Ledger Investigates Reports of Fund Losses Tied to Reseller CryptoBilis, as Investigator Traces ~$87M
Ledger is investigating reported fund losses among Southeast Asian customers who bought hardware wallets from reseller CryptoBilis, as an onchain investigator traces roughly $87 million in suspected thefts.
Ledger said Friday it is investigating reports that customers in Southeast Asia who bought its hardware wallets from a reseller called CryptoBilis have lost funds, and it has asked the reseller to halt all sales and shipments while the probe continues.
In a post from its support account on X on October 9, Ledger said anyone who bought a device from CryptoBilis in the past 90 days should not set it up. Customers who already have should move their assets to a new Ledger signer generated with a fresh seed phrase — the backup that can regenerate a wallet's private keys. The Paris-based company did not say what caused the losses, how many customers were affected, or whether any devices were tampered with. As Decrypt notes, a hardware wallet compromised before it reaches the buyer — for instance, shipped with a recovery phrase an attacker already knows — can leave funds exposed even though the keys never go online. No tampering has been confirmed.
The dollar figure comes not from Ledger but from pseudonymous onchain investigator Specter, who said they traced theft addresses flagged in user reports on X and Reddit and found inflows from "hundreds of victim wallets" across Ethereum, Tron and Bitcoin. Specter put total losses at "$86M+"; Arkham data the investigator shared shows nearly $87 million at the addresses — about $42 million in ETH, $17.6 million in BTC and $16.5 million in USDT, per Decrypt's reading of the data. Ledger has not confirmed the figure or the cause, and it is not established that every theft is linked to the reseller.
Key facts
- Who: Ledger investigating losses among Southeast Asian buyers of its devices from reseller CryptoBilis (Ledger Support on X, Oct. 9, 2026).
- Action taken: Ledger asked CryptoBilis to pause all sales and shipments; told 90-day buyers not to set up devices, and existing users to migrate to a new signer with a new seed phrase (Ledger Support via Decrypt).
- Suspected loss: "$86M+" (Specter); ~$87M per Arkham data shared by Specter — ~$42M ETH, $17.6M BTC, $16.5M USDT. Unconfirmed by Ledger (Decrypt).
- Chains hit: Ethereum, Tron, Bitcoin (Specter).
The real-world read
The headline number is doing a lot of work, so watch where it comes from. Ledger has confirmed only that it is investigating and has paused the reseller; it has not endorsed any loss figure or named a cause. The ~$87 million is Specter's tracing plus Arkham data — credible onchain work, but a single investigator's attribution, and even they flag it's unclear every theft ties back to CryptoBilis. Note also what's unsaid: Ledger named no cause and confirmed no tampering, so "compromised device" remains a plausible theory, not a finding. Decrypt frames this within a rough stretch for crypto security — Bitget's ~$387M hack, Drift's $285M, Blockstream's $320M — useful context, but not evidence about this case.
This is news, not financial or security advice.
Sources
- Decrypt (Tier 2, secondary), "Ledger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller," Oct. 9, 2026 — primary reporting; relayed Ledger's statement and Specter's tracing.
- Ledger Support (@Ledger_Support) on X, Oct. 9, 2026 (primary) — company confirmation of the investigation and the request to pause CryptoBilis sales, via Decrypt.
- Specter (@SpecterAnalyst) on X / Arkham data (onchain investigator; interested-party caveat — self-sourced tracing, unconfirmed by Ledger) — the "$86M+"/~$87M figure and chain breakdown, via Decrypt.