Jump to content
The Coin Wire

Crypto moves, protocols and policy

Ledger probes CryptoBilis wallets after reported $86M drain

Ledger is investigating reports tied to CryptoBilis devices and told recent buyers to pause setup or move funds, while the cited $86 million loss remains unverified.

By The Coin Wire Editorial3 min read

Ledger probes CryptoBilis wallets after reported $86M drain

Ledger said on Friday, October 9, that it is investigating reports of missing crypto linked to devices sold by Southeast Asian reseller CryptoBilis, and asked the reseller to pause sales and shipments. The scale could be large: investigator Specter estimated losses above $86 million across Bitcoin, Ethereum and Tron, but Ledger has not confirmed the figure or the cause, according to CoinDesk’s report.

The warning is limited to customers who bought from this reseller in the past 90 days. Ledger advised those who have not set up their device to wait; those who have should consider moving assets to a new Ledger signer with a newly generated recovery phrase. CryptoBilis is listed as an official Ledger reseller in Indonesia, Malaysia and the Philippines, The Block reported.

What do investigators know about the reported losses?

They have traced suspected outflows, but the total and connection between cases remain uncertain. Specter said they found flows from wallets on Bitcoin, Ethereum and Tron and estimated losses above $86 million. Another researcher, tanuki42, put funds moved to suspected theft addresses above $72 million. The Block reported that neither estimate had been independently confirmed and that it was unclear whether they covered the same transactions.

That distinction matters: the on-chain estimates show assets arriving at addresses investigators suspect are linked to theft, but do not establish that every transfer came from a CryptoBilis buyer. Specter also revised an earlier claim about hundreds of affected wallets, saying the actual number was not yet known. Ledger has not said how many customers reported losses.

Does this point to a Ledger-wide security failure?

There is no confirmed evidence that Ledger’s own systems or wallet technology were compromised. The investigation concerns reports linked to a third-party reseller, and Ledger has not confirmed that devices were tampered with. One possible supply-chain scenario would involve a device reaching a buyer with a recovery phrase already known to an attacker, who could then access funds deposited to that wallet; that remains a hypothesis, not an established explanation.

The distinction separates this case from a breach at an exchange, where an attacker targets assets held by a service. A hardware wallet is meant to leave control of keys with its owner, reducing reliance on a custodian. But that arrangement also makes the device and its recovery phrase central: if the phrase is exposed before setup, the device’s offline storage does not by itself protect the funds. The suspected reseller link, if confirmed, would make the distribution path part of the security question.

What should change as the investigation continues?

For affected buyers, Ledger’s immediate guidance is precautionary: do not set up a device bought from CryptoBilis in the past 90 days, or consider moving assets to a new signer with a new phrase if it is already in use. That creates friction and asks users to take action before the cause is known, but waiting could leave funds exposed if the phrase has been compromised. Ledger has asked the reseller to stop shipments while it investigates.

The next useful signals are concrete: whether Ledger identifies a device or distribution issue, whether CryptoBilis sales resume, and whether researchers can link the suspected addresses to specific affected devices. The reported dollar totals and wallet counts may also change as investigators reconcile overlapping flows. Until those details are established, the case warrants a targeted response for recent CryptoBilis buyers, not a conclusion that Ledger devices broadly are compromised.

Source material