Ledger is investigating reports of stolen funds tied to devices sold by CryptoBilis, a reseller in Southeast Asia. Anonymous onchain researcher Specter put the losses at more than $86 million. Nobody has confirmed that figure, so treat it with caution.
What is known as of October 9
According to CoinDesk, Specter said on X that they traced suspicious withdrawal addresses across the Bitcoin, Ethereum and Tron networks. The trigger was a wave of complaints from Ledger users on X and Reddit. We are talking about hundreds of wallets.
The company acknowledged complaints about missing funds from customers who bought devices through CryptoBilis. It did not name a loss amount or a cause. How many people were hit, and whether the thefts are connected, is also unknown.
How can a hardware wallet be bypassed?
To see why this is alarming, recall how it works. A hardware wallet keeps private keys offline, and they are restored from a seed phrase (12 or 24 words). Whoever knows the phrase controls the money. The device is just a convenient shell.
CoinDesk points to one possible explanation: a supply-chain attack. Here is how it would play out step by step:
- Swap before sale: an attacker prepares a device with a seed phrase they already know.
- The buyer switches the wallet on, sees a normal interface and sends funds to it.
- Two people now hold the keys, and only the owner has no idea.
- The theft can happen weeks later, once the address holds a decent sum.
That is only a hypothesis. Nobody has confirmed tampered devices or pre-generated phrases.
Was Ledger itself hacked?
Nothing points that way. The probe concerns hardware sold through a third-party seller, and there is no evidence that Ledger's systems or wallet technology were compromised. These are different scenarios, and mixing them up would be a mistake.
Still, the brand's size makes the story matter for the whole market. The Paris-based company has operated since 2014 and says it has sold more than 7 million devices. Many owners picked it precisely to avoid relying on exchanges.
What Ledger advises
Ledger asked CryptoBilis to pause sales and shipments. Anyone who bought a device from this reseller in the past 90 days is told not to set it up. If a wallet is already active, move the assets to a new Ledger and generate a fresh seed phrase. The old one must not be used.
The year has been rough for security anyway. DefiLlama data shows Bitget lost over $350 million last month, with earlier hits at Liquid Network (about $320 million), Drift ($295 million) and Kelp ($293 million). If the $86 million is confirmed, it adds another big blow.
What a wallet owner should do
At Kurslog we stick to a simple rule: buy a hardware wallet from the manufacturer or its official store. A discount on a marketplace or from a random reseller is not worth the risk. Check the packaging, and above all the seed phrase. If it is already printed on a card in the box, throw the device away. A genuine wallet always generates the phrase itself, on your screen.
Until Ledger publishes its findings, the best defense is checking where you bought the device. The company promises updates as the investigation moves on.




Comments
Your email address will not be published. Required fields are marked *