Ledger CryptoBilis Reseller Supply-Chain Drain
An estimated $86 million was drained from Ledger users who bought devices from reseller CryptoBilis, in a suspected supply-chain attack that captured their seed phrases.
- Date
- Status
- Funds Stolen
On October 9, 2026, users who bought Ledger hardware wallets from the authorized reseller CryptoBilis began reporting mass thefts that on-chain investigators estimate at approximately $86 million, in a suspected supply-chain attack that appears to have captured victims' recovery phrases before they ever signed a transaction.
What happened
CryptoBilis is an authorized Ledger reseller operating in Indonesia, Malaysia, and the Philippines, and the reports clustered almost entirely among its Southeast Asian customers. Victims said their wallets were drained even though they had kept their seed phrases offline and, in some cases, had never used the device to sign anything — a pattern that points away from phishing and toward the devices themselves being compromised before purchase. Binance co-founder Changpeng Zhao characterized it as a localized supply-chain attack involving a single vendor, with a small number of buyers receiving counterfeit or physically tampered units. Former Mt. Gox chief Mark Karpelès said he examined modified Ledger devices containing a hidden hardware implant that could monitor the communications used to display recovery words, letting an attacker read a seed phrase while the genuine Secure Element stayed intact. A competing theory is that devices were pre-initialized with an attacker-known seed before reaching buyers. No root cause has been officially confirmed.
Loss estimates come from independent on-chain analysts rather than from Ledger. Sleuth tanuki42 traced more than $72 million to suspected theft addresses, Specter estimated losses exceeding $86 million spanning BTC, ETH, and TRX, and MistTrack suggested the figure could approach $90 million. Tether reportedly froze USDT held in addresses linked to the incident.
Aftermath
Ledger said it was investigating the reports and asked CryptoBilis to pause all sales and shipments of its devices. It advised anyone who bought from the reseller in the past 90 days and had not yet completed setup to stop, and told existing users to move their assets to a new Ledger signer with a freshly generated seed phrase. Ledger stated it had "no indication that Ledger's security infrastructure, systems, or services have been compromised," framing the incident as confined to products sold through the one reseller. No funds had been recovered as of this writing, and the figures remained unverified estimates while the investigation continued.
Why it matters
The incident is a reminder that self-custody only protects users if the seed phrase is generated and held secretly — a guarantee that collapses when the hardware itself is tampered with before it reaches the buyer. It echoes the Coldcard weak-entropy seed exploit, where a firmware flaw made hardware-wallet seeds brute-forceable, and the D'CENT App Wallet compromise, where attackers swept thousands of accounts using recovery phrases obtained outside the signing device. As with the Atomic Wallet mass compromise and the Slope Wallet seed leak, the attack bypassed the device's transaction-signing security entirely by going after the secret that sits beneath it — here, apparently, through the distribution channel itself.
Sources & on-chain evidence
- [01]news.bitcoin.comhttps://news.bitcoin.com/security/ledger-investigating-86m-drained-crypto-hardware-wallets/
- [02]cryptopotato.comhttps://cryptopotato.com/ledger-investigates-86m-crypto-drain-as-reseller-supply-chain-fears-grow
- [03]financemagnates.comhttps://www.financemagnates.com/cryptocurrency/ledger-probes-reseller-supply-chain-as-analysts-track-80m-in-suspected-drains/
- [04]tftc.iohttps://www.tftc.io/ledger-cryptobilis-reseller-86m-drained-funds