0x63311c2d6331…63311c2a
Ledger Investigates Suspected $86 Million Wallet Theft Tied to Reseller
Ledger is investigating a suspected $86 million theft affecting wallets sold via Southeast Asian reseller CryptoBilis, and has told recent buyers not to activate their devices.

Outputs
Ledger is investigating suspected thefts exceeding $86 million from hundreds of wallets linked to devices sold via reseller CryptoBilis.
The estimate, traced across Bitcoin, Ethereum and Tron, comes from pseudonymous investigator Specter and is unconfirmed.
Ledger asked CryptoBilis to pause all sales and shipments and told buyers from the past 90 days not to set up their devices.
2025 exploits include Bitget at over $350 million, Liquid Network at ~$320 million, Drift at $295 million and Kelp at $293 million.
No confirmed evidence exists that Ledger's own systems or wallet technology were compromised.
Ledger, the Paris-based hardware wallet manufacturer, said Friday it is investigating reports of stolen customer funds linked to devices sold through a Southeast Asian reseller, after a pseudonymous blockchain investigator estimated that more than $86 million in crypto may have been drained from hundreds of wallets.
The estimate comes from on-chain analyst Specter, who posted on X that suspected theft addresses span Bitcoin, Ethereum and Tron. Specter traced the addresses after Ledger users reported missing funds on X and Reddit. There has been no independent confirmation of the total amount of user assets affected, and Ledger has not verified the $86 million figure.
Ledger confirmed reports of missing funds from customers who purchased devices through CryptoBilis, the reseller in question, but did not identify a cause or confirm the reported loss amount. As a precaution, the company has asked CryptoBilis to pause all sales and shipments while the investigation continues.
What should affected customers do now?
Ledger issued two directives to customers:
- Anyone who bought a device from the reseller within the past 90 days should not begin setting it up.
- Customers who have already activated wallets purchased through CryptoBilis should consider moving their assets to a new Ledger device with a newly generated recovery phrase.
Is Ledger's own technology compromised?
There is no confirmed evidence that Ledger's own systems or wallet technology were breached. The investigation concerns devices sold through a third-party reseller, a distinction that matters for the broader market because Ledger says it has sold more than 7 million devices worldwide since its founding in 2014.
One possible explanation is a supply-chain attack, in which hardware wallets are tampered with before reaching customers. An attacker could, for example, ship a device pre-loaded with a recovery phrase the attacker already knows, then sweep the funds once the victim deposits assets. That scenario would differ materially from a breach of Ledger's infrastructure. However, no one has confirmed that device tampering or pre-generated recovery phrases caused the reported losses.
The incident remains under active investigation. It is still unclear how many users were affected, whether the reported thefts are connected, or how much cryptocurrency was actually lost. Ledger said it would provide updates as the probe progresses.
How does this fit into 2025's exploit tally?
If the $86 million estimate holds, the incident would add to an already costly year for crypto security. According to DefiLlama data, the largest incidents so far include:
- Bitget: over $350 million stolen last month
- Liquid Network: about $320 million
- Drift: $295 million
- Kelp: $293 million
Ledger's role in the market amplifies the stakes. The company's devices keep private keys offline, and its products are widely used by investors who want to hold crypto without relying on exchanges. A confirmed compromise of its distribution chain — even one limited to a single reseller — would pressure the company to tighten oversight of its third-party sales channels.
The 90-day purchase window Ledger flagged gives investigators and affected customers a near-term timeline: anyone who bought from CryptoBilis since roughly mid-summer faces the most immediate exposure, and the pause on the reseller's shipments will remain in effect at least until Ledger publishes its findings.
via x.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles