In this article5 sections
Ledger is investigating reported losses among customers in Southeast Asia who bought hardware wallets from a reseller called CryptoBilis, according to Ambcrypto. The wallet maker has asked the reseller to pause all sales and shipments while it works out what happened.
Loss estimates have already diverged. Onchain investigator Specter traced more than $86 million in suspected thefts, per Decrypt, while Galaxy Research put the figure at $91 million spread across nearly 500 addresses. Ledger has confirmed neither figure nor a cause.
Also read: Bitmine buys $74M in Ether as chair sees rising odds for US Clarity Act
Key facts
- Galaxy Research attributed $91 million of thefts to nearly 500 victim addresses, with Tron the hardest hit at 276 addresses and about $64.5 million.
- Bitcoin addresses lost $17.7 million across 276 addresses, and the Ethereum ecosystem $8.8 million across 55 addresses, according to Galaxy.
- Specter traced more than $86 million in suspected thefts, Decrypt reported, citing Arkham data showing about $42 million in ETH, $17.6 million in BTC and $16.5 million in USDT.
- Ledger asked CryptoBilis to pause sales and told anyone who bought from the reseller in the past 90 days not to set up their device; those who already did should move assets to a new Ledger signer with a fresh seed phrase.
- Ark Invest’s head of crypto research, Lorenzo Valente, said: “Never buy from a reseller, even if official” and warned that self-custody will die very quickly if nothing is done.
How the losses were traced
Reporting on the scope of the episode varies because neither Ledger nor an outside auditor has completed the picture. Galaxy’s head of research, Alex Thorn, treated the $91 million as a floor, since the impact on BNB Chain, Base, Avalanche and other chains had not been fully traced ahead of a full audit.
Funds have started moving. As of October 9, roughly $73 million sat in attacker-controlled wallets across Bitcoin, Ethereum and Tron, while $3 million had been routed into Tornado Cash and other relay accounts, according to Galaxy. About $13.65 million of stolen USDT was converted to USDD, and some funds reached Binance, prompting analysts to press the exchange to freeze them.
Also read: Robinhood Chain fuels Ethereum optimism; UK weighs permanent crypto donation ban
Binance founder Changpeng Zhao and current CEO Richard Teng both said they would help with recovery. Teng said the focus must be on supporting affected users, tracing funds and assisting recovery efforts, adding that security is a shared responsibility and Binance stands ready to support the industry’s collective efforts. How much is recoverable under that arrangement is unstated.
What CryptoBilis has said
Preliminary reports pointed to a supply chain operation affecting Ledger Nano X and Ledger Nano S Plus devices sold by CryptoBilis, involving spyware components that could read and transmit seed phrases. Seed phrases are the master recovery strings that regenerate a wallet’s private keys, so a device shipped with a phrase an attacker already knows would expose funds unless the wallet sits in a multi-sig setup. No tampering has been confirmed.
The response from CryptoBilis itself has been murky. Arravind Prabu defended himself by saying he is no longer part of CryptoBilis; when asked why he did not publicly disclose the sale of the reseller, he said the firm signed a non-disclosure agreement with a Chinese buyer that would expire on October 19, right after the attack.
The episode follows a $114 million Coldcard hardware exploit in the third quarter, and Decrypt noted rival Trezor has faced its own security headaches, including customer data exposed in a shipping partner breach and a breach of its email last month. Larger crypto hacks are also still being worked through: Bitget lost roughly $387 million in August, North Korean hackers spent six months inside Solana exchange Drift before a $285 million exploit, and white hat hackers withdrew $320 million in Bitcoin from Blockstream’s Liquid sidechain in September.
Why it matters
The distinction between $86 million and $91 million, and between confirmed and alleged tampering, matters for users deciding whether to keep using devices from that reseller. Hardware wallets are sold on the premise that private keys never touch the internet; a compromised device defeats that premise before the buyer ever opens the box. Ledger’s instruction to buyers is the practical consequence, and it falls on the customer, not the manufacturer, to replace the device and migrate funds.
Valente’s warning frames the larger stake: repeated hardware exploits could push users back toward custodial services, reversing the self-custody trend that hardware wallets were built to support. That is an argument, not a measured outcome.
What to watch
The next concrete data point is Ledger’s full audit, which Galaxy expects in the coming days and which could raise the loss total beyond $91 million once BNB Chain, Base and Avalanche are traced. Also unresolved: whether frozen funds on Binance are released to victims, and whether the CryptoBilis non-disclosure agreement dated October 19 reveals who now owns the reseller.
This is not financial advice. Cryptocurrency markets are volatile and uncertain, and readers should do their own research before making decisions.
Reported by ambcrypto.com.
Sources: AMBCrypto, Decrypt

