Ledger Investigates $86 Million Wallet Drain Linked to CryptoBilis Reseller

1 hour ago 7 sources negative

Key takeaways:

  • Suspected supply-chain tampering threatens hardware wallet trust, pressuring BTC and ETH self-custody demand.
  • No core Ledger compromise suggests targeted supply-chain attack, not systemic Bitcoin, Ethereum, or TRON weakness.
  • Rotate seeds and verify devices; affected BTC, ETH, TRX wallets signal supply-chain exposure.

Ledger, the world’s largest hardware wallet manufacturer, is investigating reports of significant wallet losses now estimated at more than $86 million. The probe centers on users in Southeast Asia who purchased devices from reseller CryptoBilis, an official Ledger reseller in Indonesia, Malaysia and the Philippines.

Ledger’s support account warned customers who bought from CryptoBilis in the last 90 days not to initialize their devices if they had not already done so, and advised those who had set up a Ledger device to consider moving assets to a new Ledger signer with a new seed. The company has also asked CryptoBilis to pause all sales and shipments while the investigation continues. No evidence has emerged that Ledger’s core infrastructure was compromised.

Onchain researcher tanuki42 said more than $72 million had moved to a group of suspected theft addresses and asked affected users to contact crypto security response group SEAL 911. Another researcher, Specter, later estimated the losses at more than $86 million after tracing funds sent to addresses on Bitcoin, Ethereum and Tron. Specter initially said the funds came from hundreds of victim wallets, but later clarified the exact number of affected wallets was not yet known. The figures have not been independently confirmed.

Former Mt. Gox CEO Mark Karpeles said the reports could be linked to an issue he was already investigating and asked affected users to send pictures of their device circuit boards to check for tampering. Binance co-founder Changpeng “CZ” Zhao said available information suggested a supply chain attack involving one vendor, adding that a small number of users may have bought fake or tampered Ledger devices. He said he expects BNB ecosystem players and the wider industry to help trace and recover the funds, while noting that self-custody comes with extra responsibilities.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.