoBilis After Users Report Losses
Key Takeaways
- •Ledger is investigating reports of lost user funds among customers in South East Asia who bought hardware wallets from the reseller CryptoBilis.
- •Ledger advised customers who purchased devices from CryptoBilis in the last 90 days not to set them up, and to move assets to a new Ledger signer with a new seed if already configured.
- •Ledger asked CryptoBilis to pause all sales and shipments of its products while the investigation continues.
- •Blockchain investigator Specter traced theft addresses linked to the incident and estimated that over $86 million was lost, though Ledger has not disclosed the total or described how the losses occurred.
- •Ledger stated the incident is isolated to this specific reseller and market, with no reports involving products bought directly from Ledger and no compromise of the company's infrastructure, systems, or services.

Hardware wallet manufacturer Ledger is investigating the loss of user funds after customers in South East Asia reported issues with devices bought through a reseller, the company said on Friday, October 9.
The Paris-based maker of crypto hardware wallets advised customers who had purchased devices from the vendor CryptoBilis within the last 90 days not to set them up. Ledger added that it had asked CryptoBilis to pause all sales and shipments of its products. Ledger devices are used to store the private keys that control cryptocurrency holdings offline.
Ledger did not reveal how much money users had lost. However, blockchain investigator Specter wrote on X that he had traced theft addresses following social media posts and that over $86 million had been lost. The company has not described how the losses occurred.
BREAKING: Ledger reports loss of funds from users in South East Asia who purchased products from the reseller "CryptoBillis". The situation is ongoing and users are urged to review Ledger's official updates. pic.twitter.com/0GT3cthQtD
— Bitcoin Magazine (@BitcoinMagazine) October 9, 2026
“Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBilis,” the company said via its support account on X.
“If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed). We will continue to inform customers of updates as the investigation progresses,” the company said. The advice points to how these devices work: the seed phrase created during setup generates the private keys that control a wallet’s funds, so directing affected users to a new seed separates their assets from anything tied to the original setup.
In a statement to Bitcoin Magazine, Ledger said that, based on the information available to date, the incident is isolated specifically to this reseller in this specific market.
“No reports were made of products purchased directly from Ledger, and Ledger’s infrastructure, systems and services were not compromised,” the company added.
CryptoBilis is a hardware wallet vendor based in Kuala Lumpur, Malaysia, according to its website. The company did not immediately respond to questions from Bitcoin Magazine.
The incident is the latest in a string of data breaches and security failures to hit the crypto industry this year. In July, hackers stole close to $120 million in bitcoin from users of Coldcard hardware wallet devices.
The Coldcard products, made by Canadian company Coinkite, contained a firmware bug that led to faulty seed generation, allowing hackers to essentially guess investors’ seed phrases. Galaxy Research said that in the months following the attack, various attackers were able to exploit the bug independently.
In a separate incident, hardware wallet manufacturer Trezor reported last month that close to 81,000 customers had their details leaked after a data theft at its third-party fulfillment partner.
Criminals have targeted crypto user data throughout the year. Scammers previously obtained customer information via Global-e, the payment processor used by crypto wallet maker Ledger, and used it to send phishing emails.
This article was first published on Bitcoin Magazine and was written by Mathew Di Salvo.