Ledger Froze a Reseller as Trackers Counted $86 Million Drained
Ledger halted sales through Southeast Asian reseller CryptoBilis after users reported emptied wallets. The cause is unconfirmed, and the loss figures come from onchain trackers, not Ledger.
Hardware wallets exist to remove one risk: that your keys live on a computer someone else can reach. This week's Ledger incident is about a different risk, the one that starts before the box is opened.
Ledger said on Friday that it is investigating reports of stolen funds linked to devices sold through a reseller in Southeast Asia. That reseller is CryptoBilis, listed as an official Ledger reseller in Indonesia, Malaysia and the Philippines. Ledger has asked it to stop all sales and shipments while the investigation runs.
What Ledger told customers
The guidance is unusually direct. Customers who bought from the reseller in the past 90 days were told not to set up their devices. Those who had already set up a wallet were advised to move their assets to a new Ledger device with a newly generated recovery phrase.
Ledger acknowledged missing funds among customers who bought through that channel, but did not confirm the size of the losses or their cause. It says its own infrastructure was not compromised.
The numbers, and who produced them
Every loss figure in circulation comes from onchain analysis, not from Ledger. Pseudonymous blockchain investigator Specter estimated that more than $86 million may have been stolen from hundreds of wallets across Bitcoin, Ethereum and Tron, based on reports from users on X and Reddit. Another onchain estimate put suspected losses above $72 million. Bitquery estimated $92.9 million taken from 311 wallets across five networks.
The spread between those numbers is a reminder of how attribution works here. Trackers start from victims who post publicly, trace where funds went, then look for other wallets with the same pattern. Some wallets may not belong to this incident at all; others may not have been found yet. Until investigators link specific devices to specific drained addresses, the total is an estimate.
Tether has reportedly frozen USDT at addresses linked to the case, and Binance co-founder Changpeng Zhao urged the industry to help Ledger recover the stolen funds.
How a sealed device could be compromised
The cause is unknown. The leading theory, and only a theory, is a supply-chain attack: devices tampered with before reaching customers. One version is simple and old. An attacker preloads a device with a recovery phrase they already know, or slips a pre-printed "recovery card" into the box, and waits for the buyer to deposit funds. A buyer who uses the supplied phrase instead of generating a fresh one on the device has handed over the keys before sending the first coin.
A more alarming claim came from Mark Karpelès, who said a device he examined carried an implant hidden under its screen that still passed Ledger's authenticity check. That is a single claim from one person and has not been independently verified. If it held up, it would be a much more serious finding than a tampered package, because Ledger's device attestation is designed to catch modified hardware.
Neither theory is confirmed, and the incident should not yet be described as a proven hardware exploit or a proven supply-chain attack.
Why resellers are the weak link
Ledger says it has sold more than 7 million devices worldwide. Not all of them ship from Ledger's own store. In many markets, official resellers handle local distribution, pricing and delivery, and buyers reasonably treat a listed reseller as equivalent to the manufacturer.
That trust is the attack surface. A wallet's security model assumes the device that arrives is the device that left the factory and that the recovery phrase is generated on it, in front of the user. Every intermediary between factory and buyer is a place where one of those assumptions can break.
What buyers should take from it
The practical guidance applies to any hardware wallet:
- Buy direct when possible, or from a reseller you can verify on the manufacturer's own site.
- Never use a recovery phrase you did not generate on the device yourself. A legitimate wallet will never ship with one.
- Run the manufacturer's authenticity check, while recognizing it may not be the last word if Karpelès's claim is confirmed.
- If in doubt, rotate. Moving funds to a freshly initialized device with a new phrase is exactly what Ledger is advising affected buyers to do.
The context
This lands in a bad year for crypto security. DefiLlama data cited by CoinDesk lists Bitget at over $350 million in September, along with Liquid Network at about $320 million, Drift at $295 million and Kelp at $293 million. Those were exchange and protocol failures. A hardware-wallet incident is different in kind, because it targets the tool people buy specifically to opt out of trusting exchanges.
The next update from Ledger will matter more than the next tracker estimate. Whether this was a rogue distributor, a tampered batch or something deeper in the device determines whether the fix is a reseller contract or a hardware revision.
