Ledger is investigating reports of suspected cryptocurrency theft involving customers who bought hardware wallets through CryptoBilis, an authorized reseller serving Indonesia, Malaysia and the Philippines. Onchain researchers have linked more than $72 million—and potentially more than $86 million—to addresses associated with the suspected incident, though neither figure has been independently verified and the overlap between the estimates remains unclear.
The hardware-wallet maker has asked CryptoBilis to suspend sales and shipments while the inquiry continues. Ledger said it has not determined how the reported losses occurred, leaving open questions over whether the issue involves altered devices, compromised packaging, customer setup practices, or another point in the distribution chain.
In a Friday post on X, Ledger’s support account told customers who purchased a device from CryptoBilis within the previous 90 days not to begin setting it up. Customers who had already initialized a device were advised to consider transferring their assets to a new signer created with a new recovery phrase, commonly called a seed phrase.
The warning places the immediate focus on devices that may not yet have been used. A hardware wallet is designed to keep private keys away from internet-connected devices, but that protection depends on the buyer generating and retaining a recovery phrase privately. If a phrase was exposed before or during setup, the person holding it could control the associated assets without needing access to the physical wallet.
Onchain estimates point to a large but unconfirmed loss
The first widely circulated estimate came from onchain researcher tanuki42, who reported that more than $72 million had moved to a cluster of addresses described as connected to the suspected theft. Tanuki42 directed potentially affected users to SEAL 911, a crypto security response group that helps coordinate assistance for victims of exploits and thefts.
A second researcher, Specter, later placed the apparent losses above $86 million after following transfers across Bitcoin, Ethereum and TRON. Specter initially said the transfers appeared to originate from hundreds of victim wallets, then later clarified that the number of affected wallets had not yet been established.
The difference between the estimates is material. Public blockchain records can show where assets moved, but attributing wallets to a single theft event requires analysts to distinguish between direct victim transfers, consolidation wallets, intermediary transactions and unrelated activity. Until Ledger, CryptoBilis, or affected customers provide further evidence, the total value lost and the scope of the alleged compromise remain unresolved.
Neither Ledger nor CryptoBilis has publicly identified affected device models, batch numbers, or shipment dates beyond the 90-day customer warning. Ledger’s reseller listing identifies CryptoBilis as an official reseller in the three Southeast Asian markets, which makes the investigation especially sensitive for customers who relied on the company’s approved sales channels.
Supply-chain concerns move beyond online security
Former Mt. Gox chief executive Mark Karpeles said the reports could be connected to a separate issue he had already been examining. He asked affected users to contact him or provide photographs of opened devices and their circuit boards, which could help identify signs of physical modification.
Changpeng Zhao, Binance’s co-founder, separately said the available information appeared consistent with a supply-chain incident involving one vendor. He described a possible scenario in which a limited number of buyers received counterfeit or altered devices.
That theory has not been confirmed, but it reflects a risk distinct from a conventional phishing attack or malware infection. A compromised device could potentially direct a buyer toward a recovery phrase already known to an attacker, or could contain altered components that undermine expected security checks. Ledger’s advice to use a newly created signer and seed phrase addresses the possibility that an existing phrase may no longer be safe.
The reports do not establish that Ledger’s wallet software or its wider hardware range has been compromised. They concern purchases through a particular reseller and an investigation that is still underway. The company’s decision to halt CryptoBilis sales and shipments suggests it is treating the reseller channel as a potential source of exposure while it gathers evidence.
Customers are being urged to avoid using potentially affected devices
Customers who bought Ledger products from CryptoBilis during the stated period face a practical choice: leave an unopened device uninitialized until Ledger provides more direction, or move assets away from a wallet already set up through the reseller.
Moving funds requires creating a wallet with a recovery phrase that has never been exposed, then sending the assets to addresses controlled by that new wallet. Users should not reuse the potentially affected recovery phrase on a replacement device, since the phrase—not the physical device—is the ultimate credential controlling blockchain assets.
Customers considering a move should obtain guidance from Ledger’s official support channels rather than responding to direct messages, email links, or unsolicited offers of recovery assistance. Theft incidents often generate a second wave of impersonation attempts aimed at people seeking help.
Affected users can also preserve relevant evidence, including order confirmations, delivery information, device packaging and transaction IDs. Those records may help Ledger and independent investigators compare potentially affected purchases with onchain movements and determine whether the suspected losses trace back to a common shipment or device batch.
For now, the investigation has produced a serious warning for recent CryptoBilis customers rather than a confirmed explanation. Ledger’s 90-day setup freeze gives the company a defined group of purchases to examine, while the onchain estimates indicate that investigators may be dealing with a potentially high-value incident spanning several major networks.
Worried about wallet hacks? Strengthen your protection with Toobit’s security tips in this guide before your next move.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
