Ledger is looking into claims that over USD 86 million in cryptocurrency may have been drained from the wallets of buyers who acquired their hardware devices via a Southeast Asian vendor. On October 9, 2026, the company confirmed it was examining the reports and requested that the seller, CryptoBilis, halt all ongoing sales and deliveries during the inquiry.
Blockchain investigators uncovered the suspected thefts by following unusual activity across several blockchain networks, such as Bitcoin, Ethereum, and TRON. Even so, the USD 86 million figure is still unverified, and analysts have yet to determine if the cases are linked or stemmed from altered hardware.
Ledger Issues Warning to Recent Buyers
As a precaution, Ledger recommended that anyone who bought a device from CryptoBilis within the last 90 days hold off on setting it up if they haven’t already. For those who have already activated their devices, the company suggested moving their digital assets to a brand-new Ledger unit set up with a fresh recovery phrase. Ledger stated that additional updates will be shared as the inquiry moves forward.
CryptoBilis is recognized as an authorized Ledger distributor across Indonesia, Malaysia, and the Philippines. The probe centers specifically on complaints from customers who used this merchant, rather than a verified flaw impacting the entire Ledger product lineup.
Blockchain Investigators Trace Suspected Losses
Blockchain analyst Specter calculated that upwards of USD 86 million in crypto has been tied to suspected theft wallets. Previously, another analyst, tanuki42, put the figure at over USD 72 million.
These numbers lack independent verification, and it is uncertain whether the different totals reflect the exact same transactions. The total count of impacted wallets is likewise unknown.
Posts on social media indicate that funds vanished even though users insisted their recovery phrases were kept safe. While these stories have sparked debate over how unauthorized access occurred, they do not prove what caused the losses.
Also Read: X Sues Crypto Influencers Over Alleged GBP 207K Creator Payout Fraud
Supply-Chain Attack Remains a Possibility
Investigators are considering a supply-chain attack as a potential scenario, where hardware is modified or swapped prior to delivery. If a device is compromised in this manner and the seed phrase is already known to a malicious actor, user funds could be exposed.
Binance co-founder Changpeng Zhao noted that current data points to an issue with a single distributor tied to potentially fraudulent or modified hardware. Still, this is merely an assessment rather than an official conclusion. Ledger has not confirmed whether the incidents stemmed from physical tampering, compromised seed phrases, phishing tactics, or some other vector.




