CryptoCoinArticle is online

Ledger Investigates Reported Crypto Wallet Losses Tied to Reseller

Power Trader
Ledger Investigates Reported Crypto Wallet Losses Tied to Reseller

Highlights

Ledger says it is investigating reports that customers in Southeast Asia lost cryptocurrency after purchasing hardware wallets from reseller CryptoBilis. As a precaution, it asked the reseller to pause sales and shipments. Ledger advised customers who purchased devices from the reseller in the past 90 days not to set them up; customers who already did so were told to consider transferring assets to a new signer with a fresh seed phrase. Onchain investigator Specter reported tracing more than $86 million in suspected thefts across Ethereum, Tron, and Bitcoin. Ledger has not confirmed the reported total, the cause, or whether all identified thefts are connected to the reseller.

Sentiment Analysis

  • The article has a predominantly negative tone because it focuses on reported losses, possible wallet compromise, and the risk that customers’ digital assets may be exposed.
  • Its account is also cautious rather than conclusive. Ledger describes an ongoing investigation and precautionary steps, while the reported total comes from an independent investigator and has not been confirmed by the company.
  • The advice to pause setup or move assets presents a practical response, but it underscores uncertainty for affected customers. The article does not establish how many people were affected or confirm that a device was tampered with.
  • References to other major crypto-security incidents broaden the context and reinforce a sense of persistent industry risk. Overall, the sentiment is strongly negative, tempered by clear attribution and acknowledgement of unresolved facts.
80%

Article Text

Ledger, the Paris-based maker of hardware wallets, is investigating reports that customers in Southeast Asia lost cryptocurrency after purchasing devices from a reseller identified in the article as CryptoBilis. The company said on Friday that it had asked the reseller to pause all sales and shipments of Ledger devices while its investigation continues. The report does not establish how many customers may have been affected or what caused the losses.

Ledger’s support account advised people who bought a device from CryptoBilis in the past 90 days not to set it up if they had not already done so. Customers who had set up a device were advised to consider transferring their assets to a new Ledger signer and using a new seed phrase. A seed phrase is a master backup used to regenerate the private keys associated with a wallet. The guidance was presented as a precaution while the company examines the reports, rather than as confirmation that the devices were compromised.

Hardware wallets are designed to keep private keys offline. However, a device could leave funds vulnerable if it were compromised before reaching its buyer—for example, if it arrived with a recovery phrase already known to an attacker. The article states that no tampering has been confirmed. It also does not describe a verified attack method or establish a direct connection between the reseller and every reported loss.

Pseudonymous onchain investigator Specter said they traced addresses associated with suspected thefts after seeing reports from Ledger users on X and Reddit. Specter reported finding incoming transfers from hundreds of victim wallets across Ethereum, Tron, and Bitcoin. The investigator described the total losses as $86M+. Data from Arkham shared by Specter showed nearly $87 million at the identified addresses, including about $42 million in ETH, $17.6 million in BTC, and $16.5 million in USDT.

The reported dollar total remains an investigator’s estimate; Ledger has not confirmed it, and the available information does not show whether every theft is linked to CryptoBilis. The distinction matters because tracing funds to addresses can indicate the scale of activity under review without, by itself, proving that every transaction arose from the same incident. Ledger’s investigation is therefore central to determining the scope and circumstances of the reports.

The article places the reports within a wider run of cryptocurrency security incidents. It says rival wallet maker Trezor has dealt with customer data exposed in a shipping partner breach and a breach of its email the previous month. These examples provide industry context, but the article does not suggest that those events are connected to the Ledger investigation.

Other incidents cited include a hack in which Bitget lost roughly $387 million the previous month, which investigators have tied to North Korea. Blockchain tracking firms Chainalysis and Elliptic subsequently traced part of the funds, according to the article. It also says North Korean hackers spent six months infiltrating the Solana exchange Drift before a $285 million exploit; Drift later outlined a plan to repay users.

In another case, self-described white hat hackers withdrew $320 million in Bitcoin from Blockstream’s Liquid sidechain in September before negotiating with the company. Together, the examples illustrate the range of security challenges facing crypto businesses, from reported wallet losses and data breaches to exchange exploits and withdrawals followed by negotiations. They do not prove that the incidents share a cause or responsible parties.

For Ledger customers who purchased through the named reseller, the immediate issue is whether their device and wallet setup are safe. Ledger’s public advice focuses on avoiding setup for devices not yet used and considering a move to a new signer and fresh seed phrase for devices already set up. The company has not provided a confirmed count of affected customers, a confirmed cause, or a verified loss figure in the information described.

Key Insights Table

AspectDescription
Company responseLedger is investigating reports and asked CryptoBilis to pause sales and shipments.
Customer guidanceCustomers who bought from the reseller in the past 90 days were advised not to set up unused devices; those who had set them up were advised to consider moving assets to a new signer with a fresh seed phrase.
Reported lossesSpecter reported $86M+ in suspected losses; Arkham data showed nearly $87 million at identified addresses. Ledger has not confirmed the total.
Networks and assets citedThe suspected activity spans Ethereum, Tron, and Bitcoin. Reported holdings included about $42 million in ETH, $17.6 million in BTC, and $16.5 million in USDT.
Unresolved questionsThe cause, number of affected customers, device tampering, and connection between all traced thefts and the reseller remain unconfirmed.
Wider security contextThe article also cites incidents involving Trezor, Bitget, Drift, and Blockstream’s Liquid sidechain, without claiming they are related.

Last edited at:2026/10/9