A supply chain attack on Ledger hardware wallets has resulted in theft totaling $91 million across nearly 500 addresses, according to analysis by Galaxy Research. The breach affected Ledger Nano X and Ledger Nano S Plus devices distributed through CryptoBilis, a Southeast Asian reseller.
The Tron network sustained the largest losses, with 276 victim addresses drained of approximately $64.5 million. Bitcoin addresses ranked second, with 276 affected addresses losing $17.7 million, while the Ethereum ecosystem experienced $8.8 million in losses across 55 addresses. Galaxy Research noted that the $91 million figure represents a minimum, as the full impact on BNB Chain, Base, Avalanche, and other networks remains under investigation.
According to preliminary reports, the attack involved hardware tampering that allegedly installed spyware capable of reading and transmitting seed phrases—the cryptographic keys that grant access to wallet funds—to an attacker-controlled server. Users whose devices were not configured with multi-signature security were vulnerable to fund drainage.
Fund Laundering and Recovery Efforts
As of October 9th, approximately $73 million of stolen funds remained in attacker-controlled wallets. An additional $3 million had been moved to Tornado Cash and similar privacy-focused services. Some stolen USDT was converted to USDD, totaling $13.65 million, while a portion of funds was transferred to Binance.
Binance CEO Richard Teng stated that the exchange would assist in tracing and recovering funds, positioning the incident as a shared industry responsibility. Both Teng and Binance founder Changpeng Zhao committed to supporting affected users and recovery efforts.
Questions Around CryptoBilis and Disclosure
CryptoBilis CEO Aravind Prabu defended himself against allegations of negligence by stating he no longer holds leadership at the firm, having sold the company to a Chinese buyer. Prabu cited a non-disclosure agreement preventing public disclosure of the sale, noting the agreement was set to expire on October 19th—shortly after the attack became public.
The incident adds to a growing pattern of hardware wallet vulnerabilities. The industry was previously affected by a $114 million exploit involving Coldcard hardware wallets in the third quarter.

