Hardware wallets are supposed to be the gold standard of crypto security precisely because the private keys never leave the device. But what happens when the device itself gets tampered with before it ever reaches the buyer?
That's the question Ledger is now racing to answer. The company is investigating a wave of thefts hitting users who bought devices through CryptoBilis, a Malaysia-based reseller that calls itself Ledger's authorized partner in the country while also selling Trezor, OneKey, Tangem and SafePal hardware. Pseudonymous on-chain investigator Specter traced more than $86 million drained from hundreds of wallets across Bitcoin, Ethereum and Tron. Other estimates put the figure closer to $72 million — the exact total hasn't been confirmed.
Ledger has told CryptoBilis to halt all sales and shipments and issued a blunt warning: if you bought a device from this reseller in the past 90 days and haven't set it up yet, don't. If you already have, move your funds to a brand-new device with a freshly generated recovery phrase of your own.
Nobody has nailed down the root cause yet. Former Mt. Gox CEO Mark Karpelès said devices from unauthorized resellers have previously turned up opened and implanted with spyware designed to capture seed phrases before the box ever reaches a customer. Security researcher Taylor Monahan is urging calm, though — she says there's no sign of an actual flaw in Ledger's firmware itself, and the bigger near-term risk is that mass migrations create a perfect cover for phishing scams dressed up as official Ledger instructions.
The incident is a reminder that the weakest link in crypto custody usually isn't the cryptography — it's the supply chain. A device can be flawless on the inside and still be compromised if someone opened the box before the buyer did.



