Market tone: Bearish
John Chen · Crypto Briefing · 2026-10-09T14:16:29.000Z
Ledger has halted sales through a Southeast Asian authorized reseller as on-chain analysts track more than $86 million in drained funds
Hardware wallets are sold on one big promise: your keys stay offline, so your coins stay yours. Ledger is now telling some of its customers not to even switch their devices on.
On October 9, 2026, Ledger Support said it was investigating significant fund losses reported by users who bought devices from CryptoBilis, an authorized Ledger reseller in Southeast Asia.
What Ledger is telling users
As a precaution, Ledger instructed CryptoBilis to stop all sales and shipments while the investigation runs.
Ledger’s guidance splits buyers into two camps. Anyone who got a device from CryptoBilis in the past 90 days and hasn’t set it up yet should leave it uninitialized.
Anyone who already set one up is being encouraged to move their assets to a new Ledger device, initialized with a fresh seed phrase. A seed phrase is the master backup, the list of words that can rebuild your wallet anywhere. If that list was compromised before it ever reached you, a new device with new words is the only clean slate.
The size of the problem came into focus through independent on-chain sleuths rather than an official tally. Analysts including Specter and tanuki42 found that over $86 million had been drained from affected Ledger wallets.
Those losses were concentrated across three networks: Bitcoin (BTC), Ethereum (ETH), and TRON. According to the analysts’ tracking, the figure is still climbing.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
We respect your privacy. Unsubscribe anytime.
What nobody has nailed down yet is how it happened. Discussion has split among several theories: tampered devices, phishing attacks, or some other vulnerability entirely.
Ledger hasn’t put out a comprehensive public statement beyond its alerts about CryptoBilis. So the company has identified a reseller worth pausing, but it has not publicly explained the mechanism behind the drains.
The gap matters. A phishing campaign means users were tricked into handing over access. A tampered device means the hardware itself was the trap, and that is a far more serious problem for a company whose entire pitch is hardware you can trust.
Why the supply chain is the soft spot
Hardware wallets protect against remote attackers by keeping private keys off internet-connected computers. That model works well, right up until someone gets physical access to the device before the owner does.
Ledger runs a Genuine Check system meant to verify that a device is authentic. The CryptoBilis episode is raising concerns about the limits of that check, specifically whether it can detect every kind of physical modification.
There has been no confirmation of a broader firmware or hardware breach affecting all Ledger devices. For now, the confirmed scope is the CryptoBilis channel and buyers from the past 90 days.
What this means for hardware wallet users
The most unsettling detail isn’t the dollar figure. It’s the sales channel. Security advice has long warned people away from sketchy marketplaces and secondhand devices, and an authorized reseller was supposed to be the safe answer.
For users, the immediate checklist is short. Figure out where and when you bought your device. If it came from CryptoBilis within the past 90 days, follow Ledger’s instructions: don’t initialize it, or move funds to a new device with a new seed phrase if you already did.
The next things to watch are clear enough. Does the drained total keep rising? Does Ledger publish a detailed root-cause account? And do any similar reports surface tied to other resellers or regions?
Originally published by Crypto Briefing.