The company has launched an investigation into potentially tens of millions of dollars in crypt theft linked to hardware wallet purchased through CryptoBilis.
On-chain researchers estimate that somewhere between $72 million and $86 million may have been stolen, as Ledger begins investigating reports of these major crypto losses from users who bought hardware wallets from an authorized Southeast Asian reseller.
The hardware wallet manufacturer said there is no indication that its own infrastructure, systems, or services were compromised. However, users are piling on X to complain about substantial losses.
How Much Was Stolen?
The official support channel of Ledger on X confirmed yesterday evening that it was investigating user reports from customers of CryptoBilis, which is listed as an authorized reseller in Indonesia, Malaysia, and the Philippines. Ledger asked CryptoBilis to pause all sales and shipments for the time being.
More importantly, the post urged anyone who purchased a device from the reseller in the past 90 days and has not completed installation not to begin setup now. Customers already using such devices were advised to consider transferring their assets to a new Ledger signer using a newly generated seed phrase.
On-chain sleuth tanuki42 traced more than $72 million to suspected theft addresses, while fellow investigator Specter estimated losses exceed $86 million, across BTC, ETH, and TRX. Ledger’s official account didn’t confirm either figure, and it remains unclear whether the two estimates include overlapping transactions.
MistTrack noted that the losses could be closer to $90 million, while Tether reportedly froze USDT held in addresses connected with the incident.
What Happened?
The details on what exactly transpired are still scarce, but Binance co-founder Changpeng Zhao said the currently available information suggests a localized supply-chain attack involving one vendor, with a small number of customers potentially receiving counterfeit or physically tampered Ledger devices.
You may also like:
Former Mt. Gox CEO Mark Karpeles added that he had already been examining modified Ledger devices containing a hidden hardware implant and asked CryptoBilis to open units from its inventory to see whether similar components were present.
He said an implant he examined could monitor internal communications used to display recovery words, potentially allowing an attacker to capture a seed phrase even though the genuine Ledger Secure Element itself remained intact.
Ledger claimed that the reports appear limited to products sold through CryptoBilis and that it has “no indication that Ledger’s security infrastructure, systems, or services have been compromised.”
Meanwhile, users such as Edward Winz have publicly admitted to being victims of the incident, with $1 million reportedly stolen.
The Ledger incident comes just a month after its biggest competitor, Trezor, experienced one of its own, with the personal information of over 80,000 US users compromised.





Be the first to comment