Ledger is investigating reported thefts of more than $86 million from Southeast Asian customers who bought its hardware wallets from CryptoBilis, an authorized reseller. The company has paused the reseller’s sales and is telling recent Ledger CryptoBilis buyers not to set up their devices.
What happened with Ledger CryptoBilis buyers
On Friday, Oct. 9, Ledger’s support account said on X that it was looking into “reports of loss of funds from users in South East Asia” who bought products from CryptoBilis. As a precaution, Ledger asked the reseller to “pause all sales and shipments of Ledger devices.” According to The Block, CryptoBilis appears as an official Ledger reseller in Indonesia, Malaysia and the Philippines.
However, the size of the losses came from onchain investigators, not from Ledger. First, researcher tanuki42 flagged more than $72 million moving to a group of suspected theft addresses. Later, the analyst Specter traced inflows from hundreds of victim wallets on Bitcoin, Ethereum and Tron. Specter put total losses at “$86M+.” Arkham data shared by Specter shows nearly $87 million at those addresses, Decrypt reported. Security firm MistTrack puts the figure near $90 million, per The Defiant.

So far, Ledger has not confirmed any of these numbers. Likewise, it hasn’t said how many customers lost funds or what caused the losses.
Tether froze the USDT, but not the rest
Tether has frozen USDT at addresses linked to the thefts, The Defiant reported, citing MistTrack. That stops the stablecoin portion from moving. However, it covers only part of the haul. About $16.5 million of the traced funds were in USDT. By contrast, the larger ETH and BTC balances have no issuer that can block them.
A freeze is also not a refund. Victims usually need a legal process or a coordinated return before frozen tokens come back. Our stablecoins explainer covers why issuers like Tether can freeze tokens at all.
Why a tampered device is the main theory
Hardware wallets keep private keys offline. Because of that, a remote attacker can’t easily drain one. Instead, the weak point is what happens before the box reaches the buyer. CoinDesk and Decrypt both describe a possible supply-chain attack. In that scenario, a device arrives with a recovery phrase the attacker already knows. As a result, the buyer deposits funds into a wallet that was never private.
To be clear, nobody has confirmed this. CoinDesk notes there is no evidence that attackers breached Ledger’s own systems or wallet technology. Still, Ledger’s advice points the same way. It told anyone who already set up a CryptoBilis device to move funds to a new Ledger with a new seed. That step only makes sense if someone else might know the old seed.
What Ledger CryptoBilis owners should do now
If you bought a Ledger from CryptoBilis in the last 90 days:
- Don’t set it up. Ledger asked buyers who haven’t started setup to leave the device alone.
- If it’s already in use, move your funds. Send assets to a new Ledger signer and generate a fresh seed phrase on it.
- Never use a pre-filled recovery card. A genuine device creates your recovery words itself, on its own screen. A printed phrase in the box is a red flag.
- Report losses. Researchers have pointed victims to SEAL 911, a crypto security response group.
For everyone else, the lesson is simple. First, buy hardware wallets from the maker or from a seller you can verify. Then check the packaging. Our self-custody wallet setup guide walks through a safe first setup. Our guide on how to spot crypto scams covers the most common warning signs.
Why the Ledger CryptoBilis case matters
People usually pitch self-custody as the safe alternative to leaving coins on an exchange. This case shows the weak link can sit outside the device. If the theory holds, attackers didn’t break the hardware. Instead, they would have controlled the moment the wallet was created.
This matters because of the market Ledger serves. The company says it has sold more than 7 million devices, CoinDesk reported. In regions where many buyers rely on local resellers, the reseller becomes part of the security model. So a single bad link in that chain can reach hundreds of wallets at once.
Market and security context
Meanwhile, the news landed on a fragile day for crypto. At 17:11 UTC on Oct. 9, bitcoin traded at $82,614 and ether at $2,487, per CoinGecko. Both were up 2% to 3% over 24 hours after a week of heavy ETF outflows, which we covered in our bitcoin price report.
In addition, the incident adds to a costly year. DefiLlama data cited by CoinDesk shows Bitget lost over $350 million last month. Other major 2026 incidents include Liquid Network at about $320 million, Drift at $295 million and Kelp at $293 million. For more on how wallet threats are changing, see our explainer on crypto bunker mode.
Ledger CryptoBilis: what to watch next
- Ledger’s findings. Did someone tamper with the devices, swap in fakes, or compromise them some other way?
- Scope. Are other resellers or countries affected, or only CryptoBilis buyers?
- Recovery. Can victims get the frozen USDT back? Meanwhile, do the stolen ETH and BTC move through mixers or bridges?
- Reseller rules. Watch for any change in how Ledger vets and audits its sales partners.
FAQ
Was Ledger hacked?
There is no confirmed evidence that Ledger’s own systems or devices were compromised, CoinDesk reported. The probe centers on devices sold through CryptoBilis, and the cause is still unknown.
How much did thieves take in the Ledger CryptoBilis incident?
Onchain estimates range from about $72 million to about $90 million. Ledger has not confirmed a figure.
I bought my Ledger somewhere else. Am I affected?
Ledger’s warning covers purchases from CryptoBilis in the last 90 days. If you bought from another verified seller and created your own seed on the device, nothing reported so far points to your wallet.
Sources
- CoinDesk: Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen
- The Block: Ledger investigates wallet drains involving CryptoBilis buyers
- Decrypt: Ledger probes potential theft of $87M tied to crypto wallet reseller
- The Defiant: Tether freezes USDT linked to Ledger user thefts, MistTrack says
- Crypto Briefing: Tether freezes USDT linked to Ledger user thefts
- CoinGecko market data, Oct. 9, 2026, 17:11 UTC
This article is for information only and is not financial advice. Crypto prices are volatile; never invest more than you can afford to lose.



