NewsCryptoLedger Investigates Crypto Wallet Theft Linked to Reseller CryptoBilis as Losses Estimated Above $86 Million

Ledger Investigates Crypto Wallet Theft Linked to Reseller CryptoBilis as Losses Estimated Above $86 Million

Author: LiveBitcoinNews·

Key Takeaways

  • •Ledger has requested that CryptoBilis halt sales and shipments of its devices and has warned customers who purchased from the reseller within the last 90 days not to set them up.
  • •On-chain investigator Specter traced deposits from hundreds of victims to suspicious addresses holding nearly $87 million, comprising about $42 million in Ethereum, $17.6 million in Bitcoin, and $16.5 million in USDT across the Bitcoin, Ethereum, and TRON networks.
  • •Ledger has not determined the cause of the reported thefts or verified the total losses, but the company states there is no evidence of a direct attack on its hardware wallets or underlying infrastructure.
  • •Binance founder Changpeng Zhao suggested the incident appears isolated to a supply chain attack involving a single vendor, and said the BNB ecosystem and broader cryptocurrency community would assist in tracking the stolen funds.
  • •Customers who already activated devices purchased from CryptoBilis are advised to move their assets to a new Ledger signer and generate a fresh recovery phrase.
Ledger Investigates Crypto Wallet Theft Linked to Reseller CryptoBilis as Losses Estimated Above $86 Million

Ledger is investigating reports of stolen cryptocurrency involving customers who purchased its hardware wallets through CryptoBilis, a reseller operating in Southeast Asia. The company disclosed the probe on October 9, 2026, and it comes as Specter, an on-chain investigator, estimates that suspicious addresses linked to the case received more than $86 million across the Bitcoin, Ethereum, and TRON networks.

Hardware wallets are designed to keep a user's private keys offline, and Ledger is one of the most widely used makers of such devices. That offline model is the basis of the product's appeal: private keys are meant to stay on the device and away from internet-connected computers, which places a premium on a device arriving untouched from the factory.

As the investigation proceeds, Ledger has asked CryptoBilis to stop selling and shipping Ledger devices. The company has also urged customers who bought devices from the reseller in the last 90 days not to set them up, according to a warning posted on Ledger's support account on X.

Customers who have already activated devices purchased from CryptoBilis were advised to transfer their assets to a new Ledger signer. Ledger additionally recommended generating a fresh recovery phrase for the replacement setup.

A recovery phrase is a set of words that can be used to regain access to a cryptocurrency wallet, and anyone who knows the phrase effectively controls the funds — which is why users are repeatedly cautioned never to share it with anyone or enter it into an untrusted website. Legitimate phrases are generated by the device itself during setup; a phrase supplied by a seller or anyone else should never be used.

Ledger has not specified what caused the reported thefts, and the company has not verified the total financial losses or the number of customers affected. Both the cause of the incident and the precise scale of the losses therefore remain open questions.

On-Chain Investigator Tracks Millions to Flagged Addresses

Specter said he was able to trace suspicious wallet addresses that received deposits from hundreds of victims. Such tracing relies on the public nature of blockchain ledgers, where transfers between addresses are visible to anyone. The analysis covered Bitcoin, Ethereum, and TRON, though there is no confirmation that all of the reported cases are linked.

According to the investigator's estimates, the flagged addresses held nearly $87 million in total. That figure comprises approximately $42 million in Ethereum, $17.6 million in Bitcoin, and $16.5 million in USDT, Tether's dollar-pegged stablecoin. These amounts represent reported holdings at the suspicious addresses rather than an independently verified final loss figure, meaning the total dollar loss remains unknown as investigators continue examining the transactions.

Ledger has stated that there is no evidence of a direct attack on its hardware wallets or the underlying infrastructure. Even so, the investigation must still determine how the impacted customers lost access to their funds.

Suspected Supply Chain Attack Puts Hardware Wallet Security in Focus

Writing on X, Binance founder Changpeng Zhao, known as CZ, said the incident "seemed to be isolated," suggesting the reports could be the result of a supply chain attack by a single reseller.

⚠️ Beware if you use a Ledger hardware wallet, especially if you bought one recently.

Based on information so far, it seems to be localized to a supply chain attack with one vendor. A small number of people probably bought fake (or tampered) Ledgers.

Ledger is one of the most…

— CZ 🔶 BNB (@cz_binance) October 9, 2026

In a supply chain attack, criminals interfere with products before they reach the customer. A device might be modified in transit, or produced with a recovery phrase the attacker already knows — meaning the compromise occurs before the device ever arrives at its owner's door.

Former Mt. Gox CEO Mark Karpelès also expressed concerns about potential interference in the supply chain. Investigators have not yet confirmed, however, whether devices were altered, replaced, or provided with compromised recovery phrases.

For that reason, customers should not assume that all Ledger devices and resellers carry the same risk. The information available indicates there may be an issue with one particular seller, but the investigation is continuing.

CZ added that participants from the BNB ecosystem and the broader cryptocurrency community would also assist in tracking the stolen funds. Tracking transactions, however, does not ensure that investigators will be able to recover the assets.

Ledger is currently warning customers who bought its devices from CryptoBilis in the last 90 days. Affected users are advised to follow official company updates and to contact Ledger only through official channels.

The incident underscores the need to purchase hardware wallets from trusted sources — and to never use a recovery phrase provided by a seller or any third party.

Source: Live Bitcoin News