Need help? Support
BITCOIN
Tether Dominance USDT.D

Ledger probes suspected $86M hardware wallet thefts

Published 555 words 3 min read

TLDR

Ledger is investigating reports that up to $86 million in crypto may have been stolen from hardware wallets sold by a Southeast Asian reseller, with the cause still unconfirmed.

  1. Ledger is probing fund losses tied to devices sold by authorized reseller CryptoBilis, while onchain analysts estimate suspected drains above $72 million to $86 million across Bitcoin, Ethereum, Tron and stablecoins.
  2. Current evidence points to a reseller or supply?chain issue rather than a confirmed Ledger?wide hardware vulnerability, and Ledger says its own infrastructure and services were not compromised.
  3. Hardware wallet users should closely follow Ledgers updates, treat reseller devices with caution, and tighten basic self?custody hygiene around recovery phrases and device provenance.

Deep Dive

1. Scale And Estimates

Multiple reports say Ledger is investigating losses from customers in Indonesia, Malaysia and the Philippines who bought devices from reseller CryptoBilis, with Ledger asking the firm to suspend sales and shipments while the probe continues. Onchain researchers tanuki42 and Specter have traced suspected theft addresses and inflows from hundreds of wallets, with estimates ranging from more than $72 million to over $86 million across Bitcoin, Ethereum and Tron. Some analyses, including Arkham data cited in coverage, suggest totals nearer $87 million, but Ledger has not yet confirmed any aggregate figure or victim count.

What this means

The dollar amount is large enough to be systemically important for hardware?wallet trust, but still based on third?party tracing, so users should treat numbers as provisional until Ledger publishes a full incident report.

2. Reseller And Attack Vector

Ledgers public statements and media reports indicate the incidents are linked to devices sold by CryptoBilis, an authorized distributor in Southeast Asia, and the company has told customers who bought from that reseller in the past 90 days not to set up unused devices and to consider moving funds to a new signer with a new recovery phrase. In comments to Cointelegraph summarized by CoinMarketCaps community coverage, Ledger said the incident appears isolated to that reseller and market and that infrastructure, systems and services were not compromised. Industry figures such as Binances former CEO have floated a possible supply?chain attack involving counterfeit or tampered devices, but there is still no confirmed explanation, and it is unclear whether every reported theft is tied to CryptoBilis devices.

3. Hardware Wallet User Actions

For affected customers, Ledgers guidance is conservative: quarantine recent devices from the reseller and migrate assets to a new wallet with a freshly generated recovery phrase on a trusted device. For the wider community, this incident underlines that hardware wallets reduce many risks but do not eliminate supply?chain or social?engineering threats, so buying directly from manufacturers or highly vetted channels, inspecting packaging, and never sharing or typing recovery phrases into websites or chat windows remain critical habits. Security organizations such as SEAL have urged victims whose funds reached identified theft addresses to contact incident?response teams, which may help coordinate tracing and potential recovery efforts.

Conclusion

Ledgers probe of suspected $86 million hardware wallet thefts is a serious stress test for both the company and the wider self?custody ecosystem. The emerging picture suggests a localized reseller or logistics issue rather than a confirmed flaw in Ledgers core technology, but until the attack path is clearly documented, hardware?wallet users should assume that supply?chain integrity and recovery?phrase hygiene are key risk levers to watch in the coming days and weeks.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top