Ledger is investigating reports of cryptocurrency losses among customers in Southeast Asia who purchased hardware wallets through CryptoBilis, a reseller listed as an official distributor in Indonesia, Malaysia and the Philippines.
The incident came to light on Friday, Oct. 9, as blockchain researchers traced funds from suspected victims’ wallets. Initial estimates put the losses above $72 million, but subsequent analysis by Bitquery expanded the reported total to $92.9 million across 311 wallets on five networks: Bitcoin, Ethereum, TRON, BNB Chain and Polygon.
The distinction between a wallet-draining incident and a confirmed compromise of Ledger’s own systems is important. Ledger devices are designed to keep private keys offline, but maliciously modified hardware or a compromised supply chain could potentially undermine that protection.
The precise attack method remains unconfirmed, and the available evidence does not establish that Ledger’s core infrastructure was breached.
Ledger said it had asked CryptoBilis to suspend all sales and shipments while its investigation proceeds. It also issued precautionary guidance to customers who purchased devices from the reseller during the previous 90 days.
“Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis,” the company said in its statement.
Ledger advised customers who had bought devices from the reseller but had not yet initialized them not to proceed with setup. Customers who had already configured their devices were advised to consider moving their assets to a new Ledger signer with a new seed phrase.
Blockchain investigator Specter separately reported tracing suspicious addresses that received funds from hundreds of victim wallets across Ethereum, TRON and Bitcoin, estimating losses above $86 million.
Bitquery’s analysis identified small test transactions over approximately two weeks before the main outflows, followed by coordinated transfers across multiple networks.
Researchers also observed groups of wallets signing similar requests within seconds of one another. These patterns suggest preparation and a possible common point of control, but blockchain transactions alone cannot establish how the attacker gained access to the wallets.
$10 million in USDT frozen as investigators trace funds
The investigation has produced several developments in tracking the stolen assets. Tether reportedly froze approximately $10 million in USDT across 20 wallets associated with the suspected theft. The action prevents the affected USDT from being transferred through those addresses, but does not automatically return the funds to victims.
At the analysis cutoff, approximately 14,810 ETH remained in a group of suspected attacker-controlled wallets. Researchers also identified around 203.8 BTC in associated Bitcoin addresses, with those funds reportedly unmoved at that point.
Bitquery’s analysis further identified the movement of approximately 1,254 ETH through Tornado Cash and Zcash. The funds reportedly later appeared in three new wallets, including one holding about 2.1 million USDC.
The presence of USDC may provide another potential avenue for intervention, depending on the issuer’s assessment and the addresses involved, but a freeze should not be assumed unless confirmed.
Binance founder Changpeng Zhao, commonly known as CZ, said the information available at the time pointed toward a localized supply-chain incident involving one vendor.
He suggested that a small number of customers may have received counterfeit or tampered devices, while calling on industry participants to help trace and recover the assets. This remains an assessment, not a confirmed finding from Ledger’s investigation.
Former Mt. Gox CEO Mark Karpelès also shared photographs of a Ledger Nano X he said he had received from Malaysia. According to Karpelès, the device’s shrink-wrap appeared intact, but he found a concealed electronic module where the screen padding should have been.
He said hardware implants had become more sophisticated, potentially making modified components harder to distinguish from original parts.
Karpelès has requested photographs from affected users to help identify similar modifications. However, Ledger has not been shown to have confirmed that the reported module was functional or connected to the CryptoBilis incident.
The latest independent estimate places the reported losses at $92.9 million, but that figure has not been confirmed by Ledger. The cause of the incident also remains unresolved, with the available evidence pointing toward a possible supply-chain issue without conclusively proving that counterfeit or modified devices were responsible.
For now, the confirmed response includes Ledger’s investigation and reseller suspension, its precautionary guidance to customers, and the reported freeze of $10 million in USDT. Further conclusions will depend on forensic findings and continued on-chain tracing.






Be the first to comment