Skip to content

Ledger CryptoBilis Drains: Reseller Paused as Losses Top $86M

Ledger CryptoBilis Drains: Reseller Paused as Losses Top $86M

Short answer: On October 9, 2026, hardware wallet maker Ledger said it was investigating fund losses reported by customers in Southeast Asia who had bought its devices from CryptoBilis, an official reseller in Indonesia, Malaysia and the Philippines, and asked the reseller to pause all sales and shipments. On-chain researchers estimated that more than $86 million was drained across Bitcoin, Ethereum and Tron. Ledger has not confirmed the total or the cause and told recent buyers not to set up devices from this seller.

What happened

Early on Friday, October 9, users began posting on X and Reddit that wallets set up on Ledger devices had been emptied. The common thread was the place of purchase: CryptoBilis, which Ledger lists as an authorized reseller in three Southeast Asian countries. Later the same day the Paris-based company published a notice:

  • Sales paused: Ledger asked CryptoBilis to stop all sales and shipments of its devices as a precaution while the investigation runs.
  • Advice to buyers: anyone who bought from the reseller in the past 90 days should not initialize an unused device; anyone who already set one up should consider moving funds to a new Ledger signer with a freshly generated recovery phrase.
  • No confirmed cause: the company said it would update customers as the probe progresses and has not said how many people were affected.

Ledger has described the problem as tied to this one reseller and says its own systems show no sign of a breach.

How big are the Ledger reseller losses?

Estimates rose through the day as investigators traced more addresses. None of them is confirmed by Ledger, and it is unclear whether every theft is linked to the reseller.

SourceEstimateDetail
Researcher tanuki42Over $72 millionFunds sent to a cluster of suspected theft addresses
Researcher Specter (Arkham data)About $86–87 millionRoughly $42M in ETH, $17.6M in BTC and $16.5M in USDT
Bitquery investigationAbout $93 million315 victim wallets across six chains, most of it USDT on Tron

Bitquery's timeline suggests a single actor controlled the keys: dozens of Tron wallets signed identical approvals within seconds, and 111 Bitcoin wallets were emptied in one block. It also reported that Tether froze 37 linked addresses holding about $10 million. Most victim wallets were first funded from June 2026 onward, which fits Ledger's 90-day warning window.

Was it a supply chain attack?

A supply chain attack means a product is compromised somewhere between the factory and the buyer, for example a device that is swapped, opened or shipped with a recovery phrase the attacker already knows. A hardware wallet keeps private keys offline, so this is one of the few ways funds on it can be stolen without the owner making a mistake.

Several voices pointed in this direction, though nothing was proven on October 9:

  1. Binance founder Changpeng Zhao said the available information pointed to a supply chain attack involving one vendor, with a small number of users possibly receiving fake or tampered devices.
  2. Former Mt. Gox CEO Mark Karpeles said the reports might connect to an issue he was already examining and asked victims to send photos of their device's circuit board.
  3. Investigators told affected users to contact SEAL 911, a volunteer security response group.

The incident lands in a rough year for wallet security. Coldcard owners lost more than $100 million to a firmware randomness flaw this summer, which we covered in our report on the Coldcard wallet hack.

What it means for you

If you never bought from CryptoBilis, there is no sign your Ledger is affected. Still, the case is a reminder of how hardware wallets fail in practice:

  • Check where your device came from. If it was bought from this reseller in the last 90 days, follow Ledger's advice: do not set it up, or move funds to a new device with a new seed.
  • Never accept a pre-made seed. A genuine wallet generates the recovery phrase on the device during setup. A phrase printed on a card or already filled in is a red flag.
  • Buy direct when you can. Ordering from the manufacturer removes a link in the chain where tampering can happen.
  • Watch for follow-up scams. Fake "recovery" services and phishing emails usually appear after headlines like this. No legitimate company will ask for your recovery phrase.

Key takeaways

  • Ledger on October 9, 2026, asked reseller CryptoBilis to pause sales after customers reported drained wallets.
  • CryptoBilis is an authorized reseller in Indonesia, Malaysia and the Philippines.
  • Researchers put losses at about $72–93 million across Bitcoin, Ethereum, Tron and other chains.
  • Ledger has not confirmed the cause; a supply chain compromise is the leading theory.

For a full checklist on storing coins safely, read our crypto wallet security guide.

Frequently asked questions

What happened with Ledger and CryptoBilis?

On October 9, 2026, Ledger said it was investigating fund losses among customers who bought devices from CryptoBilis, its authorized reseller in Indonesia, Malaysia and the Philippines, and asked the reseller to pause all sales and shipments. Researchers estimated more than $86 million was drained.

Is my Ledger wallet safe?

Ledger says the issue appears limited to devices bought from CryptoBilis and that its own systems show no sign of a breach. If you bought from that reseller in the last 90 days, Ledger advises not setting the device up, or moving funds to a new signer with a new recovery phrase.

How can a hardware wallet be hacked?

Keys on a hardware wallet stay offline, so most thefts come from the recovery phrase leaking. A device tampered with before delivery, or one shipped with a phrase the attacker already knows, can expose funds even if the owner does nothing wrong.

← Blog

Read next