Ledger is investigating reports of lost funds from users in Southeast Asia who bought hardware wallets through CryptoBilis, a reseller listed by Ledger in Indonesia, Malaysia and the Philippines. On October 9, Ledger said it had asked CryptoBilis to pause sales and shipments and issued precautionary guidance for people who bought from the reseller during the previous 90 days.
The headline loss figure needs care. Onchain researchers have linked more than $72 million—and later more than $86 million—across Bitcoin, Ethereum and Tron to suspected theft addresses. Ledger has not confirmed those totals, the number of affected customers or the cause. The case is therefore an active investigation with a large reported estimate, not a completed forensic finding.
Ledger's warning is specific; the loss estimate is still provisional
The Block reported that Ledger told recent CryptoBilis customers not to initialize an unopened device. Customers who had already set one up were advised to consider moving assets to a new Ledger signer with a new seed. Ledger also directed users to its official support channels and said it would provide updates as the investigation progressed.
Those measures show that Ledger considers the reseller channel serious enough to justify immediate precautions. They do not, by themselves, establish how the losses occurred. Public reporting has raised the possibility of altered or counterfeit devices, compromised packaging or another failure somewhere in the distribution and setup process. At this stage, none of those possibilities has been confirmed as the entry point.
| Claim | Current status | What it means |
|---|---|---|
| Ledger is investigating losses connected to CryptoBilis purchases | Confirmed by Ledger | The company has opened an investigation focused on a specific reseller channel in Southeast Asia. |
| CryptoBilis was listed as an official reseller | Confirmed on Ledger's reseller directory | Authorization did not remove the need to investigate individual devices and the distribution chain. |
| Suspected losses exceeded $86 million | Onchain researcher estimate; not confirmed by Ledger | The amount may change as addresses, overlaps and ownership are verified. |
| The incident was a supply-chain attack | Working hypothesis | Tampering is plausible, but the responsible method and point of compromise remain unproven. |
| Ledger's infrastructure was breached | No evidence disclosed | The public warning is tied to CryptoBilis purchases, not a confirmed compromise of Ledger's systems or all Ledger devices. |
Where the $86 million figure comes from
The first widely cited estimate came from onchain researcher tanuki42, who said more than $72 million had reached a group of suspected theft addresses. Researcher Specter later put the figure above $86 million after adding activity across Bitcoin, Ethereum and Tron. Specter initially referred to hundreds of victim wallets, then clarified that the actual number affected was not known.
Blockchain transfers are public, but attribution is not automatic. A researcher can group addresses using timing, transaction patterns and fund flows, yet still face uncertainty about whether every address belongs to the same actor, whether transactions represent theft, and whether two analysts counted overlapping flows. USD totals also move with asset prices. Until Ledger, investigators or law enforcement publish a reconciled account, $86 million should be treated as a reported estimate rather than a verified customer-loss figure.
A newer estimate can also be larger without proving that more funds were taken after Ledger's warning. It may reflect additional networks, newly identified addresses or a different attribution method. Readers should look for a transparent address list and methodology, not just the largest headline number.
Why “official reseller” does not settle the security question
Ledger's public reseller directory listed CryptoBilis in three Southeast Asian markets when this article was prepared. That status indicates a commercial relationship, but it cannot prove that every unit remained untouched after manufacture. Hardware can pass through storage, fulfillment and last-mile delivery before reaching a buyer. The investigation must identify where custody changed, which batches and serial ranges are involved, and whether reported victims received devices from the same route.
Ledger's genuineness documentation explains that a cryptographic check can authenticate the device's Secure Element and firmware. The same document also states that the check cannot detect every unauthorized physical modification if the genuine Secure Element remains in place. That limitation does not prove a hardware implant existed here; it explains why a successful authenticity check and a later tampering investigation are not necessarily contradictory.
The decisive evidence would include examined devices, packaging and purchase records; a reproducible description of any modification; wallet-generation and signing behavior; and a match between those findings and the onchain theft pattern. Photos or isolated anecdotes can guide investigators, but they are not a substitute for that chain of evidence.
Why a new device must also use a new seed
A hardware wallet protects the keys derived from its recovery phrase. If the original seed may have been exposed during setup, restoring that same seed on a clean device reproduces the same wallet and leaves the underlying risk unchanged. Ledger's advice therefore combines two separate controls: use another signer and create a new seed.
Moving funds should be handled as a security migration, not as an ordinary device replacement. The destination addresses must belong to the new seed, and the transfer should be verified on the trusted device display. Ledger's hardware-wallet guidance says the recovery phrase should be generated by the device, kept offline and never shared. Anyone claiming to be support and asking for a seed phrase, private key, PIN or “verification transfer” should be treated as an impersonator.
What recent CryptoBilis customers should do now
- If the device is unopened or not initialized: do not begin setup. Keep the device, packaging, invoice and shipping record available for the investigation.
- If the device was already initialized: follow Ledger's public guidance and consider moving assets to a different trusted signer using a newly generated seed. Reusing the old recovery phrase does not create new keys.
- Use only official support: navigate directly to Ledger Support. Do not trust links, phone numbers or recovery services sent in unsolicited messages.
- Preserve evidence: retain transaction IDs, receiving addresses, purchase dates, reseller records and case numbers. Do not post a seed phrase or private key, even when seeking help.
- Check each address on the device: malware on a computer or phone can replace a destination address on screen. Verify the complete address on the signer's trusted display before approving.
These steps reduce exposure while facts are still developing. They do not imply that every CryptoBilis device is compromised or that losses can be recovered. Customers should monitor Ledger's official channels for a narrower affected window, batch information or revised instructions.
Readers comparing self-custody with exchange-based custody can create a KTX account and review the security controls, withdrawal rules, fees and products available in their region. An exchange account changes who controls the signing keys; it does not eliminate phishing, account-security, platform or withdrawal risks.
What would materially change the story
The investigation needs to answer four questions: how many independently verified victims there are, which devices or orders are common to them, how the attacker obtained signing authority, and how much of the traced value represents actual victim losses. A detailed technical report from Ledger, a verified device analysis, or a law-enforcement attribution would carry more weight than social-media speculation.
Fund freezes and recoveries also matter, but they answer a different question. They may reduce the final financial loss without explaining how keys were compromised. Conversely, a higher onchain estimate may change the scale while leaving the attack mechanism unresolved. Keeping those questions separate is the clearest way to follow the case.
Frequently Asked Questions
Did Ledger confirm that $86 million was stolen?
No. Ledger confirmed that it was investigating reported losses connected to CryptoBilis purchases. The amount above $86 million came from an onchain researcher and remained unconfirmed when this article was prepared.
Does this mean all Ledger devices are unsafe?
No evidence disclosed so far supports that conclusion. Ledger's warning focuses on products bought from CryptoBilis in Southeast Asia during a specific recent period. The scope may change as the investigation develops.
Can I move the old seed to a new hardware wallet?
That would restore the same keys. If the old seed may be compromised, the security benefit comes from generating a new seed on a trusted signer and moving assets to addresses derived from it.
Risk disclosure: This article is for information only and is not financial, legal or cybersecurity advice. Digital assets can be lost through key exposure, fraud, operational failure and irreversible transactions. Follow verified manufacturer guidance and seek qualified assistance for material losses.