Ledger Asks CryptoBilis to Pause Sales After Reports of $72M-$90M in Wallet Losses
Ledger has asked Southeast Asian reseller CryptoBilis to pause Ledger-device sales and shipments while it investigates suspected supply-chain tampering. On-chain estimates put losses at more than $72 million to nearly $90 million, but Ledger has not confirmed a total or established the cause.
- Ledger’s request to CryptoBilis does not confirm that the reseller has complied.
- Ledger advised customers who bought through the channel in the past 90 days to take precautions.
- Arkham-tracked wallets attributed to the suspected theft held about $70.6 million. That balance is not a verified recovery estimate.
The suspected issue is counterfeit or altered devices reaching customers through a reseller, not a confirmed flaw in Ledger’s software. That distinction matters, but the cause is still under investigation. Available information does not establish how any devices may have been tampered with.
What Ledger Advised CryptoBilis Customers
Ledger asked CryptoBilis to pause all sales and shipments of its devices while the investigation continues. CryptoBilis says it is Ledger’s authorized reseller in Malaysia and sells devices in Indonesia, Malaysia and the Philippines. It had not responded to a request for comment at the time of reporting.
Ledger advised customers who bought from CryptoBilis in the past 90 days not to set up unused devices. Customers already using a device were advised to move their assets to a new Ledger device with a new seed phrase.
If you follow that advice, make sure the new wallet has a genuinely fresh recovery phrase. Initialize a trusted replacement device as new, generate its phrase on the device, then transfer funds to addresses controlled by that wallet. Restoring the old phrase on the replacement would keep the same wallet access, rather than create a new one. Follow Ledger’s verified instructions.
A seed phrase is a set of words that can restore access to a crypto wallet. Never type it into a website, computer or phone app, and never give it to anyone in a support chat. Anyone asking for it wants control of your wallet, no matter how official the request looks.
Security researcher Taylor Monahan said the incident did not involve a Ledger zero-day, or previously unknown software vulnerability, and warned that hurried transfers could expose users to phishing. That assessment does not establish the cause or rule out every possible software issue. Verify instructions through Ledger’s official channels, and be wary of unsolicited messages offering help.
Why the Loss Estimates Differ
Ledger has not confirmed a loss figure. The estimates come from on-chain analysis, in which researchers examine public blockchain transactions and infer which addresses may be connected to the suspected theft. Those connections are analytical judgments, not a confirmed count of victims. Different methods can produce different totals.
- Analyst Specter said they traced ten collection addresses and counted inflows from hundreds of wallets they identified as victims across Ethereum, TRON and Bitcoin. Specter estimated losses above $86 million, with the tally still rising.
- Analyst tanuki42 estimated losses above $72 million.
- MistTrack estimated losses at almost $90 million.
These estimates are not a final accounting. Available information does not explain all the differences in methodology, and Ledger has not verified the figures.
Binance founder Changpeng Zhao said the information available to him pointed to a supply-chain attack at a single vendor, with a small number of people likely having bought fake or tampered devices. That is an assessment, not a confirmed finding from Ledger’s investigation. The number of affected customers and devices, and where or how any tampering occurred, remain unknown.
Where the Traced Funds Went
On-chain tracking indicated that about 430 ETH, worth roughly $1.07 million at the reported valuation, passed through Tornado Cash, a service used to obscure the movement or origin of cryptocurrency.
Arkham-tracked wallets linked to the suspected theft reportedly held about $70.6 million. That figure is the balance attributed to those wallets, not a confirmed measure of recoverable funds or total losses.
Tether froze USDT on addresses tied to the thefts. The suspected attacker then began swapping USDT into USDD, a Tron-based stablecoin. Tether can freeze the tokens it issues, but it cannot unilaterally freeze a token issued by another party. The reported swap does not establish what controls may apply to USDD itself.
Key Questions and Answers
-
Is there evidence of a Ledger software zero-day?
Monahan said the incident did not involve one. The cause remains unconfirmed, and suspected supply-chain tampering has not been confirmed.
-
How much was reportedly lost?
Analysts estimated losses of more than $72 million to almost $90 million. Ledger has not confirmed a total.
-
What should recent CryptoBilis buyers do?
Ledger advised buyers from the past 90 days not to set up unused devices. Users already using a device were advised to move their assets to a new device with a fresh seed phrase. Follow verified instructions, and never enter the phrase on a computer or phone.
-
How many customers or devices were affected?
That has not been established. Reported wallet counts are based on analysts’ on-chain identifications, not a confirmed number of customers.
The investigation still needs to determine how many devices were involved, how they may have been altered, and which of the competing loss estimates best reflects the funds taken.