What happened
Ledger said on 9 October 2026 that it was investigating reported fund losses linked to CryptoBilis, an authorized reseller in Southeast Asia. The company asked CryptoBilis to pause sales and shipments while the investigation continues.
The warning followed reports from people who said funds left wallets after they had bought Ledger devices through the reseller. Ledger has not confirmed how many people were affected, the total value lost or how access to the wallets was obtained.
Crypto newsrooms cited estimates ranging from about $72 million to $92.9 million across several blockchains. Those figures come from outside analysts, not from Ledger. They use different address sets and cannot prove that every address belongs to a CryptoBilis customer.
What Ledger told buyers
Ledger told anyone who bought a device from CryptoBilis in the previous 90 days and had not initialized it to wait for further instructions. It said people who had already initialized one should consider moving funds to a different Ledger device set up with a new recovery phrase.
A recovery phrase is the human-readable backup from which a wallet derives its keys. Restoring the same phrase on a different device recreates the same keys, so changing only the hardware would not create a new wallet. Our guide to keys, seeds and self-custody explains that distinction.
Ledger also said there was no confirmed evidence that its central systems or hardware-wallet technology had been compromised. The warning is limited to the reseller-linked reports under investigation. It does not establish that other Ledger devices or resellers are affected.
What remains unconfirmed
Some investigators suspect a supply-chain attack, in which a device or its packaging is altered before it reaches the buyer. That is a hypothesis, not a published finding. Ledger has not said whether a device was changed, a recovery phrase was exposed, software was substituted or another method was used.
Bitquery's on-chain analysis links 311 addresses on five chains and estimates $92.9 million in movements. It also states the important limit: blockchain data can follow transactions, but it cannot show how wallet keys were obtained. Address attribution can also be incomplete or wrong.
That means a valid Bitcoin transaction cannot reveal whether its signature came from the intended owner, a copied recovery phrase or a changed signing device. The network checks the signature, not the history of the device that produced it.
Why this matters for bitcoin custody
Hardware wallets reduce the need to expose keys to an internet-connected computer, but they do not remove every trust boundary. Buyers still rely on manufacturing, distribution, packaging and setup instructions. A compromised step before initialization can defeat protections that work correctly after setup.
The investigation also shows why a loss estimate is not the same as a confirmed incident total. Analysts can see movements on public chains, while only the affected users, investigators and service providers can establish which wallets belong to the same event and how access was gained.
CoinDesk, The Block, Decrypt, Cointelegraph and BitPinas independently reported the warning. They agree on Ledger's investigation and customer guidance, but the cause, number of victims and loss total remain unresolved.
