Just so you know, the hardware wallet did its job.. The box it came in did not..... On October 9, 2026, Ledger confirmed it is investigating fund losses among Southeast Asian customers who bought devices through CryptoBilis, an authorized reseller listed for Indonesia, Malaysia and the Philippines... On chain investigators have alredy traced more than $86 million to suspected theft addresses on Bitcoin, Ethereum and Tron.... Ledger says its own systems were not compromised. That is probably true, and it is also exactly the problem.
Cold storage has always been sold as the end of the trust chain. Your keys, your device, your coins. This incident is a reminder that the trust chain starts much erlier, somewhere between a factory and a shop counter in Petaling Jaya... And that a perfectly secure chip cannot protect a seed that someone else already knows.
What happened with the CryptoBilis Ledger devices?
The first alarms came from users on X and Reddit reporting wallets emptied with no phishing click, no signed approval and no obviosu mistake. Pseudonymous investigator Specter compiled those reports, traced the receiving addresses and put the total at $86.96 million across 98 addresses. Security researcher tanuki42 had earlier flagged more than $72 million and urged victims to contact SEAL 911. By Friday afternoon, an Arkham Intelligence entity labeled ledger drainer showed roughly $71.5 million still sitting in flagged addresses. Truth is, Ledgers rseponse was fast and blunt. It asked CryptoBilis to pause all sales and shipments, told anyone who bought from the reseller in the last 90 days not to start setup. And advised anyone who already had to consider moving assets to a new Ledger signer (with new seed). The company said it believes the losses are limited to devices sold through that one channel and that it has no indication its infrastrcutre was breached.. It has not accused CryptoBilis of tampering, and the reseller had made no public statement by Friday.| Source | Estimate | Scope | Status |
|---|---|---|---|
| Specter (on chain investigator) | $86.96 million | 98 addresses on Bitcoin, Ethereum, Tron | Unverified, victim count unknown |
| tanuki42 (securty researcher) | Over $72 million | Suspected theft addresses | Earlier figure, said to be rising |
| Arkham ledger drainer entity | About $71.5 million | Funds currently held in flagged addresses | Unverified entity label |
| Ledger | Not disclosed | CryptoBilis buyers in Southeast Asia | Investigation ongoing |
Specter has alredy walked back the hundreds of victim wallets phrasing, conceding the actual victim count is not established. Nobody has proven that every address in the tally belongs to a CryptoBilis buyer. , Treat the $86 million as a ceiling built from public reports, not an audited loss figure.
Where did the stolen crypto go?
The Arkham breakdown is more intersting than the headline number, because it shows what the attacker was actually collecting.

| Asset | Approximate value in flagged addresses | Share of tracked total |
|---|---|---|
| Ether (ETH) | $29.4 million | 41% |
| Bitcoin (BTC) | $17.5 million | 25% |
| USDD (Tron stablecoin) | $13.6 million | 19% |
| Tether (USDT) | $10.8 million | 15% |
Roughly a third of the haul is stablecoins, and USDD is a Tron native asset with Specters adress list also leaning on Tron... , That fits the region. Tron USDT is the default settlement rail across much of Southeast Asia, and the victims were storing exactly what local users store. The USDT slice matters for another reason: Tether can freeze it, and has done so repeatedly at the request of law enforcement. USDD has no comparable track record of issuer freezes. , If the attacker is smart, the stablecoins get swapped first and the freeze window closes... As of the Friday reports, the funds had not been visibly bridged, mixed or deposited to exchanges.
How can a genuien hardware wallet get drained?
Frankly, a hardware wallet protects one thing: the private key, after it has been generated securely on the device. Everything before that moment is outside its threat model... There are three realistic ways an attacker gets in through the supply chain, and they need very different defenses.
The pre seeded device. the oldest trick... A reseller initializes the device, writes the 24 words on the recovery card, reseals the box and sells it as new... The buyer sees a ready to use walltet, deposits funds, and the attacker sweeps them using the copy of the seed they kept. Ledgers own guidance is explicit that a real device never arrives with a recovery phrase already filled in. Any buyer who generates a fresh seed defeats this completely.
