Ledger Confirms Tampered Hardware in CryptoBilis Case Amid Reports of $86M in Crypto Losses

Ledger found an unauthorized hardware implant in one device linked to the CryptoBilis investigation.

Market tone: Bullish

Brenda Mary · Blockonomi · 2026-10-11T22:08:29.000Z

TLDR:

Ledger found an unauthorized hardware implant in one device linked to the CryptoBilis investigation.

Blockchain investigators estimate crypto losses above $86 million, but Ledger has not confirmed the total.

Bitquery estimates $93.2 million was taken from 315 wallets across five blockchain networks.

CryptoBilis halted wallet sales as Ledger reviews reseller controls and strengthens hardware security measures.

Ledger has confirmed an unauthorized hardware implant in a device linked to the CryptoBilis incident, as blockchain investigators estimate cryptocurrency losses exceeding $86 million.

The October 9 incident involved devices sold through CryptoBilis, a reseller operating in Indonesia, Malaysia and the Philippines. Ledger’s October 11 update identified the reseller as the source of all confirmed cases while investigations continued.

72 hour update on reseller CryptoBilis incident

As the investigation continues, we are working with relevant authorities. The volume of impacted devices is limited. We know this is concerning, especially for those directly affected, and we are reaching out to impacted users.…

— Ledger (@Ledger) October 11, 2026

The company said its internal systems and direct sales channels remain unaffected. However, the discovery of tampered hardware has introduced a physical security concern alongside the reported thefts, with investigators still working to establish the full extent of the incident.

The number of affected devices remains undisclosed, and the manufacturer has not confirmed the total financial losses. Meanwhile, CryptoBilis has stopped selling hardware wallets as the investigation proceeds with relevant authorities.

Blockchain Analysis Estimates $93.2M Taken From 315 Wallets

Blockchain intelligence firm Bitquery estimated that approximately $93.2 million was taken from 315 wallets across Bitcoin, Ethereum, TRON, BNB Chain and Polygon. Its analysis also found that some stolen funds moved through additional addresses after the initial thefts.

The estimate exceeds separate reports placing the suspected losses above $86 million. However, neither figure represents an official loss assessment from Ledger, which has not confirmed the total amount stolen.

Reports of missing cryptocurrency emerged on October 9, when users linked disappearing funds to wallets associated with devices purchased through CryptoBilis. Investigators subsequently identified an unauthorized hardware component inside one affected device.

Hardware wallets typically isolate private keys from internet-connected devices to reduce exposure to online attacks. However, physical modifications can undermine those protections if malicious components compromise sensitive information.

Investigators have not publicly established how the affected devices were compromised or whether the hardware implant caused every reported loss. Therefore, the connection between the discovered component and the broader thefts remains under investigation.

Ledger Issues Security Guidance and Reviews Reseller Controls

Ledger has advised customers who purchased devices through CryptoBilis to take precautions based on their devices’ initialization status. Besides, buyers who have not initialized their devices should not set them up.

On the other hand, customers who have already initialized their wallets should transfer their assets to a new Ledger device using a newly generated recovery phrase. The company has also directed affected users to its official support website for assistance.

The incident has prompted a review of authorized reseller controls, hardware protections and distribution procedures. Ledger has also warned distributors against restocking returned devices, which could introduce modified products into the supply chain.

Customers have therefore been urged to avoid unauthorized sellers as hardware wallets could be counterfeit, modified or outside manufacturer security guidelines. The company also warned about follow-up scams targeting people affected by the incident.

Ledger said it will never call customers, send direct messages or request their 24-word recovery phrases. Users should therefore avoid sharing recovery information with anyone claiming to provide technical support. The investigation remains ongoing, with the number of affected customers, the confirmed financial impact and the precise compromise method still unresolved.

The post Ledger Confirms Tampered Hardware in CryptoBilis Case Amid Reports of $86M in Crypto Losses appeared first on Blockonomi.

Originally published by Blockonomi.