Advertisement

Watch four AI agents manage money in public.

Subscription opening soon. Not financial advice.

Hack Database

Ledger: $86M Reportedly Drained From Wallets Sold by a Southeast Asian Reseller

Buyers of Ledger wallets from Malaysian reseller CryptoBilis report drained funds. Investigators estimate $86M+. Ledger says its systems were not hacked.

A Ledger Nano S. Nothing so far shows Ledger itself was at fault.

Key numbers

  • $86M+

    Stolen (estimated)

  • 98 (Arkham)

    Theft addresses

  • Bitcoin, Ethereum, Tron

    Chains

  • Suspected tampered devices

    Method

On Friday 9 October 2026, Ledger, the Paris company that makes the world's best-selling hardware wallets, told some of its own customers to leave their new devices in the box. Anyone in Southeast Asia who had bought a Ledger from a shop called CryptoBilis in the previous 90 days should not set it up. Anyone who already had should move their money to a different Ledger, with a brand new set of backup words.

The warning followed a day of reports on X and Reddit from buyers who said their wallets had been emptied. Specter, a pseudonymous on-chain investigator who follows stolen money across public blockchains, estimated that more than $86 million had flowed out of hundreds of victim wallets on Bitcoin, Ethereum and Tron. Arkham Intelligence, a blockchain analytics firm, counted 98 addresses linked to the thefts holding about $86.96 million. MistTrack, the tracking service run by the security firm SlowMist, said the losses it was following were close to $90 million. A second researcher, tanuki42, put the figure at about $72 million. None of these numbers has been confirmed by Ledger, and it is not clear whether all of them count the same transactions.

Bar chart of loss estimates on 9 October: MistTrack about $90M, Arkham $87M, Specter $86M, tanuki42 $72MCMZ chart. Data: MistTrack, Arkham, Specter, tanuki42
Four estimates of the losses on day one.

Ledger was careful about what it was and was not saying. "As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices," the company said. It added: "No reports were made of products purchased directly from Ledger, and Ledger's infrastructure, systems and services were not compromised." Nothing published so far shows Ledger was at fault. CryptoBilis has not been accused of any crime and had not issued a public statement by the evening of 9 October.

Advertisement

Powered by Cyntri AI

The technology behind this newsroom. Built by Cyntri AI.

AI-assisted publishing, content pipelines and analytics. Crypto Media Zone is our working example.

Powered by Cyntri AI

What a hardware wallet is, and why the words matter

A hardware wallet is a small gadget, about the size of a car key fob or a USB stick, that holds the secret code controlling someone's crypto. The coins themselves live on a blockchain, a public record that works like a company's share register. What the device keeps is the private key, the signature that authorises moving them. Keeping that key on a device that never touches the internet is like keeping share certificates in a home safe rather than on a laptop.

When a new Ledger is first switched on, it creates a recovery phrase, also called a seed phrase: 24 ordinary English words shown on its screen for the owner to copy onto a card. Those words are the master backup. Type them into any wallet anywhere and the key is rebuilt and every coin can be moved, with no PIN, no bank and no way to cancel the payment afterwards. The closest everyday comparison is the key to a safe-deposit box, written on paper. Whoever reads the paper owns the box.

That is why the box a device arrives in matters so much. If someone has interfered with a wallet before it reaches its buyer, they may already know the words, or be able to learn them the moment the screen displays them. The owner then deposits money into a safe that someone else already has the key to.

The leading theory: tampered boxes

Ledger has not said how the money was taken. The theory most investigators raised on 9 October is a supply-chain attack, meaning the goods were interfered with somewhere between the factory and the buyer, in the way a tampered medicine bottle is a problem with the shelf rather than the drug company.

Changpeng Zhao, the founder of the crypto exchange Binance, wrote that the losses appeared "localized to a supply chain attack with one vendor", with a small number of buyers likely to have received "fake (or tampered) Ledgers". He asked the industry to help recover the funds.

Mark Karpelès, the former chief executive of the collapsed bitcoin exchange Mt. Gox, has been taking apart suspect Ledger units for weeks and showed photos of a modified Nano X in September. On 9 October he posted pictures of a Ledger he said came from Malaysia, still sealed in undamaged plastic wrap, with a hidden implant tucked behind the screen: a mobile data chip, an antenna, an eSIM (a built-in SIM card) and a small controller wired into the device. In plain terms, a phone hidden inside a safe, able to read the screen and send what it saw. Karpelès asked CryptoBilis to open its unsold stock for inspection. Reporting by Crypto Briefing noted that his device and the CryptoBilis losses had not been proven to be connected.

The idea is not new. In April 2026 a Brazilian security researcher bought a Ledger Nano S Plus from a Chinese online marketplace at the normal price and found the real security chip had been swapped for a cheap ESP32-S3 controller made by Espressif Systems, with its markings scraped off. The fake recorded every PIN and recovery phrase and sent them to the criminals' servers. The box even carried a QR code leading to a counterfeit version of Ledger's app. The genuine app's "Genuine Check" caught it.

