What to Know
- Ledger is investigating reports that more than $86 million in cryptocurrency may have been stolen from hundreds of wallets tied to devices sold by CryptoBilis, a Southeast Asian reseller.
- The reported losses and any direct connection between the wallets, the reseller, and the devices have not been independently verified.
- Ledger has asked CryptoBilis to halt sales and shipments while the investigation continues.
- Customers who purchased devices from the reseller within the past 90 days have been advised not to begin setting them up.
- Customers who already activated wallets from the reseller should consider moving assets to a new Ledger device with a newly generated recovery phrase.
- Suspected theft addresses have been traced across Bitcoin, Ethereum, and Tron, though it remains unclear whether the incidents are connected.
- A supply-chain attack involving tampered devices is one possible explanation, but the cause, number of affected users, and total losses remain unconfirmed.
- Ledger says there is no confirmed evidence that its own systems or wallet technology were compromised.
Ledger Opens Investigation Into Reseller-Linked Wallet Reports
Ledger is investigating reports of missing cryptocurrency from wallets linked to devices sold through CryptoBilis, a Southeast Asian reseller, after social media posts raised concerns that user funds may have been drained across multiple blockchain networks. The hardware wallet maker has not confirmed the reported loss amount, the number of affected users, or the cause of the suspected thefts, but it has moved to contain potential risk by asking the reseller to pause sales and shipments.
The situation has drawn heightened attention because hardware wallets are widely used by crypto investors who want to keep private keys offline rather than leaving assets on exchanges. Ledger, founded in 2014 and based in Paris, says it has sold more than 7 million devices worldwide. Its products are designed to protect access credentials for digital assets by keeping private keys away from internet-connected environments, which is why any concern involving the supply of physical devices can quickly become a broader market issue.
The current investigation focuses on devices sold by CryptoBilis, not on a confirmed compromise of Ledger’s own infrastructure. Ledger has acknowledged reports from customers who purchased devices through the reseller, but it has not identified the cause of the losses. The company has also not verified claims that more than $86 million in cryptocurrency was stolen from hundreds of wallets.
Reported Losses Span Bitcoin, Ethereum, and Tron Addresses
Pseudonymous blockchain investigator Specter said on X that more than $86 million in crypto may have been stolen from hundreds of wallets. Specter said suspected theft addresses were traced across Bitcoin, Ethereum, and Tron after reports appeared from Ledger users on X and Reddit. However, there has been no independent confirmation of the total amount of user assets affected, and it remains unclear whether the reported incidents are linked to a single cause.
The spread of reported activity across several networks makes the situation particularly difficult to assess. Crypto users often hold assets on multiple blockchains, and a compromised recovery phrase or private key could potentially expose a range of wallets. At the same time, blockchain tracing can identify where funds moved, but it does not by itself prove how access was obtained or whether multiple victims were affected by the same mechanism.
For now, market participants are treating the figure of more than $86 million as an allegation rather than a verified loss total. The uncertainty is important because crypto security incidents often develop in stages, with early claims sometimes changing as investigators separate confirmed wallet movements from unrelated transactions, duplicate reports, or broader speculation.
Ledger Advises Recent Buyers to Avoid Setup
Ledger has advised customers who purchased devices from CryptoBilis within the past 90 days not to start setting them up. That guidance is intended to reduce the chance that new users activate a device that may be subject to an unresolved supply risk. The company has also asked CryptoBilis to pause all sales and shipments while the inquiry is ongoing.
For customers who already activated wallets purchased through the reseller, Ledger said they should consider transferring assets to a new Ledger device with a newly generated recovery phrase. That recommendation is significant because the recovery phrase is the core backup that can restore access to a wallet. If a recovery phrase was ever exposed, generated insecurely, or known to a third party, the funds associated with it could be at risk even if the device itself appears to function normally.
Crypto security specialists generally view recovery phrases as among the most sensitive pieces of information in self-custody. A user who controls the phrase controls the wallet. A user who enters a phrase supplied by someone else, receives a device that has already been initialized, or stores the phrase insecurely can lose the protection that hardware wallets are meant to provide. Ledger’s guidance to create a newly generated recovery phrase on a new device reflects that principle.
Supply-Chain Tampering Is a Possible but Unconfirmed Scenario
One possible explanation under discussion is a supply-chain attack involving tampered hardware wallets before they reached customers. In such a scenario, a device might be manipulated in a way that gives an attacker access later, or a user might be tricked into using a recovery phrase that the attacker already knows. If funds are deposited into a wallet controlled by a compromised phrase, the attacker could drain assets at a later time.
