exploit
Ledger halts CryptoBilis sales after $86M in reported wallet drains
Ledger paused shipments through Southeast Asian reseller CryptoBilis after on-chain investigators traced over $86M in suspected thefts across BTC, ETH and Tron.
Hardware wallet maker Ledger said on October 9 it is investigating fund losses tied to CryptoBilis, an official Ledger reseller in Indonesia, Malaysia and the Philippines, and has asked the reseller to pause all sales and shipments. On-chain investigator Specter traced more than $86 million in suspected thefts across Bitcoin, Ethereum and Tron. Ledger has not confirmed the figure or named a cause.
What happened
Ledger published a statement asking CryptoBilis to halt sales and shipments while it investigates reports of fund losses from users in Southeast Asia. The company advised anyone who bought from CryptoBilis in the last 90 days not to set up the device if they haven't already, and told users who had set one up to consider moving assets to a new Ledger signer with a new seed phrase.
The dollar estimate comes from pseudonymous on-chain researcher Specter, who put total losses at over $86 million based on Arkham-labeled addresses. The reported mix is roughly $42 million in ETH, $17.6 million in BTC and $16.5 million in USDT. A second researcher, tanuki42, independently traced about $72 million to suspected theft addresses; it is not clear how much the two tallies overlap.
Ledger's position
Ledger's statement is cautious. It confirms the investigation and the pause on CryptoBilis, but does not endorse a cause. From the company's advisory relayed to users:
we have asked CryptoBilis to pause all sales and shipments of Ledger devices.
No official tampering mechanism has been published. Two prominent commentators offered unverified explanations: Mark Karpeles, the former Mt. Gox CEO, said the reports may be linked to an issue he was already looking at and asked affected users to send photos of their device circuit boards. Changpeng Zhao, the Binance co-founder, said the available information pointed to a supply-chain attack involving one vendor, with a small number of users possibly receiving fake or tampered devices. Neither account is confirmed by Ledger.
On-chain trail
Specter's initial post said funds came from hundreds of victim wallets, then clarified that the number of affected wallets is not yet known. The investigator did not publish the full address list in the summary Decrypt and The Block relayed, so Ledger's eventual breakdown will matter. If the drains are supply-chain in nature — devices leaving CryptoBilis with pre-generated seeds or compromised firmware — the exploit primitive is the delivery channel, not the wallet itself.
Impact and what to watch
- Users who bought a Ledger device from CryptoBilis within the last 90 days: do not set up the device until Ledger issues a full advisory.
- Users who already set up a CryptoBilis-sourced device: Ledger's own guidance is to move funds to a fresh signer under a new seed. Reusing the same seed on a new device does not resolve a seed compromise.
- Watch Ledger's follow-up for a confirmed root cause: a tampered device chain, a fake unit substituted into the reseller's inventory, or a social-engineering layer around setup. The three outcomes have very different fixes.
- Watch for law enforcement in Indonesia, Malaysia and the Philippines — the three markets CryptoBilis served — to coordinate on physical custody of inventory.
Context
Hardware-wallet supply-chain concerns are an old pattern: Ledger has repeatedly warned over the years against buying devices from third-party sellers, and users with counterfeit units have surfaced before. What is unusual here is the scale of the on-chain estimate — more than $86 million across three chains — and that the reseller named is listed on Ledger's own channels as official for the region. The split between a counterfeit-inventory theory and a reseller-side compromise theory is the question that determines whether this is a Ledger problem or a CryptoBilis one.