Ledger has launched an investigation into potentially tens of millions of dollars in cryptocurrency theft linked to hardware wallets purchased through CryptoBilis, an authorized reseller in Southeast Asia.
On-chain researchers estimate that between $72 million and $86 million in cryptocurrency may have been stolen. Investigator tanuki42 traced more than $72 million to suspected theft addresses, while fellow researcher Specter estimated losses exceed $86 million across Bitcoin, Ethereum, and Tron. MistTrack suggested losses could approach $90 million. Tether reportedly froze USDT held in addresses connected with the incident.
Ledger's official support channel confirmed it was investigating user reports from customers of CryptoBilis, which operates in Indonesia, Malaysia, and the Philippines. The company asked CryptoBilis to pause all sales and shipments. Ledger stated there is no indication that its own infrastructure, systems, or services were compromised.
Recommended Actions
Ledger urged customers who purchased devices from the reseller in the past 90 days and have not completed installation to avoid beginning setup. Customers already using such devices were advised to consider transferring their assets to a new Ledger signer using a newly generated seed phrase.
Supply Chain Concerns
Binance co-founder Changpeng Zhao characterized the situation as a localized supply-chain attack involving one vendor, with some customers potentially receiving counterfeit or physically tampered Ledger devices.
Former Mt. Gox CEO Mark Karpeles reported examining modified Ledger devices containing hidden hardware implants. He stated that such implants could monitor internal communications used to display recovery words, potentially allowing attackers to capture seed phrases while the genuine Ledger Secure Element remained intact. Karpeles asked CryptoBilis to open units from its inventory to check for similar components.
Users have publicly reported losses from the incident, including one victim with $1 million reportedly stolen. The incident follows a separate breach affecting Ledger's competitor Trezor one month earlier, in which personal information of over 80,000 US users was compromised.


