More than $92.9 million in cryptocurrency has been traced from 311 wallets in an expanding theft case linked to Ledger devices reportedly sold through Malaysian reseller CryptoBilis, according to blockchain data cited by Bitquery. The suspected compromise spans Ethereum, TRON, Bitcoin, Polygon and BNB Chain, raising the possibility that affected devices or their distribution channel exposed users’ recovery phrases before funds ever reached the blockchain.
The initial estimates were lower. On-chain researcher Specter tracked more than $86 million flowing into addresses associated with the activity on Oct. 9, after complaints from Ledger users began circulating on X and Reddit. Ledger has since said it is investigating cases involving customers in Southeast Asia who purchased devices through CryptoBilis.
Ledger asked CryptoBilis to pause sales and shipments and advised customers who bought a device through the reseller within the previous 90 days not to initialize it. Users who already created wallets using those devices were told to set up a new wallet with a newly generated recovery phrase and transfer assets to fresh addresses.
That guidance places the investigation on the device supply chain rather than on a conventional remote software exploit. A recovery phrase, often called a seed phrase, can restore control of a wallet and its assets on another device. Anyone who obtains it can move funds without needing the physical hardware wallet.
Reports point to possible hardware tampering
Mark Karpelès, the former chief executive of Mt. Gox, warned on Oct. 8 that counterfeit or modified Ledger devices could contain hidden SIM cards designed to transmit recovery phrases. As theft reports grew, Karpelès said a Ledger unit bought in Malaysia appeared to have intact packaging but contained a suspicious module with a SIM chip beneath screen padding.
SlowMist chief information security officer 23pds described a potential technique in which an added component intercepts data displayed during wallet setup, records the recovery phrase, and transmits it through LTE or eSIM connectivity. Such an approach would focus on the device display and its wiring, rather than extracting private keys from the secure element, the hardware component designed to isolate sensitive wallet credentials.
The route of compromise has not been confirmed. Investigators are examining whether devices were altered during distribution, resale or another stage before delivery to customers. Reports describing hidden components and opened packages remain part of the developing inquiry rather than a confirmed explanation for every theft.
Bitquery’s updated tracking also identified patterns consistent with coordinated draining activity, according to the supplied data. Twenty-five wallets reportedly signed the same approval request within three seconds, while suspected attackers made 41 smaller transactions over two weeks before larger thefts emerged. Those transactions may have served as tests, although blockchain activity alone cannot establish the operators’ intent.
The same data indicated that roughly 60% of affected users had funded newly initialized wallets within the previous 90 days, aligning with Ledger’s warning to recent CryptoBilis customers. The clustering of recent setups could help investigators narrow the period in which devices were sold or delivered.
Bitcoin losses alone reached 213 BTC
Galaxy research head Alex Thorn tracked 213.42 BTC connected to the Ledger–CryptoBilis case, valued at roughly $17.70 million when he published the analysis. Thorn said about 92% of the Bitcoin had been held for fewer than 90 days before being consolidated, and the BTC remained unspent across three consolidation addresses.
Lookonchain identified individual losses that illustrate how quickly funds could disappear after a wallet was set up. In one case, a wallet labelled TY24Ya deposited 7 million USDT after its owner reportedly bought a device three weeks earlier. The funds were removed about 10 hours later, Lookonchain said.
A second wallet reportedly held 80 BTC bought four months earlier for approximately $5.2 million. The owner later transferred the full balance to a recently purchased CryptoBilis device about one week before the BTC was stolen, according to Lookonchain’s tracing. The coins had an unrealized gain of about $1.38 million before the loss.
Onchain Lens reported that addresses believed to be controlled by the attackers deposited 430.2 ETH, then valued around $1.07 million, into Tornado Cash through four wallets. Tornado Cash is a transaction-mixing protocol that can make it harder to connect deposits and withdrawals on Ethereum.
Part of the USDT connected to the case was frozen by Tether, according to transaction tracing cited in the reports. Remaining unfrozen USDT was swapped into USDD through TRON-based SUN.io and the USDD PSM mechanism. Some transfers also interacted with a Binance hot wallet, though that interaction alone does not identify the owner or destination of the funds.
Reseller halts regional sales
CryptoBilis has suspended hardware-wallet sales and shipments in Malaysia, the Philippines and Indonesia, according to its X account. The company said it had temporarily closed physical stores and would cooperate with Ledger’s security inquiry, including allowing independent experts to review its internal processes. It said an update was expected within three working days.
CryptoBilis describes itself as a Web3 e-commerce and self-custody tools seller based in Petaling Jaya, Malaysia. Public information previously associated the business with Arravind Prabu as chief executive and Vimal Selvamany as chief technology officer.
Prabu said after the incident became public that he no longer operated CryptoBilis, stating that the company was acquired in March and that the prior management team had exited operations, management and system access. He directed inquiries to Nicholas Chang at the company.
Questions online followed about why the ownership transition had not been announced earlier, as well as a recent CryptoBilis social-media post featuring a Lamborghini. Prabu said the post was made by the new team and that a nondisclosure provision prevented a public announcement until Oct. 19. Ownership records cited after the theft reports listed an individual identified as “JIAMING,” registered in Heilongjiang, China, as holding 100% of CryptoBilis shares from Aug. 3. The records presented do not establish a connection between that shareholder and the suspected device compromise.
Ledger has not announced a compensation arrangement or a recovery plan for affected users. The practical priority for customers who bought through the reseller is to avoid entering a recovery phrase into an uninitialized device and, where a wallet has already been created, migrate assets using a separately generated seed phrase and new receiving addresses.
Worried about wallet hacks? Learn key crypto safety practices to better protect your assets before your next major transfer.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
