toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Toobit CardPay with crypto wherever you go.
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
To be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Ledger investigates CryptoBilis hardware wallet loss reports

2026-10-09 15:04

Ledger is investigating reports of suspected cryptocurrency theft involving customers who bought hardware wallets through CryptoBilis, an authorized reseller serving Indonesia, Malaysia and the Philippines. Onchain researchers have linked more than $72 million—and potentially more than $86 million—to addresses associated with the suspected incident, though neither figure has been independently verified and the overlap between the estimates remains unclear.

The hardware-wallet maker has asked CryptoBilis to suspend sales and shipments while the inquiry continues. Ledger said it has not determined how the reported losses occurred, leaving open questions over whether the issue involves altered devices, compromised packaging, customer setup practices, or another point in the distribution chain.

In a Friday post on X, Ledger’s support account told customers who purchased a device from CryptoBilis within the previous 90 days not to begin setting it up. Customers who had already initialized a device were advised to consider transferring their assets to a new signer created with a new recovery phrase, commonly called a seed phrase.

The warning places the immediate focus on devices that may not yet have been used. A hardware wallet is designed to keep private keys away from internet-connected devices, but that protection depends on the buyer generating and retaining a recovery phrase privately. If a phrase was exposed before or during setup, the person holding it could control the associated assets without needing access to the physical wallet.

Onchain estimates point to a large but unconfirmed loss

The first widely circulated estimate came from onchain researcher tanuki42, who reported that more than $72 million had moved to a cluster of addresses described as connected to the suspected theft. Tanuki42 directed potentially affected users to SEAL 911, a crypto security response group that helps coordinate assistance for victims of exploits and thefts.

A second researcher, Specter, later placed the apparent losses above $86 million after following transfers across Bitcoin, Ethereum and TRON. Specter initially said the transfers appeared to originate from hundreds of victim wallets, then later clarified that the number of affected wallets had not yet been established.

The difference between the estimates is material. Public blockchain records can show where assets moved, but attributing wallets to a single theft event requires analysts to distinguish between direct victim transfers, consolidation wallets, intermediary transactions and unrelated activity. Until Ledger, CryptoBilis, or affected customers provide further evidence, the total value lost and the scope of the alleged compromise remain unresolved.

Neither Ledger nor CryptoBilis has publicly identified affected device models, batch numbers, or shipment dates beyond the 90-day customer warning. Ledger’s reseller listing identifies CryptoBilis as an official reseller in the three Southeast Asian markets, which makes the investigation especially sensitive for customers who relied on the company’s approved sales channels.

Supply-chain concerns move beyond online security

Former Mt. Gox chief executive Mark Karpeles said the reports could be connected to a separate issue he had already been examining. He asked affected users to contact him or provide photographs of opened devices and their circuit boards, which could help identify signs of physical modification.

Changpeng Zhao, Binance’s co-founder, separately said the available information appeared consistent with a supply-chain incident involving one vendor. He described a possible scenario in which a limited number of buyers received counterfeit or altered devices.

That theory has not been confirmed, but it reflects a risk distinct from a conventional phishing attack or malware infection. A compromised device could potentially direct a buyer toward a recovery phrase already known to an attacker, or could contain altered components that undermine expected security checks. Ledger’s advice to use a newly created signer and seed phrase addresses the possibility that an existing phrase may no longer be safe.

The reports do not establish that Ledger’s wallet software or its wider hardware range has been compromised. They concern purchases through a particular reseller and an investigation that is still underway. The company’s decision to halt CryptoBilis sales and shipments suggests it is treating the reseller channel as a potential source of exposure while it gathers evidence.

Customers are being urged to avoid using potentially affected devices

Customers who bought Ledger products from CryptoBilis during the stated period face a practical choice: leave an unopened device uninitialized until Ledger provides more direction, or move assets away from a wallet already set up through the reseller.

Moving funds requires creating a wallet with a recovery phrase that has never been exposed, then sending the assets to addresses controlled by that new wallet. Users should not reuse the potentially affected recovery phrase on a replacement device, since the phrase—not the physical device—is the ultimate credential controlling blockchain assets.

Customers considering a move should obtain guidance from Ledger’s official support channels rather than responding to direct messages, email links, or unsolicited offers of recovery assistance. Theft incidents often generate a second wave of impersonation attempts aimed at people seeking help.

Affected users can also preserve relevant evidence, including order confirmations, delivery information, device packaging and transaction IDs. Those records may help Ledger and independent investigators compare potentially affected purchases with onchain movements and determine whether the suspected losses trace back to a common shipment or device batch.

For now, the investigation has produced a serious warning for recent CryptoBilis customers rather than a confirmed explanation. Ledger’s 90-day setup freeze gives the company a defined group of purchases to examine, while the onchain estimates indicate that investigators may be dealing with a potentially high-value incident spanning several major networks.


Worried about wallet hacks? Strengthen your protection with Toobit’s security tips in this guide before your next move.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Toobit Card
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.