Ledger Probes $86M Bitcoin (BTC) Theft Linked to Reseller CryptoBilis
Ledger is investigating about $86 million in Bitcoin, Ethereum and Tron stolen from wallets sold by reseller CryptoBilis and has paused all its shipments.
AI SummaryAI
- Ledger opened an investigation into roughly $86 million stolen from wallets sold by reseller CryptoBilis on Friday.
- Researcher Specter traced inflows from hundreds of victim wallets across Bitcoin, Ethereum and Tron.
- Researcher tanuki42 identified eight wallet addresses linked to more than $72 million in losses.
- Ledger told customers who bought from CryptoBilis in the past 90 days not to set up their devices.
Ledger halts a vetted reseller
Hardware wallet maker Ledger has opened an investigation into the theft of roughly $86 million in crypto from devices sold through CryptoBilis, one of its authorized resellers in Southeast Asia. The company said on Friday via its support account that it had asked CryptoBilis to pause all sales and shipments of Ledger products while the probe continues. Customers who bought from the reseller within the past 90 days were told not to set up their devices, and buyers who had already activated one were advised to move their assets to a new Ledger signer with a freshly generated recovery phrase. In its statement, Ledger said the incident appears isolated to the reseller and its market, that it has received no reports involving devices purchased directly from the company, and that its infrastructure, systems and services were not compromised. The drained wallets held
Bitcoin (BTC), Ethereum and Tron, and Bitcoin price-weighted estimates from on-chain researchers put the combined losses above $86 million.
@Ledger_Support · X post
Support account.
View on X
Investigators trace inflows from hundreds of wallets
On-chain researchers moved before the company did. Pseudonymous investigator Specter wrote on X that complaints of drained wallets had surfaced across X and Reddit among Ledger owners, and that tracing the suspected theft addresses showed deposits arriving from hundreds of victim wallets on Bitcoin, Ethereum and Tron, adding up to more than $86 million. Fellow researcher tanuki42 identified eight addresses allegedly tied to more than $72 million in losses. The crypto security organization SEAL amplified the findings and urged anyone whose funds were transferred to the flagged addresses to contact its incident-response team. Ledger has confirmed neither estimate, has not identified a cause and has not said whether the devices themselves were tampered with. Whether the individual cases share a single mechanism also remains unconfirmed, though every report so far runs through one shared channel, a single reseller.
@SpecterAnalyst · X post
Wrote on X.
View on X
Inside CryptoBilis and the supply-chain theory
CryptoBilis is a Kuala Lumpur-based online store launched in December 2020 by Arravind Prabu, Vimal Selvamany and Dhivager Rathakrishnan under their company, Fetch International. The store said in 2021 that it became an authorized reseller for the Paris-based wallet maker, and it is listed as an authorized seller for Indonesia, Malaysia and the Philippines. Its own site markets it as a trusted Web3 brand in Southeast Asia carrying Tangem wallets, SafePal, OneKey and Trezor alongside Ledger devices. The leading theory for the thefts is a supply-chain attack, in which a device is tampered with so that the recovery phrase programmed into it is already known to an attacker before the buyer opens the box; once funds land on the wallet, they can be drained. Researchers documented the method in 2023 with a tampered Trezor Model T whose main chip had been replaced and whose software was rigged to hand users one of 20 phrases known to the attackers, who waited about a month before emptying it. Former Mt. Gox chief Mark Karpelès has also pointed to claims that reseller-sold Ledger units were implanted with spyware designed to steal passkeys. None of these mechanisms has been confirmed for the current case.
A rough stretch for hardware wallet security
The case lands during the sector's most damaging run in recent memory. In July, hackers stole close to $120 million in
Bitcoin (BTC) from Coldcard users after a firmware bug in devices made by Coinkite produced faulty seed generation that attackers could effectively guess; Galaxy Research later said several attackers exploited the flaw independently. Last month, Trezor disclosed that details of about 81,000 customers leaked through a third-party fulfillment partner. Ledger itself recorded a January incident in which its payment processor, Global-e, leaked customer data that scammers reused for phishing emails. Not everyone accepts the framing of the current case as a zero-day device flaw: security researcher Taylor Monahan has warned that accounts amplifying the drain reports are pushing people toward panic moves, and that migration searches create openings for phishing pages, fake ads and counterfeit apps. The scrutiny adds pressure to Ledger, which abandoned a planned $4 billion US IPO in May, citing poor market conditions.
The channel, not the chip
Our reading of the evidence so far is that the weak link sits in the retail channel rather than in the device itself: every confirmed report involves units bought through CryptoBilis, while buyers who purchased directly from Ledger have filed none. That still cuts against the core promise of a cold wallet, because a tampered unit looks identical to a sealed one on a shop shelf. Until the probe names a mechanism, the practical steps stand: hold off on setting up recently bought devices, migrate activated wallets to a new signer with a fresh seed, and buy only through official channels, applying the same vetting discipline used when comparing the Best Crypto Exchanges. The loss total, now above $86 million, may still climb as more victims come forward.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

