0x7fca616c7fca…7fca6169
Ledger Probes Losses Tied to Southeast Asian Reseller CryptoBilis
Hardware wallet maker Ledger has suspended sales at authorized reseller CryptoBilis as on-chain researchers estimate $72M–$86M in suspected losses across Bitcoin, Ethereum and Tron. The investigation remains open.

Outputs
On-chain researchers tanuki42 and Specter flagged 8 wallet addresses tied to $72M–$86M in suspected losses across Bitcoin, Ethereum and Tron
Ledger has asked authorized reseller CryptoBilis to suspend sales and shipments in Indonesia, Malaysia and the Philippines
Customers who purchased devices from CryptoBilis in the past 90 days have been advised not to initialize them
Ledger says its infrastructure, systems and services were not compromised and reports involve only reseller-sourced units
SEAL amplified the findings and urged affected users to contact its incident-response team
On-chain researchers have identified roughly $72 million to $86 million in suspected cryptocurrency thefts involving addresses tied to a Southeast Asian reseller of Ledger hardware wallets, according to X posts by investigators tanuki42 and Specter.
Hardware wallet manufacturer Ledger has asked authorized reseller CryptoBilis to suspend sales and shipments of its devices while it investigates reports of customer fund losses across multiple markets. CryptoBilis operates in Indonesia, Malaysia and the Philippines, three of the region's largest retail crypto markets.
What did Ledger tell affected customers?
In a post on X, Ledger advised customers who purchased devices from CryptoBilis within the past 90 days not to initialize their units. Users who had already set up their devices were told to consider transferring assets to a new Ledger signer generated with a freshly created recovery phrase.
Ledger has not disclosed how many customers may be affected, the value of reported losses or the precise failure mode. The company has also not confirmed whether the devices themselves were tampered with prior to delivery, leaving open whether the compromise sits in hardware, firmware or seed-phrase generation.
How large are the suspected losses?
Researcher tanuki42 flagged eight wallet addresses allegedly linked to more than $72 million in losses, while Specter estimated losses exceeding $86 million across Bitcoin, Ethereum and Tron. Neither estimate has been validated by Ledger, and the extent of any overlap between the on-chain activity and the CryptoBilis reseller inquiry remains unclear.
Crypto security organization Security Alliance (SEAL), a volunteer incident-response group, amplified tanuki42's findings on X and urged anyone whose funds were sent to the identified addresses to contact its team. SEAL did not publish its own loss estimate or assign a cause.
What has Ledger said about its infrastructure?
"Ledger's infrastructure, systems and services were not compromised," the company said in a statement to Cointelegraph. Ledger added that the incident appeared isolated to the reseller and its market, and that it had received no reports involving devices purchased directly from the manufacturer.
The action against CryptoBilis was framed by Ledger as a precaution. CryptoBilis remains listed as an authorized reseller in Indonesia, Malaysia and the Philippines on Ledger's support materials, even as sales and shipments are paused.
Why does this matter for the hardware wallet market?
The episode puts renewed focus on distribution channels for self-custody devices. Hardware wallets are sold on the premise that private keys never leave the device, but that security model depends on supply-chain integrity and on buyers sourcing units from trusted vendors.
A confirmed link between compromised reseller inventory and eight-figure thefts would test the practical limits of that model in markets where gray-market imports and third-party distributors carry meaningful share. It would also put pressure on manufacturers to publish verifiable device-authenticity checks and on resellers to document provenance end to end.
What happens next?
Ledger's investigation remains open, and the company has not committed to a timeline for findings or to a decision on CryptoBilis's reseller status. Customers holding funds on CryptoBilis-sourced devices purchased in the past 90 days face a narrow migration window before the on-chain pattern is either confirmed, ruled out or formally attributed to the reseller channel.
via x.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles