Ledger Halts CryptoBilis Sales Amid $86M Wallet Drain Probe

Ledger has halted hardware wallet sales through Southeast Asian distributor CryptoBilis and advised anyone who purchased a device from CryptoBilis in the past 90 days not to begin setup. The company is investigating reports of lost funds from users in Southeast Asia who bought products from the reseller.
In a statement posted on X, Ledger said it asked CryptoBilis to pause all sales and shipments of Ledger devices as a precaution pending the investigation's results. The company recommended that users who purchased from the reseller in the last 90 days and have not yet set up their device avoid initiating setup. Those who have already set up their Ledger device should consider moving assets to a new Ledger signer with a new seed phrase.
Ledger has not disclosed how many customers are affected or confirmed the value of the reported losses. The widely cited figure of more than $86 million comes from pseudonymous on-chain investigator Specter, who published addresses associated with reported wallet drains across Bitcoin, Ethereum and Tron. Specter later admitted that the actual victim count had not yet been established, and the available information does not prove that every transaction included in the estimate involved a CryptoBilis customer.
Ledger has confirmed only that it is investigating reports from Southeast Asian users who purchased products through CryptoBilis. It has not identified the countries involved, named individual victims, or linked the incident to a vulnerability affecting Ledger devices generally. It is not known whether customers received altered or counterfeit hardware, used recovery phrases that had already been exposed, or lost their assets through another route such as phishing or malicious transaction approval. Until the mechanism is established, the incident cannot be described as a confirmed hardware-wallet exploit or supply-chain attack.
The reports emerged less than three weeks after Bitget confirmed a $387.5 million breach affecting part of its hot- and warm-wallet infrastructure. The two incidents involve different custody models: Bitget controlled the compromised wallets, while Ledger users hold their own keys. In the Ledger case, the unresolved question is whether that control was compromised before buyers received or initialized their devices.
Subscribe Now

