Ledger Investigates Reports of Crypto Drain Linked to Southeast Asia Reseller CryptoBilis

·

Ledger said Saturday it is investigating reports that customers in Southeast Asia who bought hardware wallets from reseller CryptoBilis had their crypto funds drained, and it warned recent buyers not to set up unused devices. Third-party blockchain investigators have put possible losses far higher, with the largest public estimate so far from forensic firm Bitquery at $92.9 million.

The wallet maker said it opened the investigation on Oct. 9 and asked CryptoBilis to pause all sales and shipments while it reviews the reports. Ledger also said, in a statement reported by The Block, that “Ledger's infrastructure, systems and services were not compromised.”

What Ledger has not publicly confirmed is just as important. The company has not identified a cause, disclosed how many customers may have been affected, confirmed a total loss figure, or said whether any devices were physically tampered with. The likely mechanism remains unproven.

Outside researchers have produced different estimates of the losses, underscoring the uncertainty around the scope of the incident. A researcher using the name tanuki42 estimated more than $72 million drained. Another on-chain investigator, Specter, put the figure at more than $86 million. Bitquery, in a broader forensic analysis published Oct. 10, said $92.9 million was drained from 311 wallets across TRON, Bitcoin, Ethereum, BNB Chain and Polygon. Ledger has not endorsed any of those totals.

Bitquery said the funds were moved across multiple blockchains on the morning of Oct. 9 and that the attackers used mixers — services intended to obscure transaction trails — and stablecoin swaps while laundering funds. The firm also said Tether, the company behind the USDT stablecoin, froze about $10 million in USDT tied to addresses linked to the suspected theft, spread across 20 wallets at the time of its snapshot.

The case carries unusual weight because CryptoBilis was listed on Ledger’s official reseller finder for Malaysia, Indonesia and the Philippines. That meant buyers in those markets were directed to the company through Ledger’s own authorized reseller pages, making the episode as much a consumer-protection and trust issue as a crypto crime story.

Hardware wallets are designed to keep private keys — the credentials that control crypto holdings — offline, reducing exposure to online attacks. But that security model depends on the device and the setup process being genuine. If a buyer receives a compromised device or is guided through a compromised setup, the protection can break down. Investigators and industry observers suspect some form of reseller or supply-chain compromise in this case, but on-chain data alone cannot prove whether the problem involved a tampered device, a pre-seeded recovery phrase, phishing or some other method.

For now, Ledger’s public guidance to recent CryptoBilis customers is cautious and unusually direct. “We recommend Ledger users who purchased from this reseller in the last 90 days to not initiate set up if you have not done so yet. If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed). We will continue to inform customers of updates as the investigation progresses,” Ledger Support said, as quoted by The Block.

The warning leaves customers with a stark message: even without a confirmed explanation, Ledger believes the risk is serious enough to tell recent buyers not to trust unused devices from a reseller it had listed as authorized while the investigation continues.

Tags: #ledger, #cryptocurrency, #hardware-wallets, #security