That possibility remains unconfirmed. Ledger has not said that tampering occurred, and there is no confirmed evidence that pre-generated recovery phrases or device manipulation caused the reported losses. The company has also not said that its own systems or wallet technology were breached. This distinction matters because a reseller-linked supply issue would differ sharply from a compromise of Ledger’s core hardware design, software systems, or internal infrastructure.
Supply-chain risks are a persistent concern in the hardware wallet sector because users must trust that devices arrive in a legitimate, untampered state. Reputable wallet makers typically instruct users to initialize devices themselves, generate recovery phrases only during setup, and reject any device that arrives with a recovery phrase already provided. Those practices are designed to prevent attackers from inserting themselves between the manufacturer and the end user.
Crypto Security Losses Remain in Focus
The investigation lands during a difficult period for crypto security. Last month, crypto exchange Bitget suffered an exploit that resulted in over $350 million in stolen assets. Other major incidents included Liquid Network at about $320 million, Drift at $295 million, and Kelp at $293 million, according to DefiLlama data.
Those figures have kept exploit risk near the center of market discussion, especially as investors continue to weigh the tradeoffs between self-custody, exchange custody, decentralized protocols, and third-party service providers. Hardware wallets are often promoted as a way to reduce exchange and online wallet exposure, but they also place more responsibility on users to safeguard recovery phrases and buy devices through trusted channels.
The Ledger investigation underscores that self-custody is not a single action but a chain of security decisions. The purchase channel, packaging, device initialization, recovery phrase handling, and later transaction approvals all matter. Even a well-known wallet brand cannot eliminate every risk if a user receives a device through a compromised distribution path or follows unsafe setup instructions.
No Confirmed Compromise of Ledger Systems
At this stage, there is no confirmed evidence that Ledger’s own systems or wallet technology were compromised. The investigation concerns devices sold by a third-party reseller, and Ledger has framed its actions as precautionary while it gathers more information. The company said it would provide updates as the investigation progresses.
That does not remove the urgency for potentially affected customers. Anyone who bought a Ledger device through CryptoBilis within the past 90 days has been told not to begin setup. Anyone who already activated such a device has been advised to consider moving assets to a new Ledger device with a new recovery phrase. Until the cause is established, the safest interpretation for users in the affected purchase group is that unresolved risk may exist.
For the broader crypto market, the case is a reminder that asset security often depends on operational discipline as much as technical design. Hardware wallets can reduce some online attack surfaces, but they do not protect users from every form of social engineering, reseller misconduct, shipping interference, or recovery phrase exposure. The final impact of the Ledger-linked reports will depend on what investigators can verify about the wallets, devices, reseller channel, and fund movements.
Frequently Asked Questions (FAQs)
What is Ledger investigating?
Ledger is investigating reports that cryptocurrency may have been stolen from wallets linked to devices sold by CryptoBilis, a reseller in Southeast Asia. The company has not confirmed the total loss amount, the number of affected users, or the cause.
How much cryptocurrency was reportedly stolen?
Pseudonymous blockchain investigator Specter said more than $86 million in crypto may have been stolen from hundreds of wallets. That figure has not been independently confirmed.
Which blockchain networks were mentioned in the reports?
Suspected theft addresses were traced across Bitcoin, Ethereum, and Tron. It remains unclear whether those incidents are connected or whether they share the same cause.
What has Ledger told recent CryptoBilis buyers to do?
Ledger advised customers who purchased devices from CryptoBilis within the past 90 days not to begin setting them up while the investigation continues.
What should customers do if they already activated a device?
Ledger said customers who already activated wallets purchased through the reseller should consider moving their assets to a new Ledger device with a newly generated recovery phrase.
Was Ledger’s own technology compromised?
There is no confirmed evidence that Ledger’s own systems or wallet technology were compromised. The investigation currently concerns devices sold through a third-party reseller.
Could this be a supply-chain attack?
A supply-chain attack involving tampered devices is one possible explanation, but it has not been confirmed. Investigators have not established whether device tampering, pre-generated recovery phrases, or another cause led to the reported losses.
Why are hardware wallets important for crypto users?
Hardware wallets keep private keys used to access cryptocurrency offline, helping users reduce exposure to online attacks and exchange-related risks. They still require careful setup, secure recovery phrase handling, and trusted purchase channels.
What happens next in the investigation?
Ledger said it will provide updates as the investigation progresses. Key unresolved questions include how many users were affected, whether the reported thefts are connected, and how much cryptocurrency was actually lost.