The counterfeit device. In 2023 Kaspersky dissected a fake Trezor Model T bought from a classifieds site with seals that looked intact. Its modified firmware replaced the randm seed with one of 20 phrases hardcoded by the attacker and quietly ignored all but the first character of any passphrase. The user did everything right and generated a new seed on the device.... it was simply never new. Here, generating your own seed does nothing.... What saves you is the manufacturers attestation check, which a cloned chip cannot pass. Which means, The implant.. This is the scary one, and it is the theory now attached to CryptoBilis. Former Mt. Gox CEO Mark Karpelès posted teardown photos of a Ledger he says he bought in Malaysia, still in intact shrink wrap.... He describes a second board hidden where the screen padding normalley sits, with a wire antenna, an LTE module and a data eSIM. According to his account, the implant reads the 128 by 64 pixel display, recognizes the setup screen, and transmits the seed words as text over the cellular network. The genuine secure element stays untouched. The firmware stays untouched... The attestation check passes, because the device is geniune. It just has a passenger.
Karpelès has not said his unit came from CryptoBilis, and his findings are one researchers device, not a confirmed root cause. But if the mechanism holds up, it explains why victims reported no suspicious approvals the seed left the device at the moment it was displayed. And the attacker simply waited for deposits.
Does Ledger Geniune Check catch tampered devices?
Partially, and that partially is the whole story. Our analysis of the documented attack routes shows that no single defense covers every case. The only control that touches all three supply chain attacks is where you bought the device.
| Attack route | Genuien Check catches it? | Generating your own seed helps? | Buying direct helps? |
|---|---|---|---|
| Pre seeded recovery card | No (device is genuine) | Yes, fully | Yes |
| Counterfeit device with hardcoded seeds | Yes, if run through official software | No | Yes |
| Hardware implant redaing the screen | No (secure element is genuine) | No | Yes, largely |
| Fake wallet app or phishing page | Not relevant | No | No |
The last row is there for perspective..... In April a musician lost about $424,000 in bitcoin after downloading a fake Ledger Live app from Apples Mac App Store. Most hardware walltet hacks are still people typing 24 words into software that asked nicely. what makes the CryptoBilis case different is that victims apparently did nothing wrong at all, other than trust an authorized storefront.
Is this a Ledger problem or a reseller problem?
Both, depending on who is answering... Changpeng Zhao said the evidence points to a supply chain attack localized to one vendor and added, with questionable timing, that self custody comes with extra responsibilities........ AnchorWatch CEO Rob Hamilton warned that the blast radius could extend beyodn Ledger, since CryptoBilis also sells Trezor, Tangem, SafePal, OneKey, Ellipal and CoolWallet. Bitcoin Malaya is already asking that question publicly.
Ledgers position is technically correct. Its chips were not broken and its servers were not breached. But the company lists CryptoBilis on its official reseller page, which is precisely the signal a buyer in Kuala Lumpur or Manila uses to desice a shop is safe. an authorized reseller program is a trust delegation. When it fails, our systems were not compromised is a true statement that does not return anybodys ETH.. This also lands in a rough year for the brand. In January a breach at payment processor Global e exposed names and contact details of Ledger.com buyers, and the 2023 Conect Kit library compromise is still fresh in memory.
What should hardware wallet owners do right now?
Honestly, if you bought from CryptoBilis in the last 90 days, follow Ledgers advice without debate. Do not set it up... If it is already set up, move everything to a new device bought directly from the manufacturer, with a seed generated on that new device. Do not reuse the old seed on the new hardware. That seed is the thing that may be compromised.
For evryone else, the takeaways are simple and boring, which is why people skip them: Sure, Buy from the manufacturers own store. Not a marketplace listing, not a discount reseller, not a sealed unit from a forum. The table above shows it is the only defense that covers all three supply chain routes.
Reject any device that arrives with words alredy written down. No legitimate wallet ships pre seeded. Ever.
Run the attestation check through official software, every time. It will not catch an implant, but it kills counterfeits. Even so, Use a passphrase. It neutralizes a leaked recovery card on its own.... , An implant watching the screen could still capture it druing entry, so treat it as an extra layer that raises the cost of an attack, not a fix.
Split large holdings. If one device turns out to be compromised, it should not be holding everything.
This matters for anyone who moves funds between platforms and cold storage regularly, crypto casino players included. Fast payout platforms such as CryptoCasino.Vegas prcess withdrawals automatically to whatever address you give them, which means the security of those winnings rests entirely on the device that generated that address. A clean, directly sourced hardware wallet is the last link in that chain. As the CryptoBilis buyers just learned, it is also the link most people never think to inspect.
Ledger has promised updates as the investigation continues.... Until it names a root cause, the safest assumption is the uncomfortable one: a geniune device from an authorized seller can still be compromised..... And the only fully trusted supply chain is the shortest one.