Ledger Investigates Reported $86 Million Crypto Theft Linked to CryptoBilis Wallet Sales
Ledger is investigating reports that more than $86 million in cryptocurrency was stolen from users who purchased hardware wallets through CryptoBilis, a reseller operating in Southeast Asia. The reported incidents have raised concerns about a possible supply chain attack, although the method used to compromise the wallets and the total confirmed losses remain unknown.
In a support announcement, Ledger advised customers who bought devices from CryptoBilis within the previous 90 days not to activate wallets that had not yet been configured. Customers who had already initialized their devices were advised to consider moving their cryptocurrency to new Ledger signers using different recovery phrases. The company directed affected users to its official support channels for further assistance.
Blockchain Analysis Identifies More Than $86 Million in Suspicious Transfers
Blockchain investigators have traced suspicious transactions involving multiple addresses across Bitcoin, Ethereum, and TRON. In an analysis published on October 9, blockchain investigator Specter reported that 10 suspicious addresses had received more than $86 million in cryptocurrency across the three networks.
Specter's latest assessment found that approximately $25 million remained in the identified addresses, suggesting that substantial amounts had moved elsewhere. The figure represents the balance observed during the assessment rather than the total amount originally received by the addresses.
Another investigator, tanuki42, had previously identified eight suspicious addresses and estimated losses exceeding $72 million. Specter's subsequent analysis incorporated those eight addresses and added two more Bitcoin addresses, expanding the set of addresses associated with the suspected thefts.
Security Alliance also urged affected cryptocurrency holders to contact its SEAL 911 service for help tracing stolen assets and reporting suspicious transactions. The investigation into the movement of funds remains ongoing.
Mark Karpelès Examines Possible Hardware Tampering
The reported thefts have prompted questions about whether the incidents involved physical modifications to hardware wallets before they reached customers. Mark Karpelès, the former CEO of Mt. Gox, said he was investigating the possibility that attackers had installed malicious components inside Ledger devices before distribution.
Karpelès requested photographs of the internal circuit boards of affected devices to examine whether unauthorized components had been added alongside legitimate hardware. His inquiry also raised questions about the limits of Ledger's Genuine Check feature, which uses the company's security architecture to verify device authenticity.
Ledger's documentation acknowledges that its verification process cannot detect certain unauthorized physical modifications if the original Secure Element remains intact. However, Karpelès has not confirmed that malicious implants were present in any affected devices. A hardware-based supply chain attack therefore remains a possibility rather than an established explanation for the reported losses.
Changpeng Zhao Warns About Supply Chain Risks
Binance founder Changpeng Zhao also commented on the reported thefts, pointing to a possible supply chain attack involving compromised devices distributed through a single reseller. His preliminary assessment suggested that counterfeit or physically altered hardware wallets could be involved.
Zhao acknowledged Ledger's established security record while emphasizing that hardware wallets may still face risks during distribution. He advised cryptocurrency holders to exercise caution when purchasing devices and avoid transferring substantial funds immediately after receiving a new wallet.
He also expressed confidence that participants across the blockchain industry would help investigators trace the stolen cryptocurrency and support potential recovery efforts.
Ledger Users Face Uncertainty as Investigation Continues
The precise attack method has not been established. Possible explanations raised in connection with the incidents include compromised hardware, malicious applications, and phishing attacks. The available findings do not establish which, if any, of these methods caused the reported losses.
Users can reduce exposure to common wallet-security risks by obtaining software from verified sources, protecting recovery phrases from disclosure, and carefully checking transaction details before approving transfers. Recovery phrases should never be entered into websites, applications, or devices that request them without a legitimate and verified security reason.
Researchers are continuing to monitor suspicious cryptocurrency addresses for additional movements potentially connected to the reported thefts. One address was reportedly holding 211 BTC, although that balance alone does not establish the amount recoverable or confirm the funds' connection to every reported incident.
The estimate of more than $86 million in losses remains based on independently reported blockchain analysis and has not been officially confirmed by Ledger as a final loss figure. The number of affected customers, the total verified financial impact, and the precise mechanism behind the suspected thefts remain undetermined as the company's investigation continues.
Writer: Marcus RenfieldCrypto Market Analyst & Onchain WriterMarcus Renfield covers cryptocurrency markets with a focus on onchain data, Bitcoin price action, and emerging market narratives. His writing examines how capital flows, network activity, and broader market structure influence short- and medium-term trends.He aims to provide clear, data-informed analysis for readers seeking a deeper understanding of crypto market dynamics.




