News

Ledger warns CryptoBilis buyers after reported wallet drains

Ledger told recent CryptoBilis buyers not to initialize their hardware wallets while it investigates reported drains. The cause and total losses remain unconfirmed.

3 min readWallets
Ledger warns CryptoBilis buyers after reported wallet drains

What happened

Ledger said on 9 October 2026 that it was investigating reported fund losses linked to CryptoBilis, an authorized reseller in Southeast Asia. The company asked CryptoBilis to pause sales and shipments while the investigation continues.

The warning followed reports from people who said funds left wallets after they had bought Ledger devices through the reseller. Ledger has not confirmed how many people were affected, the total value lost or how access to the wallets was obtained.

Crypto newsrooms cited estimates ranging from about $72 million to $92.9 million across several blockchains. Those figures come from outside analysts, not from Ledger. They use different address sets and cannot prove that every address belongs to a CryptoBilis customer.

What Ledger told buyers

Ledger told anyone who bought a device from CryptoBilis in the previous 90 days and had not initialized it to wait for further instructions. It said people who had already initialized one should consider moving funds to a different Ledger device set up with a new recovery phrase.

A recovery phrase is the human-readable backup from which a wallet derives its keys. Restoring the same phrase on a different device recreates the same keys, so changing only the hardware would not create a new wallet. Our guide to keys, seeds and self-custody explains that distinction.

Ledger also said there was no confirmed evidence that its central systems or hardware-wallet technology had been compromised. The warning is limited to the reseller-linked reports under investigation. It does not establish that other Ledger devices or resellers are affected.

What remains unconfirmed

Some investigators suspect a supply-chain attack, in which a device or its packaging is altered before it reaches the buyer. That is a hypothesis, not a published finding. Ledger has not said whether a device was changed, a recovery phrase was exposed, software was substituted or another method was used.

Bitquery's on-chain analysis links 311 addresses on five chains and estimates $92.9 million in movements. It also states the important limit: blockchain data can follow transactions, but it cannot show how wallet keys were obtained. Address attribution can also be incomplete or wrong.

That means a valid Bitcoin transaction cannot reveal whether its signature came from the intended owner, a copied recovery phrase or a changed signing device. The network checks the signature, not the history of the device that produced it.

Why this matters for bitcoin custody

Hardware wallets reduce the need to expose keys to an internet-connected computer, but they do not remove every trust boundary. Buyers still rely on manufacturing, distribution, packaging and setup instructions. A compromised step before initialization can defeat protections that work correctly after setup.

The investigation also shows why a loss estimate is not the same as a confirmed incident total. Analysts can see movements on public chains, while only the affected users, investigators and service providers can establish which wallets belong to the same event and how access was gained.

CoinDesk, The Block, Decrypt, Cointelegraph and BitPinas independently reported the warning. They agree on Ledger's investigation and customer guidance, but the cause, number of victims and loss total remain unresolved.

Newsletter

Bitcoin, without the noise

What happened in Bitcoin, what it actually changes, and the sources so you can check us. One issue at a time, straight to your inbox.

  • One email per issue, never a drip campaign
  • No tracking pixels and no shared addresses
  • Unsubscribe from any issue in one click

Get the next issue

One email per issue, no tracking pixels, and unsubscribe from any of them. We do not share your address. Privacy policy