Ledger Halts Authorized Reseller After $86M+ in Drained Funds
Ledger has halted sales by authorized Southeast Asian reseller CryptoBilis after on-chain investigators traced more than $86M in losses. The attack mechanism is unconfirmed. Here's what to know and what to do.

Ledger's own "buy from an authorized reseller" advice just became the problem.
Key takeaways
- Ledger is investigating reports of drained funds from Southeast Asian customers who purchased devices from CryptoBilis, a Kuala Lumpur-based reseller that was an officially authorized Ledger partner for Malaysia, Indonesia, and the Philippines.
- On-chain investigators estimate losses above $86M across Bitcoin, Ethereum, and TRON; the attack mechanism remains unconfirmed, and Ledger has not corroborated that figure.
- If you bought a Ledger from CryptoBilis in the last 90 days, do not initialize the device. If already initialized, move funds to a fresh wallet with a newly generated seed phrase.
Ledger went public on October 9, 2026 with an alert that it is investigating reports of fund losses from customers in Southeast Asia who purchased devices from a reseller named CryptoBilis, per the company's own @Ledger_Support post. Ledger immediately asked CryptoBilis to pause all sales and shipments pending investigation.
Pseudonymous on-chain investigator Specter (@SpecterAnalyst on X) estimated total losses above $86M by tracing theft addresses across Bitcoin, Ethereum, and TRON. Ledger has not confirmed a loss figure.
What Ledger Said and What It Did Not
Ledger's statement is precise in two directions. It told customers: "If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed)." And it drew a hard line around its own infrastructure: "No reports were made of products purchased directly from Ledger, and Ledger's infrastructure, systems and services were not compromised."
What Ledger has not said is how the funds left users' wallets. The attack mechanism is unconfirmed. Leading theories include pre-seeded or tampered devices shipped with a known seed phrase, a firmware implant, or a phishing campaign targeting CryptoBilis customers after a data exposure. None of these has been publicly substantiated.
CryptoBilis is a Kuala Lumpur-based vendor operating in Malaysia, Indonesia, and the Philippines. It was not a gray-market operation: it was listed as an official Ledger reseller for Indonesia, Malaysia, and the Philippines on Ledger's own reseller page at shop.ledger.com/pages/resellers. The company did not respond to press inquiries.
The Problem "Authorized Reseller" Does Not Solve
The doctrine most hardware wallet buyers operate under is: buy from an authorized reseller if you can't get directly from the manufacturer. CryptoBilis destroys that heuristic.
Authorization means Ledger vetted the business relationship. It does not mean Ledger audited every device that passed through that reseller's warehouse, every employee who handled fulfillment, or every step of the logistics chain between manufacture and your door. The moment a device leaves Ledger's custody, you are trusting a node you cannot inspect.
Buying from an authorized reseller is not materially different from buying from an unauthorized one in terms of physical supply-chain exposure. The only safe default is buying directly from the manufacturer's website, shipped directly to you.
The $86M figure carries a second piece of context worth holding. The per-asset breakdown from on-chain investigators shows the losses are concentrated in Ethereum, TRON, and USDT. Reported Bitcoin-denominated losses are a fraction of that total.
Bitcoiners holding BTC only in a Ledger purchased directly from Ledger.com are not implicated. The headline number will cause broader alarm than the underlying exposure warrants for that specific group.
Hardware wallet trust is being stress-tested across the board. A firmware bug in Coldcard devices in July 2026 led to faulty seed generation that allowed attackers to guess seed phrases, with losses reported at approximately $116 million, based on TRM Labs' tally of roughly 1,816 BTC drained from over 5,200 addresses across four waves beginning July 30, 2026.
Trezor last month reported that close to 81,000 customers had their details leaked after its third-party fulfillment partner had data stolen.
Three major incidents across three leading hardware wallet brands in under four months is pressure on the entire sector toward multisig setups and collaborative custody risk arrangements that do not concentrate exposure in a single device or vendor relationship.
The falsifiable thesis here: reseller supply chains are a systemic counterparty risk that no hardware wallet brand can fully underwrite once a device leaves their direct custody. The trigger that collapses that framing is a post-investigation finding that the CryptoBilis devices were never physically tampered with and that users were compromised purely through social engineering after a data leak. If that is the root cause, the hardware was fine and the lesson shifts. Watch Ledger's official post-mortem closely.
What to Watch
Ledger's investigation is active. The critical unknown is the attack vector: tampered hardware and phishing carry very different remediation implications for the broader customer base. A confirmed post-mortem will either validate or collapse the supply-chain framing. Until then, if you purchased any hardware wallet from any third-party source and have not verified your seed phrase was generated by the device itself on first initialization, treat it as potentially compromised.
Sources
- Ledger Support official alert, X, October 9, 2026
- First reported by Bitcoin Magazine
Frequently Asked Questions
Is a Ledger purchased directly from Ledger.com safe?
Yes, per Ledger's own statement. Ledger confirmed its infrastructure, systems, and services were not compromised, and no reports have come from direct purchasers. The incident is isolated to CryptoBilis buyers in Southeast Asia.
What should I do if I bought a Ledger from any third-party reseller?
For CryptoBilis specifically: do not initialize the device if you haven't already. If already initialized, move your assets to a fresh Ledger with a newly generated seed phrase. The broader principle applies everywhere: never accept a device that arrives with a pre-configured seed phrase, and when possible buy direct from the manufacturer.
How did attackers drain wallets if Ledger's own hardware and systems weren't breached?
That is still unknown. The leading theories are that CryptoBilis devices were pre-loaded with a known seed phrase before reaching buyers, or that a phishing campaign targeted CryptoBilis customers using data obtained through or about the reseller. Ledger's investigation is ongoing. No root cause has been confirmed.