Taylor Monahan, a well-known security researcher, warned on the same day that panic about a supposed flaw in all Ledgers was itself a danger. Scammers often follow headlines like these with fake "migration" apps and emails urging owners to move their funds, which then steal them.

Who CryptoBilis is

CryptoBilis is a crypto hardware shop based in Kuala Lumpur, Malaysia. It is listed as an authorised Ledger reseller in Malaysia, Indonesia and the Philippines, and also sells Trezor devices. In January 2025 it bought Isawwwshop, a Philippine hardware wallet retailer, and it has hosted large Bitcoin Pizza Day events in Kuala Lumpur and Manila, one of them with Trezor's maker SatoshiLabs. Being authorised means Ledger approved the shop to sell its products. It does not mean Ledger packs or checks every box the shop ships.

Where the money went

Decrypt, citing Arkham data, broke the tracked total down as roughly $42 million in ether, about $17.6 million in bitcoin and about $16.5 million in Tether (USDT), a stablecoin, which is a digital dollar meant to stay worth exactly $1. Most of the USDT moved on Tron, a blockchain widely used in Asia for cheap dollar transfers.

Stablecoins are the one part of the haul that can be stopped. Tether, the company that issues USDT, can freeze tokens at any address, much as a bank can freeze an account. MistTrack said it was "seeing Tether freeze a significant number of USDT across addresses linked to this incident". Tether has not said how much. Bitcoin and ether have no issuer and no freeze button. Once they move, only exchanges that receive them can refuse to pay out.

What an ordinary buyer should do

Buy a hardware wallet only from the maker's own website or from a shop the maker lists as a reseller, and treat cheap or third-party marketplace listings as suspect. This case shows that even an authorised shop is a link in the chain, so the checks below apply to every box.

When it arrives, a genuine new Ledger comes with blank recovery cards and creates the 24 words itself, on its own screen, during setup. If the box contains a card with words already printed or written on it, or a scratch card with words under the foil, or if the device is already set up and asks only for a PIN, it is not safe. Do not use it and do not send it money.

Set it up only with the app downloaded from Ledger's own website, never from a QR code or link in the box, and let the app run its Genuine Check. Any hint of a broken seal, loose case, unusual weight or extra parts is a reason to stop.

Anyone who bought from CryptoBilis in the last 90 days should follow Ledger's advice: if the device is unused, leave it that way. If it is in use, buy a new Ledger directly from Ledger, set it up with fresh words, and move everything across. Never type the old words into a website or app that offers to "secure" or "migrate" them. Victims can report losses to Ledger support, to the police, and to the Security Alliance (SEAL), a volunteer incident-response group that asked affected users to contact it.

The aftermath

By the end of 9 October, Ledger had not confirmed a loss figure, a cause, or how many customers were affected. CryptoBilis had paused Ledger sales at Ledger's request and had not made a public statement. No arrests, charges or suspects had been announced, and no law enforcement agency had said it was investigating. Tether's freezes may preserve part of the USDT for victims, though a frozen token is not a refund, and recovering it normally takes a court or police request. The bitcoin and ether, roughly two thirds of the tracked total, had no such brake.

For Ledger the damage is to trust rather than to its code, and it has been here before. In July 2020 a breach of its online shop's database leaked about 1 million customer email addresses, plus the names, phone numbers and home addresses of roughly 272,000 buyers, which later led to years of phishing and even threatening letters. In May 2023 it announced Ledger Recover, an optional paid service that backs up an encrypted copy of the recovery phrase with outside firms including Coincover, and faced a backlash from customers who had believed the words could never leave the device. In December 2023 attackers phished a former employee and slipped malicious code into Ledger Connect Kit, software used by crypto websites, draining about $600,000 before it was removed. In January 2025 the company's co-founder David Balland was kidnapped in France and held for ransom.

The CryptoBilis case lands during a hard year for hardware wallets. Trezor's shipping contractor ShipMonk was breached, Trezor's customers were targeted by fake support staff in a $282 million theft, and Coldcard owners lost money to a flaw in how keys were generated. In each case the device did roughly what it promised. The weak point was somewhere around it: a warehouse, a phone call, a box.

What this teaches

  • A hardware wallet is only as safe as the route it took to its owner. Buy direct from the maker where possible.
  • A genuine device always creates its own recovery phrase on its own screen. Any words supplied in the box mean the wallet is compromised.
  • Authorised reseller status is permission to sell, not a guarantee that every box was checked.
  • Use only the maker's official app, downloaded from its own website, and run its genuine-device check.
  • Stablecoins like USDT can be frozen by their issuer; bitcoin and ether cannot. Speed of reporting matters.
  • After a scare, expect fake 'migration' apps and emails. Never type a recovery phrase into anything except a new hardware wallet.
Advertisement

AI agents and automation

Could AI answer your customers from your own documents?

Assistants trained on your files, website and FAQs, with limits on what they can say. Fixed price before any work starts.

AI agents and automation