New guide: Best Crypto Cards 2026
LIVE
BTC— ETH— XRP— BNB— SOL— DOGE— ADA— TON— TRX— LINK— AVAX— DOT—
Breaking Ledger CryptoBilis Thefts Top $86M as Ledger Halts Reseller Sales
News

Ledger CryptoBilis Thefts Top $86M as Ledger Halts Reseller Sales

Ledger CryptoBilis buyers report $86M+ in thefts. What we know, why a tampered device is suspected and what owners should do right now.

· · 5 min read
Ledger CryptoBilis theft illustration: a hardware wallet with a broken padlock leaking coins beside a torn shipping box

Explained in 30 seconds

  • Ledger is investigating losses among Southeast Asian buyers of its wallets from reseller CryptoBilis and has paused the reseller's sales.
  • Onchain researchers trace $72M to about $90M in suspected thefts across Bitcoin, Ethereum and Tron; Ledger has not confirmed a figure or a cause.
  • Recent CryptoBilis buyers should not set up their device, and anyone already using one should move funds to a new Ledger with a fresh seed.
In this article
  1. What happened with Ledger CryptoBilis buyers
  2. Tether froze the USDT, but not the rest
  3. Why a tampered device is the main theory
  4. What Ledger CryptoBilis owners should do now
  5. Why the Ledger CryptoBilis case matters
  6. Market and security context
  7. Ledger CryptoBilis: what to watch next
  8. FAQ
  9. Sources

Ledger is investigating reported thefts of more than $86 million from Southeast Asian customers who bought its hardware wallets from CryptoBilis, an authorized reseller. The company has paused the reseller’s sales and is telling recent Ledger CryptoBilis buyers not to set up their devices.

What happened with Ledger CryptoBilis buyers

On Friday, Oct. 9, Ledger’s support account said on X that it was looking into “reports of loss of funds from users in South East Asia” who bought products from CryptoBilis. As a precaution, Ledger asked the reseller to “pause all sales and shipments of Ledger devices.” According to The Block, CryptoBilis appears as an official Ledger reseller in Indonesia, Malaysia and the Philippines.

However, the size of the losses came from onchain investigators, not from Ledger. First, researcher tanuki42 flagged more than $72 million moving to a group of suspected theft addresses. Later, the analyst Specter traced inflows from hundreds of victim wallets on Bitcoin, Ethereum and Tron. Specter put total losses at “$86M+.” Arkham data shared by Specter shows nearly $87 million at those addresses, Decrypt reported. Security firm MistTrack puts the figure near $90 million, per The Defiant.

Bar chart of funds at suspected Ledger CryptoBilis theft addresses: $42M in ETH, $17.6M in BTC and $16.5M in USDT
Data: Arkham via Specter, reported by Decrypt. Chart: CryptoVank.

So far, Ledger has not confirmed any of these numbers. Likewise, it hasn’t said how many customers lost funds or what caused the losses.

Tether froze the USDT, but not the rest

Tether has frozen USDT at addresses linked to the thefts, The Defiant reported, citing MistTrack. That stops the stablecoin portion from moving. However, it covers only part of the haul. About $16.5 million of the traced funds were in USDT. By contrast, the larger ETH and BTC balances have no issuer that can block them.

A freeze is also not a refund. Victims usually need a legal process or a coordinated return before frozen tokens come back. Our stablecoins explainer covers why issuers like Tether can freeze tokens at all.

Why a tampered device is the main theory

Hardware wallets keep private keys offline. Because of that, a remote attacker can’t easily drain one. Instead, the weak point is what happens before the box reaches the buyer. CoinDesk and Decrypt both describe a possible supply-chain attack. In that scenario, a device arrives with a recovery phrase the attacker already knows. As a result, the buyer deposits funds into a wallet that was never private.

To be clear, nobody has confirmed this. CoinDesk notes there is no evidence that attackers breached Ledger’s own systems or wallet technology. Still, Ledger’s advice points the same way. It told anyone who already set up a CryptoBilis device to move funds to a new Ledger with a new seed. That step only makes sense if someone else might know the old seed.

What Ledger CryptoBilis owners should do now

If you bought a Ledger from CryptoBilis in the last 90 days:

  1. Don’t set it up. Ledger asked buyers who haven’t started setup to leave the device alone.
  2. If it’s already in use, move your funds. Send assets to a new Ledger signer and generate a fresh seed phrase on it.
  3. Never use a pre-filled recovery card. A genuine device creates your recovery words itself, on its own screen. A printed phrase in the box is a red flag.
  4. Report losses. Researchers have pointed victims to SEAL 911, a crypto security response group.

For everyone else, the lesson is simple. First, buy hardware wallets from the maker or from a seller you can verify. Then check the packaging. Our self-custody wallet setup guide walks through a safe first setup. Our guide on how to spot crypto scams covers the most common warning signs.

Why the Ledger CryptoBilis case matters

People usually pitch self-custody as the safe alternative to leaving coins on an exchange. This case shows the weak link can sit outside the device. If the theory holds, attackers didn’t break the hardware. Instead, they would have controlled the moment the wallet was created.

This matters because of the market Ledger serves. The company says it has sold more than 7 million devices, CoinDesk reported. In regions where many buyers rely on local resellers, the reseller becomes part of the security model. So a single bad link in that chain can reach hundreds of wallets at once.

Market and security context

Meanwhile, the news landed on a fragile day for crypto. At 17:11 UTC on Oct. 9, bitcoin traded at $82,614 and ether at $2,487, per CoinGecko. Both were up 2% to 3% over 24 hours after a week of heavy ETF outflows, which we covered in our bitcoin price report.

In addition, the incident adds to a costly year. DefiLlama data cited by CoinDesk shows Bitget lost over $350 million last month. Other major 2026 incidents include Liquid Network at about $320 million, Drift at $295 million and Kelp at $293 million. For more on how wallet threats are changing, see our explainer on crypto bunker mode.

Ledger CryptoBilis: what to watch next

  • Ledger’s findings. Did someone tamper with the devices, swap in fakes, or compromise them some other way?
  • Scope. Are other resellers or countries affected, or only CryptoBilis buyers?
  • Recovery. Can victims get the frozen USDT back? Meanwhile, do the stolen ETH and BTC move through mixers or bridges?
  • Reseller rules. Watch for any change in how Ledger vets and audits its sales partners.

FAQ

Was Ledger hacked?
There is no confirmed evidence that Ledger’s own systems or devices were compromised, CoinDesk reported. The probe centers on devices sold through CryptoBilis, and the cause is still unknown.

How much did thieves take in the Ledger CryptoBilis incident?
Onchain estimates range from about $72 million to about $90 million. Ledger has not confirmed a figure.

I bought my Ledger somewhere else. Am I affected?
Ledger’s warning covers purchases from CryptoBilis in the last 90 days. If you bought from another verified seller and created your own seed on the device, nothing reported so far points to your wallet.

Sources

This article is for information only and is not financial advice. Crypto prices are volatile; never invest more than you can afford to lose.

CryptoVank Desk covers Bitcoin, Ethereum, altcoins, DeFi and crypto regulation, checking every story against primary sources and live market data. Nothing we publish is financial advice.

Leave a Reply

Your email address will not be published. Required fields are marked *

Daily Brief

Signal over noise. Delivered daily.

The stories that moved crypto, in a three-minute read. Free, every morning.

No spam. Unsubscribe anytime.