Ledger Users Drained of $86 Million Across Bitcoin (BTC), Ethereum and TRON
An on-chain trace shows over $86 million drained from Ledger users across Bitcoin (BTC), Ethereum and TRON, as SEAL urges victims to contact SEAL 911.
AI SummaryAI
- Specter traced over $86 million in Ledger wallet drains across Ethereum, TRON and Bitcoin on October 9
- The trace listed 10 addresses holding just over $25 million at last check
- tanuki42 reported total losses above $72 million and increasing at 12:00 UTC
- SEAL directed drained victims to the SEAL 911 Telegram bot at 12:29 UTC
Ledger Drains Cross $86 Million
More than $86 million has been pulled from users of Ledger hardware wallets in a theft spanning several major networks, an on-chain trace published on Friday, October 9, shows. The trace, posted by the analyst account Specter at 12:24 UTC, follows a cluster of theft wallet addresses across blockchains that include
Ethereum (ETH), TRON and Bitcoin (BTC), and it consolidates user reports from X and Reddit of Ledger wallets being emptied. Specter said the addresses took in funds from hundreds of victims' wallets on those chains. The post listed 10 addresses. At the last check those addresses held just over $25 million combined, which suggests the majority of the stolen funds have already been moved onward and no longer sit where they landed. Reports of emptied devices surfaced across social platforms on Friday morning, and the tally hardened into a single address set within hours. The losses sit with individual holders rather than with market plumbing: the Bitcoin price was not the driver, and no exchange or protocol breach accompanies the incident. What the trace establishes so far is scale and spread, not method. The reported drains cover three of the most liquid networks in the industry, and a victim count in the hundreds places this among the larger retail-facing wallet incidents of the year. A list of receiving addresses is also the incident's most useful public artifact. It gives exchanges, explorers and monitoring desks concrete identifiers to flag, while the entry point, whether a compromised device, a malicious signing flow or something else, remains unnamed. That gap matters for the many Ledger users whose devices remain in daily use, and it explains why two of Friday's three posts behind the tally were address lists rather than a technical post-mortem.
SEAL Opens a Line to Victims
An earlier tally shows how fast the figure grew. A post from the account tanuki42, published at 12:00 UTC, put the running total at more than $72 million and described it as increasing; it listed eight addresses, every one of which also sits in Specter's set of 10, and Specter's trace added two more
Bitcoin (BTC) addresses on top. The Security Alliance, the industry response group known as SEAL, quote-posted the list at 12:29 UTC and asked anyone whose funds were drained to those addresses to make contact through the SEAL 911 Telegram bot as soon as possible. None of the three posts explains how the wallets are being drained, and that remains the central unknown. Hardware wallets, whether a Ledger device or a Tangem Mobile Wallet, are built on the premise that private keys never touch an internet-connected machine, so a drain at this scale raises a pointed question about where the failure sits: with the devices, with a distribution or supply step, or with holders interacting with something that spoofed the signing experience. Candidate explanations circulating on Friday range from a compromised signing flow to a replay attack, but neither Specter nor SEAL has endorsed any of them, and no technical post-mortem exists yet. What is confirmed is narrower: the receiving addresses, the totals credited to them, and the overlap between two independent lists compiled 24 minutes apart. That overlap is itself evidence of a single campaign rather than several unrelated incidents. For victims the instruction is unchanged: contact SEAL 911, preserve whatever transaction records exist, and treat the listed addresses as the map of where the money went.
Funds Moved Onward Within Hours
Our reading of the trace is that the most probative figure is the residue. Of the more than $86 million taken, the 10 listed addresses held only about $25 million at the last check, so the bulk of the haul has already been pushed onward rather than parked. That pace, measured in hours from receipt to redistribution, suggests the operator treated the drain as an imminent-exposure event from the start. Public address lists do not recover funds by themselves, but they give exchanges and monitoring desks concrete identifiers to flag or freeze, in the same way recent on-chain scrutiny surfaced 6.26M Bitcoin with exposed public keys. Our Bitcoin coverage will follow the post-mortem when one lands. The open file stays the mechanism. The closed number stays the loss: more than $86 million across the three chains.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

