0x7c2ab93c7c2a…7c2ab939

ConfirmedSecurity624 vB34 sat/vB3 min decode

Ledger Probes $87M in Suspected Losses Tied to Wallet Reseller

Ledger halted sales by reseller CryptoBilis after an investigator traced $86M+ in suspected thefts across Ethereum, Tron and Bitcoin tied to victim wallets.

Ledger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller
WitnessLedger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet ResellerAI-generated

Outputs

  1. Ledger asked reseller CryptoBilis to pause all sales and shipments on October 9 while it investigates customer fund losses in Southeast Asia.

  2. Investigator Specter traced $86M+ in suspected thefts; Arkham data shows nearly $87 million, including ~$42M ETH, $17.6M BTC and $16.5M USDT.

  3. Ledger told CryptoBilis buyers in the past 90 days not to set up devices, and existing users to migrate funds to a fresh seed phrase.

  4. Ledger has not confirmed the loss figure, the cause, or the number of affected customers.

Ledger, the Paris-based hardware wallet maker, is investigating reports of fund losses among Southeast Asian customers who bought devices from reseller CryptoBilis, and has asked the reseller to pause all sales and shipments pending the outcome of the probe. On-chain investigator Specter has traced more than $86 million in suspected thefts tied to addresses flagged by victims across Ethereum, Tron and Bitcoin — a figure Arkham data puts at nearly $87 million. Ledger has not confirmed the losses or their cause.

The company disclosed the investigation on Friday via its support account on X. "As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices," Ledger Support wrote. The company did not specify how many customers are affected or what mechanism caused the losses, and no tampering has been confirmed.

What should CryptoBilis customers do now?

Ledger issued two direct instructions to buyers:

  • Anyone who purchased a device from CryptoBilis in the past 90 days and has not yet set it up should not initialize it.
  • Anyone who has already set up a device from the reseller should move assets to a new Ledger device configured with a fresh seed phrase — the master backup that regenerates a wallet's private keys.

The guidance points to the operational risk inherent in third-party distribution. Hardware wallets are designed to keep private keys offline, but a device compromised before it reaches the buyer — for example, one shipped with a pre-filled recovery phrase an attacker already knows — leaves funds fully exposed. A reseller channel that inserts itself between manufacturer and customer breaks the custody assumption on which the entire product category rests, and the episode raises due-diligence questions about how Ledger vets and monitors its authorized sellers in the region.

How large are the suspected losses?

Pseudonymous investigator Specter said they traced theft addresses flagged in reports from Ledger users on X and Reddit and identified inflows from hundreds of victim wallets across several major blockchains, including Ethereum, TRON and Bitcoin. "Total losses $86M+," Specter wrote on X.

Arkham data shared by the investigator shows nearly $87 million held at those addresses, broken down as approximately:

  • $42 million in ETH
  • $17.6 million in BTC
  • $16.5 million in USDT

Ledger has not confirmed the figure, and it remains unclear whether every traced theft is linked to the reseller. The investigation is ongoing, and the company has not set a public timeline for its findings.

Why this matters beyond Ledger

The incident lands during an unusually damaging stretch for crypto security. Last month, exchange Bitget lost roughly $387 million in a hack investigators have tied to North Korea, with blockchain tracking firms Chainalysis and Elliptic tracing part of the haul. North Korean hackers also spent six months infiltrating Solana exchange Drift before a $285 million exploit; Drift has since published a repayment plan for users. In September, self-described white hat hackers withdrew $320 million in Bitcoin from Blockstream's Liquid sidechain before negotiating with the company.

Rival wallet maker Trezor has faced its own recent security headaches, including customer data exposed in a shipping partner breach and a compromise of its email systems last month.

For Ledger, the immediate commercial exposure is twofold: potential liability questions tied to its reseller network, and reputational pressure on a brand whose core selling point is that its supply chain never touches a user's keys. The company's response — pausing the reseller, warning recent buyers and advising seed-phrase migration — suggests it is treating the channel, not the device firmware, as the likely point of compromise. Customers who bought from CryptoBilis in the past 90 days should expect further guidance as the investigation concludes.

via x.com (Original)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles