Ledger Suspends Reseller Shipments Amid Investigation Into Reported $86 Million Crypto Thefts
Key Takeaways
- •Ledger asked reseller CryptoBilis on October 9 to pause all sales and shipments while it investigates reported customer losses in Southeast Asia.
- •Onchain investigator Specter estimated that suspected thefts involving Bitcoin, Ethereum, and Tron exceed $86 million, a figure that remains unconfirmed.
- •Ledger advised buyers with unactivated devices to postpone setup and existing users to move funds to a new device using a newly generated recovery phrase.
- •A supply-chain attack, in which devices are altered before reaching customers, is one possible explanation, but hardware tampering has not been confirmed.
- •Ledger has not established how the losses occurred, how many customers were affected, or whether every reported loss is linked to a CryptoBilis-purchased device.

Ledger is investigating reports of cryptocurrency losses affecting customers in Southeast Asia who purchased hardware wallets through the reseller CryptoBilis. The company has asked the reseller to halt sales and shipments while investigators examine the incidents. An onchain investigator estimates that suspected thefts spanning Bitcoin, Ethereum, and Tron exceed $86 million, though the total remains unconfirmed.
The episode has raised concerns about hardware wallet security and the risks posed by compromised devices. Ledger has not confirmed how the reported losses occurred, how many customers were affected, or whether the reseller's products were tampered with before reaching buyers. The reseller focus matters because hardware wallets commonly reach buyers through third-party channels as well as manufacturer-direct sales, and any tampering question centers on the interval between manufacture and delivery, where individual buyers have little visibility. Customers who purchased devices through CryptoBilis within the past 90 days face particular uncertainty as the investigation continues.
Ledger Issues Urgent Warning to Recent Buyers
Ledger announced its precautionary measures on October 9, asking CryptoBilis to pause all sales and shipments until the company completes its investigation.
The company also advised recent buyers who have not yet activated their devices to postpone setup. Customers who have already configured their wallets should consider moving their cryptocurrency to a new Ledger signer using a newly generated recovery phrase.
A recovery phrase is a sequence of words that restores access to a cryptocurrency wallet; anyone who obtains the phrase may gain access to the funds it controls. The guidance aims to reduce potential exposure while investigators determine whether the reported incidents share a common cause. Ledger has not, however, established a direct link between every reported loss and a device purchased from CryptoBilis.
Onchain Investigators Trace Millions in Suspected Losses
Blockchain investigator Specter estimated that more than $86 million in cryptocurrency may have been stolen from wallets across Bitcoin, Ethereum, and Tron. The investigator traced transactions involving suspected theft addresses after reports of missing funds circulated online.
Another investigator, operating under the name tanuki42, previously estimated losses exceeding $72 million. Researchers have not independently confirmed the aggregate amount or established whether the two estimates cover the same transactions.
A potential supply-chain attack has emerged as one possible explanation. Such an attack could involve devices being altered before reaching customers, potentially exposing their owners to unauthorized access. The distinction matters because a compromise introduced before purchase would fall outside a buyer's control, regardless of how carefully a recovery phrase was handled afterward. Nevertheless, investigators have not confirmed that hardware tampering occurred.
The case highlights security challenges facing the cryptocurrency industry, where individual users often bear responsibility for protecting their own assets. Hardware wallets generally keep private keys offline, but that protection depends on secure device initialization and the safeguarding of recovery phrases.
Ledger's investigation remains ongoing. The company has not confirmed the total financial losses or identified the mechanism behind the reported thefts. Developments worth tracking include whether investigators converge on a confirmed loss total, whether the reported incidents are tied to a shared cause, and whether and when CryptoBilis resumes sales and shipments. The findings could carry wider implications for hardware wallet distribution and customer trust in cryptocurrency self-custody.
Primary source: CoinDesk