Ledger pauses reseller sales as loss reports top $86 million
Ledger told the reseller CryptoBilis to stop selling after users in Southeast Asia reported drained wallets. One on-chain investigator estimated losses above $86 million, a figure Ledger has not confirmed.
Published · 4 min read
Ledger asked one of its resellers to stop selling after customers in Southeast Asia reported drained hardware wallets. The company named the reseller as CryptoBilis on Friday. One on-chain investigator put the losses above $86 million, a figure Ledger has not confirmed.
The warning went out early on Friday, October 9, 2026, from Ledger's support account on X. The firm said it was looking into reports of lost funds from users in Southeast Asia who bought devices through CryptoBilis. It asked the reseller to pause all sales and shipments while the investigation ran.
What Ledger told buyers to do
Ledger gave plain advice to anyone who bought from CryptoBilis in the last 90 days. The steps are simple.
Buyers who had not yet set up a device were told not to start. Those who had already set one up were told to move their coins to a new Ledger signer with a fresh seed phrase. A seed phrase is the string of words that controls a wallet, so a new one cuts any tie to a device that might be compromised.
Where the $86 million figure comes from
That $86 million total did not come from Ledger. It came from Specter, an on-chain investigator who traced funds sent to a group of suspected theft addresses. Specter counted more than $42 million in Ether, about $17.5 million in Bitcoin and $16.5 million in Tether, moved across several blockchains as of Friday morning.
A second researcher, known as tanuki42, put the figure lower, above $72 million. The two estimates may not cover the same wallets. The counts differ. Neither has been checked by an outside party. No audit exists yet.
Specter first said the money came from hundreds of victim wallets, then said the true number was not yet known. A single on-chain tally, however careful, is not an audit.
What is still unknown
What caused the losses is the open question. The cause is not clear. No confirmed total, either. Ledger has not said whether any devices were tampered with before they reached buyers, and it has not confirmed any loss figure.
Some in the industry pointed to the supply chain. Changpeng Zhao, the Binance co-founder, wrote on X that the problem "seems to be localized to a supply chain attack with one vendor" and that "a small number of people probably bought fake (or tampered) Ledgers." Zhao called Ledger "one of the most secure and oldest hardware wallets in the industry" and said self-custody "comes with extra responsibilities."
Mark Karpeles, the former chief executive of the failed exchange Mt. Gox, said the reports might tie into something he was already examining. He asked affected users to send photos of their device circuit boards, which he said could show signs of tampering.
One account points away from a simple phishing scam. On Reddit, a user said nearly 100,000 USDT was drained from a Ledger Stax. The seed phrase had been kept offline, the user wrote, and the device had never signed a transaction. That is the kind of report that makes researchers look at the hardware rather than the owner. It is one claim, not proof.
Ledger has sold hardware wallets for years and is a well-known name in self-custody, the practice of holding your own keys rather than leaving coins on an exchange. A hardware wallet is meant to keep those keys offline, away from any internet-connected machine. That promise is what the reports call into question.
What to watch
The next move is Ledger's own account of what happened. Watch for whether it confirms a cause, a total, and how many people lost money. Watch, too, for word on whether the devices were genuine units or fakes sold as the real thing.
CryptoBilis has not commented. It has not said whether it will follow the pause request or what it believes went wrong. For anyone who bought a wallet through a third party this year, the safest step is the one Ledger already gave. Treat the device as suspect and move funds to a wallet you set up yourself.
Frequently asked
Should I stop using my Ledger wallet?
Not on its own. Ledger's warning is aimed at people who bought from the reseller CryptoBilis in the last 90 days. If that is you, Ledger says do not set up a new device, and move funds from an already-set-up device to a new wallet with a fresh seed phrase. Buyers outside that group are not covered by the alert.
Who says the losses are $86 million?
The $86 million estimate comes from Specter, an independent on-chain investigator, not from Ledger. Specter traced funds across Ether, Bitcoin and Tether. A second researcher put the total near $72 million. Ledger has not confirmed any figure, and no outside party has audited the numbers, so treat the total as preliminary.
What is a supply chain attack on a hardware wallet?
It means a device is interfered with somewhere between the factory and the buyer, so it no longer works as a sealed product should. Binance co-founder Changpeng Zhao suggested that may have happened here with one vendor. Ledger has not confirmed a cause, and the claim is unproven for now.
Sources, and what is behind them
- Ledger Support statement on the CryptoBilis investigation, Ledger (October 9, 2026)Other
- Ledger investigates wallet drains involving CryptoBilis buyers; estimate tops $86 million in losses, The Block (October 9, 2026)Press report
- Ledger Investigating Reports of Drained Crypto Wallets as Estimated Losses Hit $86M, Bitcoin.com News (October 9, 2026)Press report
- Ledger investigates significant fund losses tied to CryptoBilis reseller, Crypto Briefing (October 9, 2026)Press report