Ledger is investigating reports that cryptocurrency worth more than USD 86 million may have been stolen from wallets belonging to customers who purchased its hardware devices through a Southeast Asian reseller. The company acknowledged the reports on October 9, 2026, and asked the reseller, CryptoBilis, to suspend sales and shipments while the investigation continues.
Blockchain investigators identified the reported losses by tracking suspicious transactions across multiple networks, including Bitcoin, Ethereum, and TRON. However, the USD 86 million estimate remains unconfirmed, and investigators have not established whether the incidents share a common cause or resulted from device tampering.
As a precaution, Ledger advised customers who purchased devices through CryptoBilis in the past 90 days not to set them up unless they have already done so. Customers who have activated their devices were advised to consider transferring their cryptocurrency to a new Ledger device configured with a newly generated recovery phrase. Ledger said it would provide further updates as the investigation progresses.
CryptoBilis is listed as an official Ledger reseller in Indonesia, Malaysia and the Philippines. The investigation is currently focused on reports involving customers who purchased through this seller, rather than a confirmed vulnerability affecting all Ledger products.
Blockchain investigator Specter estimated that more than USD 86 million in cryptocurrency had been linked to suspected theft addresses. Another investigator, known as tanuki42, had previously estimated losses exceeding USD 72 million.
The figures have not been independently confirmed, and it remains unclear whether the estimates cover the same transactions. The number of affected wallets is also uncertain.
Social media reports describe funds disappearing from wallets despite claims that their recovery phrases were stored securely. These accounts have raised questions about how attackers gained access, but they do not establish the cause of the losses.
Also Read: X Sues Crypto Influencers Over Alleged GBP 207K Creator Payout Fraud
One possible explanation is a supply-chain attack, in which attackers alter or replace devices before they reach customers. A compromised device could potentially expose funds if an attacker already knows its recovery phrase.
Binance co-founder Changpeng Zhao suggested that the available information pointed towards a problem involving one vendor and possibly fake or tampered devices. However, this remains an assessment, not a confirmed finding. Ledger has not established whether the reported thefts resulted from device tampering, compromised recovery phrases, phishing, or another method.