Ledger Probes CryptoBilis Wallet Drains as Estimated Losses Reach $92.9 Million

Coinmama



Ledger is investigating a major cluster of wallet drains affecting customers in Southeast Asia who purchased hardware wallets from reseller CryptoBilis, with the latest onchain estimate placing suspected losses at $92.9 million.

The company asked CryptoBilis to stop all Ledger sales and shipments on October 9 while the investigation continues. Anyone who purchased a device from the reseller during the previous 90 days and has not initialized it should not begin setup. Customers already using one of the devices were advised to consider moving their assets to a new Ledger signer generated with an entirely new recovery seed.

Ledger later said the reports identified so far were limited to devices distributed through CryptoBilis and that it had no indication its security infrastructure, systems or services had been compromised.

The company has not confirmed the amount stolen, the number of victims or the mechanism used to gain access to their wallets.

Onchain Estimate Reaches $92.9 Million

Suspected losses have expanded beyond the initial estimates of $72 million to $86 million as investigators identified additional affected addresses and networks.

A detailed Bitquery reconstruction of the drain identified $92.9 million taken from 311 wallets across Tron, Bitcoin, Ethereum, BNB Chain and Polygon.

The largest losses were concentrated on Tron, where approximately $70.5 million was removed. Bitcoin wallets lost about 203.8 BTC worth $16.8 million, while Ethereum, BNB Chain and Polygon accounted for the remaining funds.

The transaction timing points to centralized control over the affected private keys. Twenty-five Tron wallets authorized the same spender within three seconds, and 111 Bitcoin wallets were emptied within a single block. Bitquery also traced 41 small test transactions across Tron and Ethereum during the two weeks preceding the main drain.

That pattern does not establish how the private keys were obtained, but it differs from individual victims independently approving malicious transactions over an extended period.

Tether subsequently froze approximately $10 million in USDT across 20 addresses connected to the activity. Another 15.1 million USDD remained in attacker-controlled wallets, while 1,254 ETH was sent through Tornado Cash later on October 9. Roughly $79 million remained traceable at the latest analysis.

Physical Implant Raises Supply Chain Questions

A possible hardware-based attack route is also under examination.

Former Mt. Gox CEO Mark Karpelès opened a Ledger device obtained from Malaysia and reported finding a concealed electronic implant positioned where screen padding would normally sit.

Karpelès said the modified device retained convincing packaging and that the implant was difficult to spot even after the case was opened. His analysis indicated the additional hardware could monitor information displayed during setup and transmit recovery phrase data externally.

No public evidence has yet established that the device inspected by Karpelès came from CryptoBilis or that the same modification caused the $92.9 million drain. Ledger has also not confirmed a supply-chain attack.

The technique resembles risks exposed earlier this year when a counterfeit Ledger containing hidden hardware was found capable of targeting recovery phrases and PIN information.

The current case is also distinct from the Coldcard wallet drains earlier in 2026, where investigators traced the losses to weak seed generation in affected firmware rather than reseller-level hardware modification.

Ledger’s warning currently applies specifically to customers who purchased devices from CryptoBilis within the last 90 days. Users who already initialized one of those devices need a new signer and newly generated seed, rather than simply moving the existing recovery phrase onto another hardware wallet.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*