Ledger has confirmed the discovery of an unauthorized hardware implant in a device linked to the CryptoBilis incident, as blockchain investigators estimate cryptocurrency losses exceeding $86 million.
The unauthorized modifications were found in hardware wallets sold through CryptoBilis, a reseller operating in Indonesia, Malaysia, and the Philippines. The thefts were first reported on October 9, when users discovered missing funds from wallets associated with devices purchased through the reseller. Ledger identified CryptoBilis as the source of all confirmed cases in an October 11 update.
Ledger stated that its internal systems and direct sales channels remain unaffected. The company noted that the volume of impacted devices is limited, though the exact number has not been disclosed.
Financial Losses Remain Unconfirmed
Blockchain intelligence firm Bitquery estimated that approximately $93.2 million was taken from 315 wallets across Bitcoin, Ethereum, TRON, BNB Chain, and Polygon. Some stolen funds moved through additional addresses after the initial thefts, according to the analysis.
This estimate exceeds separate reports placing suspected losses above $86 million. However, Ledger has not confirmed the total amount stolen or provided an official loss assessment.
Hardware Security Concerns
Hardware wallets typically isolate private keys from internet-connected devices to reduce exposure to online attacks. Physical modifications can compromise these protections if malicious components access sensitive information.
Investigators have not publicly established how the affected devices were compromised or whether the hardware implant caused every reported loss. The connection between the discovered component and the broader thefts remains under investigation.
Ledger's Response and Guidance
CryptoBilis has halted hardware wallet sales as the investigation proceeds with relevant authorities.
Ledger has issued security guidance for customers who purchased devices through CryptoBilis. Users who have not initialized their devices are advised not to set them up. Customers who have already initialized wallets should transfer assets to a new Ledger device using a newly generated recovery phrase.
The company has prompted a review of authorized reseller controls, hardware protections, and distribution procedures. Ledger warned distributors against restocking returned devices, which could introduce modified products into the supply chain.
The manufacturer cautioned customers to avoid unauthorized sellers, as hardware wallets could be counterfeit, modified, or outside security guidelines. Ledger also warned about follow-up scams targeting affected users and stated it will never call customers, send direct messages, or request recovery phrases.
The investigation remains ongoing, with the number of affected customers, confirmed financial impact, and precise compromise method still unresolved.


