- Ledger said on Oct. 9, 2026, that it was investigating reports of lost funds among Southeast Asian customers who bought devices from reseller CryptoBilis.
- Blockchain analyst Specter estimated losses from hundreds of wallets across Bitcoin, Ethereum and TRON at more than $86 million.
- Ledger asked CryptoBilis to pause sales and shipments while the investigation continues and advised recent customers not to set up unused devices.
French hardware-wallet maker Ledger said on Oct. 9, 2026, that it was investigating reports of lost funds among Southeast Asian users who bought its products from reseller CryptoBilis. The inquiry follows reports involving hundreds of wallets and losses estimated by blockchain analyst Specter at more than $86 million.
Ledger said in an X post that it had asked CryptoBilis to pause all sales and shipments of Ledger devices as a precaution pending the investigation’s findings. The company has not confirmed the cause of the reported thefts.
Ledger advises customers to move cautiously
Ledger advised customers who bought devices from CryptoBilis in the previous 90 days not to begin setup if they had not already done so. Customers who had completed setup should consider moving their assets to a new Ledger signer using a new seed, the company said.
Ledger said it would provide updates as the investigation progressed and directed customers with questions to contact its support team through official channels.
Binance co-founder Changpeng Zhao said the available information suggested the incident may be localized to a supply-chain attack involving one vendor. He said a small number of users probably bought counterfeit or modified Ledger devices, but Ledger has not established that as the cause.
“Hardware can be tempered with, software official website can be hacked. Self custody comes with extra responsibilities,” Zhao said.
Report describes hidden implant
Former Mt. Gox CEO Mark Karpelès said he received a Ledger hardware wallet from Malaysia containing a hidden spyware module even though its factory shrink wrap appeared intact. In an X post, he said the implant was concealed where the screen’s padding would normally be located.
Karpelès said a Ledger Nano X contained a 2-by-2 millimeter microchip connected to the screen’s data lines. According to his account and a related research report, the module intercepts the 24 words of a seed phrase during setup, stores the data and transmits it through a cellular modem using a SIM card and antenna.
Because the module does not disrupt the main secure chip, Ledger’s authenticity check can still succeed, Karpelès said. He added that newer modifications are harder to identify even after a device is disassembled and could probably be installed at scale.
Analysts track more than $86 million in reported losses
Blockchain analyst Specter said complaints on X and Reddit described Ledger users’ wallets being drained. Specter said addresses linked to the reported thefts had received funds from hundreds of victim wallets across Bitcoin, Ethereum and TRON, with total losses exceeding $86 million, according to an X post.
Analytics platform Arkham began tracking the addresses under the label “cryptobilis-ledger-drainer.” Its published data showed that 158 addresses held about $71 million in assets at the time of publication.
The reports follow other incidents involving hardware-wallet companies in 2026. Coldcard users lost nearly $89 million in a large-scale attack in early August. Trezor said later that month that a breach of logistics partner ShipMonk exposed data belonging to 13,689 customers, and in September it reported that attackers had compromised a third-party email provider and used its infrastructure for phishing campaigns.
Source: Incrypted
