cleartext

Independent, sourced crypto news. No paid placements.

ledger

Ledger probes Malaysian reseller CryptoBilis after wallets drained of up to $86M

Ledger says it is investigating its Malaysian reseller CryptoBilis after wallets bought there were drained of an estimated $72M to over $86M, and has ordered the reseller to halt sales.

Ledger has told a Southeast Asian reseller to stop selling its hardware wallets while it investigates a wave of thefts from customers who bought devices through that channel, according to reporting by Protos published 9 October.

The reseller is CryptoBilis, which markets itself as "the authorized reseller of Ledger products in Malaysia" and also sells Trezor, OneKey, Tangem and SafePal devices. Protos reported that users who bought Ledger wallets from CryptoBilis have been drained of funds in an ongoing incident.

The loss figures come from crypto analysts Specter and Tanuki42, who Protos says first flagged the reports and traced the affected addresses. Their estimates range from $72 million to over $86 million. That range is an analyst estimate derived from on-chain tracing, not a figure confirmed by Ledger.

Ledger confirmed it was investigating "a specific issue" concerning CryptoBilis and said the reseller has been told "to pause all sales and shipments of Ledger devices," per the X statement Protos cited. Ledger advised anyone who bought a device from CryptoBilis in the past 90 days not to initiate setup, and told those who already had to move their assets to a new Ledger signer. The company said it would keep customers updated and, approached by Protos for comment, pointed back to the same X statement and said it had "nothing further to add."

CryptoBilis had not responded to Protos at the time of publication. Cleartext has not independently verified the loss figures or the tampering mechanism.

Key facts

  • Ledger is investigating its reseller CryptoBilis and has ordered it to pause all Ledger sales and shipments (Ledger X statement, via Protos).
  • Estimated losses: $72M to over $86M, from analysts Specter and Tanuki42's address tracing (via Protos).
  • Buyers from CryptoBilis in the last 90 days told not to set up devices; those who did, to move funds to a new Ledger signer (Ledger, via Protos).
  • CryptoBilis bills itself as Ledger's "authorized reseller" in Malaysia and sells multiple wallet brands (Protos).

The real-world read

The suspected vector here is the supply chain, not the Ledger device design. Former Mt. Gox CEO Mark Karpelès noted that reseller-sold Ledgers have previously been found tampered with and implanted with spyware to steal passkeys — the pattern this incident appears to fit. Security researcher Taylor Monahan pushed back on the louder reports, warning they were stoking panic and making people assume a zero-day when none is apparent, and flagging the real follow-on danger: phishing, fake Google ads and fake migration apps that prey on rattled users. Monahan also said Ethereum researcher Justin Drake's recent call to go "bunker mode" over AI breaking elliptic-curve crypto "within months" may do more harm than the threat it warns of. Worth noting: this all rests on one secondary report plus public posts from the named researchers; Ledger has confirmed an investigation but not the dollar figures, and CryptoBilis has said nothing.

This is reporting, not financial or security advice.

Sources

  • Protos, "Ledger says Southeast Asia reseller linked to $86M draining" (9 Oct 2026) — the core reporting; relayed Ledger's statement and the analyst loss estimates, and gathered the Karpelès, Monahan and Drake comments. Secondary source; figures attributed to analysts Specter and Tanuki42.