Suspected thefts linked to Ledger hardware wallets purchased through CryptoBilis, an authorized reseller in Southeast Asia, are approaching $90 million, according to blockchain investigators. On October 9, Ledger announced it was investigating reports of customer fund losses tied to devices sold by the distributor and asked CryptoBilis to pause sales and shipments while the investigation continues.
Ledger advised customers who purchased devices from CryptoBilis within the past 90 days not to initialize them if setup had not yet begun. Those with already-configured wallets were urged to transfer cryptocurrency to new Ledger devices initialized with fresh recovery phrases.
Investigation Into Compromise Method
CryptoBilis appears in Ledger's official reseller directory for Malaysia, Indonesia, and the Philippines. The nature of the compromise remains unclear. Former Mt. Gox CEO Mark Karpelès is investigating whether malicious hardware components were inserted into distributed devices, requesting that CryptoBilis open unsold wallets for circuit board inspection.
Ledger's security documentation acknowledges a limitation in its Genuine Check system: it verifies a device's Secure Element but cannot necessarily detect physical modifications elsewhere in the hardware if the original security chip remains intact. This means a physically altered device could pass authentication checks even with unauthorized components.
No confirmed evidence has established whether malicious hardware implants caused the thefts, and Ledger has not disclosed how many devices may have been compromised or whether the incident resulted from counterfeit hardware, physical tampering, or another attack method.
Tracking and Freezing Stolen Funds
Blockchain investigators have identified inflows from hundreds of suspected victim wallets into addresses across Bitcoin, Ethereum, and Tron. On-chain investigator Specter initially estimated losses exceeding $86 million, while blockchain security firm MistTrack later placed reported losses closer to $90 million. These estimates remain unverified, and investigators have not confirmed whether every wallet included resulted from the same operation.
Tether has begun freezing USDT stablecoin linked to the incident. USDT's administrative controls allow Tether to restrict transfers from designated addresses, preventing stolen tokens from moving to additional wallets or converting to other cryptocurrencies while investigations proceed.
However, this intervention has significant limitations. The suspected thefts span multiple blockchain networks and involve assets beyond USDT. Tether cannot directly freeze native Bitcoin or Ethereum, leaving investigators dependent on cooperation from exchanges, custodians, and law enforcement. Additionally, freezing USDT does not automatically return tokens to original owners; restitution would require further verification and coordination with authorities. MistTrack has not disclosed the dollar value of restricted tokens, making it unclear what portion of the $90 million in reported losses could be recovered.


