Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen
Hardware wallet maker Ledger is investigating reports of over $86 million in crypto potentially stolen from devices sold by Southeast Asian reseller CryptoBilis, though losses remain unverified. Ledger has advised CryptoBilis to halt sales and urged recent buyers to take …
Intelligence analysis by Gemini 2.5 Flash
Ledger, a prominent hardware wallet manufacturer, is probing claims of significant cryptocurrency theft, reportedly totaling $86 million, from wallets linked to devices purchased through a third-party reseller, CryptoBilis. The company has issued warnings to customers and paused the reseller's operations while investigating a potential supply-chain attack.
Imagine you have a special piggy bank that keeps your digital money super safe, called a Ledger wallet. Now, some people are saying that money disappeared from their piggy banks, but only from ones they bought from a specific store far away. The company that makes the piggy banks is checking if someone secretly messed with them before they were sold, like putting a secret key inside so they could take money later. They're telling people who bought from that store to be careful or get a new, fresh piggy bank.
Analysis
Ledger, a leading provider of hardware wallets designed to keep cryptocurrency private keys offline, has initiated an investigation into alarming reports of substantial crypto thefts. The company is specifically looking into devices sold by CryptoBilis, a reseller operating in Southeast Asia, following social media posts detailing drained Bitcoin, Ethereum, and Tron addresses. While the reported sum of over $86 million and the direct link to CryptoBilis devices remain unverified by independent sources, the sheer scale of the alleged losses has prompted Ledger to take immediate, precautionary measures.
CryptoBilis
Ledger has formally requested that CryptoBilis cease all sales and shipments of its devices while the investigation is underway. Furthermore, Ledger has issued a strong advisory to customers who purchased devices from this reseller within the last 90 days, urging them not to proceed with setting up their new hardware wallets. For those who have already activated their devices, the company recommends transferring their assets to a new Ledger device, ensuring it is set up with a freshly generated recovery phrase. This proactive stance by Ledger underscores the seriousness with which it is treating the allegations, even in the absence of full confirmation regarding the cause or extent of the losses.
Supply-chain attack
One prominent theory being explored is a potential supply-chain attack, where hardware wallets are tampered with at some point before they reach the end-user. This could involve an attacker pre-configuring a device with a recovery phrase they already know, thereby gaining future access to any funds deposited into that wallet. Such a scenario would represent a sophisticated form of theft, distinct from a direct breach of Ledger's own internal systems or core wallet technology. Ledger has explicitly stated that there is no confirmed evidence that its own systems or wallet technology have been compromised, focusing the investigation on the integrity of the devices distributed through the reseller channel. However, the exact mechanism of the reported losses, including whether device tampering or pre-generated recovery phrases are indeed the cause, is still unconfirmed.
Bitget
The potential $86 million theft, if confirmed, would contribute to an already challenging year for crypto security. The article highlights several other major exploits that have plagued the industry recently, including a significant incident involving crypto exchange Bitget, which reportedly suffered over $350 million in stolen assets last month. Other notable incidents cited include Liquid Network at approximately $320 million, Drift at $295 million, and Kelp at $293 million, according to DefiLlama data. These figures illustrate a broader trend of vulnerabilities and sophisticated attacks targeting various facets of the cryptocurrency ecosystem, making Ledger's current investigation a critical test for the perceived security of hardware wallets amidst a landscape of escalating digital asset exploits.
Key points
- Ledger is investigating reports of over $86 million in crypto stolen from wallets linked to devices sold by CryptoBilis, a Southeast Asian reseller.
- The reported losses and the direct connection to CryptoBilis devices have not been independently verified.
- Ledger has asked CryptoBilis to halt sales and shipments and advised recent buyers not to set up their devices.
- Customers who have activated wallets from CryptoBilis are urged to transfer assets to a new Ledger device with a newly generated recovery phrase.
- A supply-chain attack, where devices are tampered with before reaching customers, is a possible explanation, but Ledger's own systems are not confirmed to be compromised.
Ledger's swift investigation and precautionary advice to customers demonstrate a commitment to security, potentially limiting further losses and identifying the root cause quickly. If the issue is isolated to a single reseller's supply chain and not a flaw in Ledger's core technology, it could reinforce trust in the broader hardware wallet ecosystem once resolved.
A confirmed supply-chain attack could severely damage user trust in hardware wallets, leading to widespread panic and withdrawals. The difficulty in identifying all affected devices and recovering stolen funds could result in significant financial losses for many users and a lasting blow to Ledger's reputation.


