Ledger confirms draining cases linked to CryptoBilis-sold devices

An unauthorized hardware implant in a reseller-sold Ledger device is tied to estimated losses of $72 million to $93.2 million across hundreds of wallets

Market tone: Bullish

John Chen · Crypto Briefing · 2026-10-11T17:21:41.000Z

An unauthorized hardware implant in a reseller-sold Ledger device is tied to estimated losses of $72 million to $93.2 million across hundreds of wallets

The whole point of a hardware wallet is that your keys never touch anything you don’t control. On October 10, 2026, Ledger confirmed that, for some buyers of a Southeast Asian reseller, that promise was quietly broken before the box was opened.

Ledger said at least one of its devices sold by reseller CryptoBilis contained an unauthorized hardware implant that gave attackers access to users’ recovery phrases. Estimates put the damage at between $72 million and $93.2 million, drained from 311 to 315 wallets across multiple blockchains.

What Ledger found and who got hit

The affected devices were purchased from CryptoBilis within the last three months. According to the research findings, this is the first confirmed case of a physical implant in a Ledger device linked to a reseller.

Most of the losses landed in one place. Roughly $70 million of the stolen funds were in USDT on the Tron blockchain.

The rest was spread around. Losses were also reported on Bitcoin, Ethereum, BNB Chain, Polygon, and Solana, which suggests the attackers simply swept whatever the compromised seed phrases unlocked.

Ledger stressed that its own systems and direct sales channels were not affected. The company also used the moment to remind resellers that returned products should never be restocked.

Ledger’s guidance to CryptoBilis buyers is blunt. Customers should not initialize devices they haven’t used yet, and they should not move assets without first generating a new seed phrase.

The news moving money, markets, and the world—before your day starts.

Daily. Free. Join 34,000+ readers across crypto, finance, and policy.

We respect your privacy. Unsubscribe anytime.

CryptoBilis has ceased operations pending an investigation. The reseller may also have changed ownership, a detail that will likely matter a great deal as investigators try to establish when and how the tampered units entered its stock.

Tether, meanwhile, froze approximately $10 million tied to the incident. Given that the bulk of the losses were in USDT, the issuer’s ability to blacklist addresses gave victims at least a partial backstop.

That backstop has limits. Against estimated losses in the tens of millions, approximately $10 million frozen covers only a fraction, and assets drained on chains like Bitcoin don’t come with a central party that can hit pause.

Why the supply chain is the soft spot

CryptoBilis operated as an authorized reseller selling sealed and authentic devices across Indonesia, Malaysia, and the Philippines. Every additional pair of hands is another point where a box can be opened, modified, and resealed. The CryptoBilis case turns that theoretical risk into a confirmed one.

What this means for buyers and the industry

For anyone holding a device bought through a reseller, the practical takeaway is to verify where it came from. Buyers of CryptoBilis units in particular should follow Ledger’s instructions and treat existing seed phrases as exposed.

Ledger’s position is that its core products and services remain uncompromised, and the facts so far support a distinction between its own channels and a single rogue distributor.

Key things to watch include the outcome of the CryptoBilis investigation, any clarification on the possible ownership change, and whether the confirmed wallet count or loss estimates move further. Additional freezes by Tether, or tracing of funds on other chains, would also shape how much victims ultimately recover.

Originally published by Crypto Briefing.