Ledger Probes Reseller Supply Chain as Analysts Track $86 Million in Suspected Drains

Friday, 09/10/2026 | 16:39 GMT by Tanya Chepkova
  • Ledger froze distribution via CryptoBilis, advising recent buyers to replace both their signer and seed phrase.
  • Widely circulated loss estimates of $86M stem from preliminary third-party wallet tracking.
Ledger

Ledger has halted hardware wallet sales through Southeast Asian distributor CryptoBilis and advised anyone who purchased a device from CryptoBilis in the past 90 days not to begin setup.

All active users should immediately sweep their balances to newly generated seed phrases.

The world’s largest hardware wallet manufacturer is investigating a reported wallet drain that could lead to crypto losses above $86 million.

This hardware wallet stores private keys once it has been securely initialised, but a device or recovery phrase compromised anywhere in the supply chain could give another party access, no matter how carefully the buyer later stores the wallet.

Where the $86 Million Estimate Came From

Ledger has not disclosed how many customers are affected or confirmed the value of the reported losses. The widely cited figure of more than $86 million comes from pseudonymous on-chain investigator Specter, who published addresses associated with reported wallet drains across Bitcoin, Ethereum and Tron.

However, the researcher later admitted that the actual victim count had not yet been established. The available information also does not prove that every transaction included in the estimate involved a CryptoBilis customer.

The Attack Vector Remains Unknown

Ledger has confirmed only that it is investigating reports from Southeast Asian users who purchased products through CryptoBilis. It has not identified the countries involved, named individual victims or linked the incident to a vulnerability affecting Ledger devices generally.

It is not known whether customers received altered or counterfeit hardware, used recovery phrases that had already been exposed, or lost their assets through another route such as phishing or malicious transaction approval.

Until the mechanism is established, the incident cannot be described as a confirmed hardware-wallet exploit or supply-chain attack.

However, Ledger’s instruction to replace both the signer and seed phrase places the distribution channel at the centre of the investigation, and shows why the seller and chain of custody matter as much as the device’s security after setup.

The reports emerged less than three weeks after Bitget confirmed a $387.5 million breach affecting part of its hot- and warm-wallet infrastructure.

The two incidents involve different custody models: Bitget controlled the compromised wallets, while Ledger users hold their own keys. In the Ledger case, the unresolved question is whether that control was compromised before buyers received or initialized their devices.

Ledger has halted hardware wallet sales through Southeast Asian distributor CryptoBilis and advised anyone who purchased a device from CryptoBilis in the past 90 days not to begin setup.

All active users should immediately sweep their balances to newly generated seed phrases.

The world’s largest hardware wallet manufacturer is investigating a reported wallet drain that could lead to crypto losses above $86 million.

This hardware wallet stores private keys once it has been securely initialised, but a device or recovery phrase compromised anywhere in the supply chain could give another party access, no matter how carefully the buyer later stores the wallet.

Where the $86 Million Estimate Came From

Ledger has not disclosed how many customers are affected or confirmed the value of the reported losses. The widely cited figure of more than $86 million comes from pseudonymous on-chain investigator Specter, who published addresses associated with reported wallet drains across Bitcoin, Ethereum and Tron.

However, the researcher later admitted that the actual victim count had not yet been established. The available information also does not prove that every transaction included in the estimate involved a CryptoBilis customer.

The Attack Vector Remains Unknown

Ledger has confirmed only that it is investigating reports from Southeast Asian users who purchased products through CryptoBilis. It has not identified the countries involved, named individual victims or linked the incident to a vulnerability affecting Ledger devices generally.

It is not known whether customers received altered or counterfeit hardware, used recovery phrases that had already been exposed, or lost their assets through another route such as phishing or malicious transaction approval.

Until the mechanism is established, the incident cannot be described as a confirmed hardware-wallet exploit or supply-chain attack.

However, Ledger’s instruction to replace both the signer and seed phrase places the distribution channel at the centre of the investigation, and shows why the seller and chain of custody matter as much as the device’s security after setup.

The reports emerged less than three weeks after Bitget confirmed a $387.5 million breach affecting part of its hot- and warm-wallet infrastructure.

The two incidents involve different custody models: Bitget controlled the compromised wallets, while Ledger users hold their own keys. In the Ledger case, the unresolved question is whether that control was compromised before buyers received or initialized their devices.

About the Author: Tanya Chepkova
Tanya Chepkova
  • 535 Articles
  • 3 Followers
About the Author: Tanya Chepkova
Tanya Chepkova is a News Editor at Finance Magnates with more than 16 years of experience in financial journalism, covering forex, crypto, and digital asset markets. Her work spans daily industry reporting and data-driven, long-form explainers focused on market structure, trading models, and regulatory shifts. Before joining Finance Magnates, she led the editorial team of a cryptocurrency-focused media outlet for six years. Her reporting combines analytical depth with clear storytelling, with particular attention to how structural changes in trading, stablecoin infrastructure, and emerging products such as prediction markets reshape the broader financial ecosystem. She covers global developments and provides additional insight into CIS markets. Areas of Coverage: Crypto and digital asset markets Prediction markets Stablecoins and cross-border payments Industry analysis and long-form explainers
  • 535 Articles
  • 3 Followers

More from the Author

CryptoCurrency

!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|} !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}