Ledger CryptoBilis Losses Prompt Sales Halt and Wallet Warning
Ledger is investigating reported thefts from customers who bought its devices through Southeast Asian reseller CryptoBilis, after an on-chain investigator traced more than $86 million in suspected losses.

The Ledger CryptoBilis case put hardware-wallet security back in focus on Friday, October 9, 2026, when the Paris-based device maker said it was investigating reports that customers in Southeast Asia who bought its products through reseller CryptoBilis had lost funds. CoinDesk reported that a pseudonymous blockchain investigator traced more than $86 million in suspected thefts from hundreds of wallets, a figure Ledger has not confirmed.
What happened
Ledger's support account said on X that it had asked CryptoBilis to pause all sales and shipments of Ledger devices "as a precaution, and pending the results of our investigation," according to Decrypt. The company told anyone who had bought from the reseller in the past 90 days not to set up the device if they had not already done so. Customers who had already activated a wallet were told to consider moving their assets to a new Ledger device with a newly generated recovery phrase, the master backup from which a wallet's private keys can be regenerated.
The loss estimate came from Specter, an on-chain investigator who said on X that they had traced theft addresses flagged in user reports on X and Reddit and found inflows from hundreds of victim wallets across Ethereum, Tron and Bitcoin. "Total losses $86M+," Specter wrote. Arkham data shared by the investigator showed nearly $87 million at those addresses, including about $42 million in ETH, $17.6 million in BTC and $16.5 million in USDT, Decrypt reported.
Ledger acknowledged the reports but did not confirm the amount, the number of affected customers or the cause. Both outlets stressed that it remained unclear whether every theft was linked to the reseller, and CoinDesk said there had been no independent confirmation of the total.
Why it matters
The Ledger CryptoBilis episode matters because hardware wallets are sold on a simple promise: private keys stay offline, out of reach of exchange hacks and malware. Ledger, founded in 2014, says it has sold more than 7 million devices worldwide, CoinDesk noted, which makes any security question around its products relevant to a broad slice of self-custody users.
The current investigation, however, concerns devices sold through a third party, and CoinDesk said there was no confirmed evidence that Ledger's own systems or wallet technology had been compromised. One possible explanation both outlets raised is a supply-chain attack, in which devices are tampered with before reaching buyers. An attacker could, for example, ship a device with a recovery phrase the attacker already knows and later sweep any funds deposited. Decrypt emphasized that no tampering has been confirmed. The distinction matters: a reseller problem would point to distribution controls and buyer verification, while a flaw in Ledger's own stack would be a far larger issue.
The timing adds to an already heavy year for crypto security. CoinDesk cited DefiLlama data showing that Bitget lost more than $350 million to an exploit last month, while other major incidents included Liquid Network at about $320 million, Drift at $295 million and Kelp at $293 million. Decrypt put the Bitget loss at roughly $387 million and said investigators have tied it to North Korea; the two outlets' figures differ, and we attribute each. We covered the forensic work on that theft in our report on the Bitget zero-day investigation, and the Liquid sidechain withdrawal in our piece on Liquid Network L-BTC.
Rival Trezor has had its own problems, including customer data exposed in a shipping partner breach and a breach of its email last month, Decrypt reported. Neither case involved Ledger.
What's next
Ledger said it would provide updates as the investigation progresses. The key questions are whether the reported thefts share a common cause, whether that cause sits with the reseller's devices or elsewhere, and how many customers were affected. Until those answers arrive, the Ledger CryptoBilis figure should be read as an on-chain estimate rather than a confirmed loss.
For the wider market, the case is a reminder that the security of a self-custody device depends on its entire path from factory to user. Buyers who acquired devices through unofficial channels face the hardest questions, and Ledger's own guidance to recent CryptoBilis customers, to hold off on setup or move funds to a device with a fresh recovery phrase, is the clearest indication of how seriously the company is treating the reports.
Any confirmation of device tampering would likely push manufacturers and resellers toward stricter authentication of devices at activation. Any finding that the losses stem from phishing or other causes unrelated to the hardware would narrow the story considerably. This article is for information only and is not investment advice.
This article is for information only and is not investment advice.