BTC$83,004.47▲ 0.27%
ETH$2,502.61▲ 0.23%
USDT$0.9990▼ 0.01%
BNB$748.57▼ 0.07%
XRP$1.39▼ 0.62%
USDC$0.9999▲ 0.01%
SOL$109.41▼ 0.36%
TRX$0.3303▼ 0.24%
HYPE$85.42▲ 1.40%
ZEC$1,231.56▲ 0.28%
DOGE$0.0853▼ 0.61%
XMR$531.26▲ 1.77%
LINK$12.96▼ 0.37%
ADA$0.2477▼ 2.81%
BTC$83,004.47▲ 0.27%
ETH$2,502.61▲ 0.23%
USDT$0.9990▼ 0.01%
BNB$748.57▼ 0.07%
XRP$1.39▼ 0.62%
USDC$0.9999▲ 0.01%
SOL$109.41▼ 0.36%
TRX$0.3303▼ 0.24%
HYPE$85.42▲ 1.40%
ZEC$1,231.56▲ 0.28%
DOGE$0.0853▼ 0.61%
XMR$531.26▲ 1.77%
LINK$12.96▼ 0.37%
ADA$0.2477▼ 2.81%
Home / Crypto News / Ledger Probes $86M Theft as CZ Flags Supply Chain Attack
A hardware crypto wallet and open packaging on a desk beside a screwdriver
Crypto News

Ledger Probes $86M Theft as CZ Flags Supply Chain Attack

Jackson Miller · ·3 min read
In this article5 sections
  1. 01Key facts
  2. 02Where the funds went and how much
  3. 03What CZ and Ledger advise
  4. 04Why it matters
  5. 05What to watch

Ledger is investigating reported fund losses among Southeast Asian customers who bought hardware wallets from reseller CryptoBilis, with analyst estimates of the total running above $86 million across Bitcoin, Ethereum and Tron, according to Cointribune. The company has not confirmed the cause or the number of devices involved.

On October 9, 2026, Ledger Support said on X that it had asked CryptoBilis to pause all sales and shipments of Ledger devices as a precaution, as Coinpedia reported. Binance founder Changpeng Zhao, writing on X the same day, said the thefts appeared localized to a supply chain attack involving a single seller and that a small number of people probably bought fake or tampered devices.

Also read: Ledger Theft Hits $91M as CryptoBilis Reseller Probed

Key facts

  • Ledger announced on October 9, 2026 that it was investigating losses among buyers from CryptoBilis, a reseller in Southeast Asia, and requested a halt to its sales and shipments.
  • Estimates of the total diverge: Specter said more than $86 million across 98 wallet addresses, MistTrack placed losses near $90 million, and Arkham valued its “ledger-drainer” entity of 152 addresses at $71.6 million.
  • According to MistTrack, Tether froze USDT on addresses linked to the thefts; separately, about $1.45 million in USDT was blocked in THORChain vaults on Tron and released roughly three hours later.
  • Coinpedia reported that a capture attached to Specter’s post showed another Arkham entity valued at about $87 million, and that security researcher tanuki42 had earlier estimated losses above $72 million and rising.
  • U.today reported that on-chain researchers tracked outflows across Bitcoin, Ethereum and Tron from wallets belonging to investors in Malaysia, Indonesia and the Philippines.

Where the funds went and how much

Arkham grouped 152 addresses under the label “ledger-drainer”, with the cluster valued at $71.6 million, and its tracing showed outflows to other addresses of between $500,000 and $4 million each. The dollar figures do not line up because the trackers cover different scopes: Specter’s count runs above $86 million, MistTrack’s sits near $90 million, and Arkham’s entity figure is $71.6 million.

Cointribune described the gap as three watches not showing the same second. Coinpedia put Specter’s number more precisely at $86.96 million across 98 addresses, while cautioning that those addresses do not necessarily represent 98 confirmed victims.

Also read: Duelbits takes casino offline after $7M hot-wallet hack

What CZ and Ledger advise

CZ recommended waiting a few weeks before placing a large sum on a new wallet. U.today reported he framed the delay as a quarantine: if a batch of devices reaches a reseller already compromised, on-chain analysts get a window to detect the first thefts and warn other buyers.

Ledger’s Genuine Check, its authenticity control, does not detect physical modification while the original chip remains intact, per Ledger’s documentation cited by Cointribune. It still works against counterfeits. Mark Karpelès, the former Mt. Gox chief executive, posted on X a Ledger he claims was modified with a hidden implant that he said could read the screen and retrieve the recovery phrase during setup; nothing establishes that the device came from CryptoBilis or explains the thefts.

Ledger asked CryptoBilis customers from the past 90 days not to initialize their devices, and said those who already did may consider moving funds to a new device with a new recovery phrase.

Why it matters

The alert is narrow — one reseller, one region — so it should not be read as proof of a Ledger-wide hardware exploit, which no source has confirmed. U.today noted that physical delivery has become a recurring weak link: hardware maker Coinkite said in August that third-party distributor systems were compromised, and Trezor acknowledged in September a data breach affecting 80,000 US customers after logistics contractor ShipMonk was hacked. Buying through local marketplaces or distributors is now widely treated as unsafe for large holders.

What to watch

As of October 10, 2026 no end date for the investigation had been announced. Further statements from Ledger and MistTrack should indicate whether the thefts involved hardware implants or another mechanism.

Reported by cointribune.com.

Sources: Cointribune, Coinpedia, U.today

Staff writer

Jackson Miller covers Bitcoin and cryptocurrency markets for CoinPulseHQ, tracking price movements and on-chain trends.