Ledger is investigating reports of large fund losses among buyers of its devices in Southeast Asia who purchased from official reseller CryptoBilis. On-chain researchers put the suspected thefts between $72 million and $86 million across bitcoin, ethereum and tron holdings. The hardware wallet maker says the root cause is still unclear.
CryptoBilis is listed as an official Ledger reseller in Indonesia, Malaysia and the Philippines. Ledger said it has asked the company to pause all sales and shipments while the review proceeds. The company has not said how many devices are implicated and has not confirmed any tampering. The Block first reported the losses on Friday, and the story moved fast once researchers began tracing the outgoing transfers.
Ledger’s support account told buyers from the past 90 days to hold off on setup. The recommendation covers anyone who has not initialized a device yet, and those who already set one up are told to move funds to a wallet with a new seed.
“If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed). We will continue to inform customers of updates as the investigation progresses.”
The loss estimates come from independent on-chain analysis and have not been verified. Researcher tanuki42 traced more than $72 million in suspected theft proceeds to a cluster of addresses. Another researcher, Specter, later raised the figure to more than $86 million after following flows on Bitcoin, Ethereum and Tron networks. Specter initially described the outflows as coming from hundreds of victim wallets, then said the number of affected wallets cannot yet be confirmed. It is also unclear whether the two estimates cover the same set of transactions.
Former Mt. Gox CEO joins the effort
Mark Karpeles, the former chief executive of the collapsed Mt. Gox exchange, said the reports may connect to a case he was already investigating. He asked affected users to contact him and to send photos of their device circuit boards, which he says can reveal whether the hardware was modified after leaving the factory.
Binance co-founder Changpeng Zhao also weighed in. Based on the information available, he said, the pattern looks like a supply chain attack involving a single vendor, meaning some buyers may have received fake or tampered units. Zhao urged the industry to help trace the funds and added that “self-custody comes with extra responsibilities.” Researchers asked victims to report their cases to the crypto security group SEAL 911.
| Researcher | Estimate | Scope |
|---|---|---|
| tanuki42 | More than $72 million | Funds moved to a group of suspected theft addresses |
| Specter | More than $86 million | Traces across Bitcoin, Ethereum and Tron |
If the higher estimate holds, the incident would rank among the larger hardware-wallet related thefts of 2026, and it would not have touched a single exchange or protocol. Losses of this kind are hard to police because the seed phrase sits with the buyer. A tampered device can leak its recovery phrase at the moment of setup, at which point the attacker has full access to every deposit that follows.
Reseller channels have drawn scrutiny before. Built-in protections depend on how devices arrive at the front door. Buyers who order through third parties rather than Ledger’s own store have less certainty that the seal and packaging they received match the original item. Ledger’s guidance effectively treats the past three months of reseller purchases as untrusted until the investigation concludes.
Industry figures have moved quickly because the story could put off new users who are already uneasy about self-custody. Zhao said he expects companies across the BNB ecosystem and the wider industry to help trace and recover the funds. Karpeles’s open request for circuit board photos is a practical step. Production variances and firmware versions are recorded, and a board that differs from the reference can serve as evidence.
Why hardware wallets are hard to replace
Hardware wallets sit at the bottom of most security advice because they keep private keys offline, away from the malware that drains browser wallets. That protection only works if the device itself is genuine. A compromised unit defeats the entire model: the buyer follows every best practice, writes down the recovery phrase on paper, and still hands over the keys on first use. The apparent vector here, if the supply chain theory is right, would be a tampered unit preloaded with altered firmware or swapped parts. Karpeles’s request for board photos suggests a defect that can be spotted visually.
The timing compounds the damage. Crypto prices have been sliding all month, and many users who bought devices recently may be looking to move coins to safekeeping right now. Ledger’s pause on the reseller’s shipments narrows the supply of new units in three countries, and the company will need to reassure those markets quickly. Official resellers exist precisely so buyers can confirm provenance, and a breach of that trust affects the whole certification scheme.
Neither Ledger nor CryptoBilis has confirmed whether any devices were intercepted in shipping, altered at a distributor, or counterfeited entirely. The company’s statement stops short of a product recall. Buyers with older devices from other channels have not been told to take action.
What affected buyers should do
Ledger’s advice so far stays narrow. Anyone who bought from the reseller within the past 90 days and has not set the device up should not do so yet. Those who already generated a recovery phrase on such a device should move their assets to a wallet with a fresh seed, preferably created on a device from a verified source. The company says it will publish updates as the investigation progresses.
The episode lands during a week when researchers and officials are already focused on how crypto funds move after a theft, with a separate US effort under way to seize roughly $1 billion in Iran-linked coins. A confirmed supply chain attack would add a new layer to that picture, one that reaches into the retail accessories aisle rather than the blockchain layer itself.
