Ledger Wallets Drained of $86 Million — All Trace Back to One Reseller

iEXExchanger
Ledger Wallets Drained of $86 Million — All Trace Back to One Reseller

Ledger is investigating mass fund losses among users who bought devices through Malaysian reseller CryptoBilis. Analysts estimate $72–86 million drained from hundreds of wallets across Bitcoin, Ethereum and Tron.

Hardware wallets are supposed to be the gold standard of crypto security precisely because the private keys never leave the device. But what happens when the device itself gets tampered with before it ever reaches the buyer?

That's the question Ledger is now racing to answer. The company is investigating a wave of thefts hitting users who bought devices through CryptoBilis, a Malaysia-based reseller that calls itself Ledger's authorized partner in the country while also selling Trezor, OneKey, Tangem and SafePal hardware. Pseudonymous on-chain investigator Specter traced more than $86 million drained from hundreds of wallets across Bitcoin, Ethereum and Tron. Other estimates put the figure closer to $72 million — the exact total hasn't been confirmed.

Ledger has told CryptoBilis to halt all sales and shipments and issued a blunt warning: if you bought a device from this reseller in the past 90 days and haven't set it up yet, don't. If you already have, move your funds to a brand-new device with a freshly generated recovery phrase of your own.

Nobody has nailed down the root cause yet. Former Mt. Gox CEO Mark Karpelès said devices from unauthorized resellers have previously turned up opened and implanted with spyware designed to capture seed phrases before the box ever reaches a customer. Security researcher Taylor Monahan is urging calm, though — she says there's no sign of an actual flaw in Ledger's firmware itself, and the bigger near-term risk is that mass migrations create a perfect cover for phishing scams dressed up as official Ledger instructions.

The incident is a reminder that the weakest link in crypto custody usually isn't the cryptography — it's the supply chain. A device can be flawless on the inside and still be compromised if someone opened the box before the buyer did.

Questions and answers

Frequently asked questions about this article

What happened to Ledger wallets?

Users who bought Ledger devices through Malaysian reseller CryptoBilis reported stolen funds. Analysts estimate total losses at $72–86 million across hundreds of wallets.

Is this a vulnerability in Ledger devices themselves?

There's no confirmed firmware vulnerability so far. Suspicion centers on the device itself — it may have been opened and implanted with spyware before being sold through the unauthorized reseller.

What should affected users do?

Ledger advises anyone who bought a device from CryptoBilis in the past 90 days and hasn't set it up to avoid doing so. Those already using the wallet should immediately move funds to a new device with a fresh recovery phrase.

What risks exist beyond the theft itself right now?

Researchers warn of a phishing wave: scammers may disguise messages as official Ledger migration instructions, exploiting the panic among affected users.