0x69c8cadb69c8…69c8cade
Ledger Investigates $86M Loss Tied to Malaysian Reseller CryptoBilis
Hardware wallet maker Ledger is investigating reports of more than $86 million in user losses tied to Malaysian reseller CryptoBilis, warning customers against setting up recently purchased devices.

Outputs
Blockchain investigator Specter traced more than $86 million in losses to CryptoBilis-sold Ledger devices via on-chain analysis posted on X on October 9, 2026
Ledger advised customers who bought from CryptoBilis in the last 90 days not to set up their devices and asked the reseller to halt all sales and shipments
Ledger said its infrastructure, systems and services were not compromised and that no reports involve products purchased directly from the company
A July 2026 firmware bug in Coinkite's Coldcard wallets enabled attackers to steal close to $120 million in bitcoin, per Galaxy Research
Trezor disclosed last month that nearly 81,000 customers had their details leaked after a third-party fulfillment partner was breached
October 9, 2026 — More than $86 million in user funds have been lost from Ledger devices sold by Malaysian reseller CryptoBilis, blockchain investigator Specter wrote on X on Friday, citing theft addresses he traced from victim posts.
The estimate emerged hours after the Paris-based hardware wallet manufacturer told customers in South East Asia to stop setting up devices purchased from CryptoBilis within the last 90 days. Ledger disclosed the warning via its support X account and said it had asked the Kuala Lumpur-based vendor to halt all sales and shipments of Ledger devices.
What did Ledger actually say?
In a statement on X, Ledger wrote: "Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBilis."
The company added: "If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed). We will continue to inform customers of updates as the investigation progresses."
In a separate statement to Bitcoin Magazine, Ledger said the incident is "isolated specifically to this reseller in this specific market." The company added: "No reports were made of products purchased directly from Ledger, and Ledger's infrastructure, systems and services were not compromised."
CryptoBilis did not respond to questions from Bitcoin Magazine.
How significant is the loss?
Ledger has not publicly disclosed a dollar figure for the alleged thefts. Specter, an on-chain investigator, said he followed addresses referenced in social media posts from affected users and arrived at the $86 million total.
If confirmed, the case would rank among the largest supply-chain incidents ever attributed to a hardware-wallet retail channel, though the methodology rests on addresses publicly flagged by victims and third-party researchers rather than corroborated by Ledger or law enforcement.
Where does this fit in 2026's hardware-wallet breaches?
The episode lands in a difficult year for self-custody security:
- A July firmware vulnerability in Coinkite's Coldcard wallets let attackers guess seed phrases and steal close to $120 million in bitcoin.
- Galaxy Research reported that several attackers independently exploited the Coldcard bug in the months after disclosure.
- Trezor said last month that nearly 81,000 customers had their personal data exposed after a third-party fulfillment partner suffered a breach.
- Earlier in the year, scammers obtained customer data through Ledger's payment processor Global-e and used it to send phishing emails.
The CryptoBilis case differs in one respect. The Coldcard and Trezor incidents touched device firmware and back-office partners. Ledger's statement places the CryptoBilis compromise at the retail distribution layer, with the company's manufacturing and signing pipeline so far unaffected.
What happens next?
Ledger's advisory instructs affected customers to migrate assets to a freshly initialized Ledger device generated from a new seed. The company has not announced a recall, a firmware update for the reseller channel, or coordination with Malaysian regulators.
The 90-day window Ledger cited for recent CryptoBilis purchases suggests investigators believe tampered stock has moved through the reseller for at least that long. Whether Ledger extends the warning window, files a formal complaint in Malaysia, or escalates through international channels will determine whether the $86 million figure closes the episode or simply opens it.
via x.com (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles