Summary

  • Ledger is looking into claims of financial losses from Southeast Asian customers who purchased devices from the reseller CryptoBilis, requesting that the reseller halt sales and shipments.
  • The company advised anyone who bought from CryptoBilis within the last 90 days not to activate their device, and those who have already done so should transfer their assets to a new device with a different seed phrase.
  • Onchain investigator Specter has traced over $86 million in suspected thefts across Ethereum, Tron, and Bitcoin, although Ledger has not verified this amount or the reasons behind it.

Ledger has recommended that certain customers refrain from setting up their hardware wallets.

The Paris-based manufacturer announced on Friday that it is investigating reports of users in Southeast Asia losing funds after purchasing devices from a reseller named CryptoBilis.

“As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices,” the company's support account stated on X.

Ledger has urged anyone who made a purchase from CryptoBilis in the past three months not to set up their device if they haven't already. For those who have, it is advisable to transfer their assets to a new Ledger signer with a new seed phrase, which serves as the master backup to regenerate a wallet's private keys.

Ledger is investigating reports of loss of funds from users in Southeast Asia who purchased products from a reseller named CryptoBilis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices.…

— Ledger Support (@Ledger_Support) October 9, 2026

Ledger has not disclosed the cause of these losses or the number of affected customers. Hardware wallets are intended to keep private keys offline, yet if a device is compromised before reaching the buyer—such as being shipped with a recovery phrase known to an attacker—it can expose funds. There has been no confirmation of tampering.

The potential losses could be significant, possibly amounting to tens of millions of dollars. The pseudonymous crypto investigator Specter reported tracing theft addresses identified in reports from Ledger users on X and Reddit, discovering inflows from hundreds of victim wallets across Ethereum, Tron, and Bitcoin.

There have been reports on X and Reddit of wallet-draining incidents involving Ledger users.

I traced the theft addresses and identified inflows from hundreds of victim wallets across several major blockchains, including Ethereum, TRON, and Bitcoin.

Total losses $86M+… pic.twitter.com/c5dhQeAZ0l

— Specter (@SpecterAnalyst) October 9, 2026

“Total losses $86M+,” Specter stated. Data from Arkham shared by the investigator indicates nearly $87 million at these addresses, including around $42 million in ETH, $17.6 million in BTC, and $16.5 million in USDT. Ledger has yet to confirm this figure, and it remains unclear if all the thefts are connected to the reseller.

Competitor Trezor has also encountered security issues, including a breach of customer data due to a shipping partner incident and another email breach just last month.

Crypto Security Concerns Persist

This incident adds to a troubling trend in crypto security. Last month, Bitget reportedly lost approximately $387 million in a hack attributed to North Korea, with blockchain tracking firms Chainalysis and Elliptic tracing parts of the stolen funds.

North Korean hackers also infiltrated the Solana exchange Drift for six months, leading to a $285 million exploit, with Drift subsequently announcing plans to reimburse users. In September, self-proclaimed white hat hackers withdrew $320 million in Bitcoin from Blockstream’s Liquid sidechain before negotiating with the company.

Daily Debrief Newsletter

Stay updated with the latest news stories, original features, podcasts, videos, and more.