Partner · Blockchain Life 2026 — Dubai, December 1–2 · 15,000+ attendees from 130+ countriesGet tickets →
LIVE
BTC—ETH—SOL—BNB—XRP—ADA—AVAX—DOGE—LINK—DOT—MATIC—ATOM—LTC—TRX—TON—BTC—ETH—SOL—BNB—XRP—ADA—AVAX—DOGE—LINK—DOT—MATIC—ATOM—LTC—TRX—TON—
—▲0.0%
News

Ledger Tells CryptoBilis Buyers Not to Set Up Their Devices

10 Oct 2026by CryptoJazz Admin1 min read9 views
Ledger Tells CryptoBilis Buyers Not to Set Up Their Devices

Ledger said on Friday it is investigating reports of lost funds among customers in Southeast Asia who bought its hardware wallets through a reseller in Kuala Lumpur. The company asked that reseller, CryptoBilis, to pause sales and shipments while the investigation runs. Buyers from the past 90 days were told not to begin setup; anyone already using one was told to move assets to a new signer with a fresh recovery phrase. Four loss estimates were in circulation by Saturday. None of them is Ledger's, and no outlet has verified any of them.

What Ledger put its name to

The advisory went out through the company's support account on X, and it is narrow. Ledger said it is investigating "reports of loss of funds from users in South East Asia" who bought from CryptoBilis, and that it had asked the reseller to pause sales and shipments. Nothing in the post names a cause. It has sold more than 7 million devices worldwide and says its own infrastructure, systems and services were not compromised.

"No reports were made of products purchased directly from Ledger," the company said in a statement to Bitcoin Magazine.

CryptoBilis is based in Kuala Lumpur and is listed as an authorised Ledger reseller in Indonesia, Malaysia and the Philippines, so the guidance turns on where a device was bought. The company has said nothing. Bitcoin Magazine, The Block and Protos each asked and got no reply. The last time Ledger was in this position the fault was in its own software: it patched an Ethereum signing flaw and then fought publicly over the disclosure. This is a different failure entirely.

No two estimates agree

The pseudonymous researcher tanuki42 listed eight suspected theft addresses and put the sum moved through them above $72 million. Another investigator, Specter, traced addresses on Bitcoin, Ethereum and Tron and put the losses above $86 million. Protos put it above $80 million. The on-chain analytics firm Bitquery, in a count no other party has published, puts it at about $92.9 million drained from 311 wallets across five chains. It stands unverified, and it is the only hard wallet count published.

These are not revisions of one tally. The Block and Techreport both say it is unclear whether the tanuki42 and Specter estimates cover the same addresses and transactions, and the chains listed differ between accounts. They do not reconcile. Specter first described funds arriving from hundreds of victim wallets, then said the number affected is not yet known. Ledger has confirmed no total, no count of affected customers and no cause.

A chip in a device, and a claim about it

CoinDesk reported on Friday that a supply-chain attack is one possible explanation: a device compromised before it reaches the buyer, shipped with a recovery phrase the attacker already knows. The same report says plainly that there is no confirmation tampering or pre-generated phrases caused the losses. Mark Karpelès, formerly of Mt. Gox, said a device he received from Malaysia arrived with apparently intact shrink-wrap and held a hidden component near where screen padding normally sits, which he later described as a "spy SIM card" roughly two millimetres square. That is one device and one person's account.

Other voices pulled the other way. The security researcher Taylor Monahan said the reports look like panic and that no zero-day vulnerability appears to be involved. Changpeng Zhao said the problem looks localised to one vendor and that a small number of people are likely affected. Neither claim is settled. Both sit alongside this year's run of vendor-side incidents, among them a MetaMask breach that left Ethereum stakers in a two-week exit line.

Still open on Saturday

The total is unknown. So is the number of customers, the number of devices and whether any of them was physically altered. We could not establish which of the four figures supersedes which, and the parties behind them are separate. The Security Alliance has asked anyone drained to contact its SEAL 911 team. Ledger said it will keep informing customers. Until it names a cause, the only instruction with the company's name on it is the one about not setting up a device.

Read also: ZachXBT Says He Paid $349,700 to Sit Inside a Laundering Ring

← All news