0x6903c7886903…6903c785
Ledger Probes $86 Million Wallet Drains Tied to CryptoBilis Buyers
Ledger is investigating wallet drains affecting customers of Malaysian retailer CryptoBilis, with estimated losses exceeding $86 million across affected buyers.
Outputs
Ledger is investigating wallet drains involving buyers from retailer CryptoBilis
Estimated losses top $86 million
CryptoBilis is a Malaysia-based third-party reseller of Ledger devices
The investigation concerns devices sold through the reseller, not Ledger's direct channel
Ledger, the French hardware wallet manufacturer, is investigating a string of wallet drains affecting buyers who purchased its devices through the retailer CryptoBilis, with estimated losses now exceeding $86 million.
The figure represents an aggregate estimate across affected users rather than a single incident. According to the investigation's current scope, the compromised funds belong to customers who acquired Ledger devices through CryptoBilis, a third-party reseller based in Malaysia.
What is known so far?
- Ledger has opened an investigation into wallet drains affecting CryptoBilis customers.
- Estimated aggregate losses top $86 million.
- The probe centers on devices sold through the Malaysian reseller rather than Ledger's own direct sales channel.
The case revives a well-documented threat model in hardware wallet distribution: compromise introduced not at the manufacturer but at an intermediary. Ledger devices ship with firmware that generates private keys on-device, and the seed phrase is never meant to leave secure hardware. A reseller-level compromise would typically involve tampering before delivery — for example, supplying pre-configured seed phrases or altered packaging that induces users to enter credentials an attacker already controls.
Ledger has not yet publicly detailed the exact compromise vector under investigation. The company's standard guidance is that users should initialize devices themselves and never trust a seed phrase supplied pre-printed or pre-sealed by a seller.
Why does the distribution channel matter?
Hardware wallets are only as trustworthy as the path from factory to customer. Ledger sells directly and through authorized resellers; the CryptoBilis case shows how a point of sale outside the manufacturer's direct control can become a single point of failure for thousands of users.
For CryptoBilis buyers, the operational consequences are immediate. Anyone who purchased a Ledger device from the retailer and followed setup instructions provided by the seller — rather than generating a fresh seed phrase on-device — may have exposed their funds to whoever controlled those credentials. The $86 million estimate suggests a substantial share of affected customers did exactly that.
The episode also carries reputational stakes for Ledger, whose brand rests on the premise that self-custody hardware eliminates counterparty risk. An investigation implicating a reseller does not implicate the devices' firmware, but it does raise questions about how the company vets and monitors its retail partners.
What happens next?
Ledger's investigation is ongoing. Affected users can expect the company to publish findings on the compromise mechanism, and the outcome will likely shape how Ledger structures — or restricts — its reseller network going forward.
via The Block (Source)