Ledger says it is looking into reports of lost funds from Southeast Asian customers who bought through the reseller, and has confirmed neither an amount nor a cause. Two independent researchers put the losses at more than $72 million and more than $86 million, figures that may not cover the same addresses.
Ledger said on Friday that it is investigating reports of lost funds from customers in Southeast Asia who bought its hardware wallets from a reseller named CryptoBilis, and that it has asked the reseller to pause all sales and shipments of Ledger devices while the investigation continues.
The company published the statement through its support account at 13:32 UTC. It advises anyone who bought a Ledger device from the reseller in the past 90 days not to begin setting it up, and tells customers who have already set one up to consider moving their assets to a new Ledger signer with a new seed. Ledger describes the halt on sales and shipments as a precaution pending the results of its investigation, which is not the same as a finding against the reseller.
What Ledger has not said is how much was taken, or how. The statement confirms neither a loss total nor a cause, and it makes no claim about tampering, counterfeit devices or any compromise of the company's own systems.
The figure now attached to the incident comes from outside the company. The pseudonymous on-chain researcher Specter posted at 12:24 UTC that they had traced theft addresses receiving inflows from hundreds of victim wallets across Bitcoin, Ethereum and Tron, put total losses above $86 million, and listed ten addresses across the three chains. A second researcher, Tanuki42, put more than $72 million moved into a group of suspected theft addresses, according to The Block, which reported that it is unclear whether the two estimates cover the same transactions and addresses, and that Specter later said the number of affected wallets is not yet known.
The two traces differ by roughly $14 million, and neither has been independently confirmed. Both rest on identifying addresses the researchers believe received stolen funds and then totaling what flowed in, which requires a judgment about who controlled the sending wallets. Publishing the addresses, as Specter did, makes that judgment checkable by others, which is also why the total should be read as a working estimate rather than a count.
The mechanism remains unestablished. A reseller supply-chain compromise is the explanation the available facts point toward, because a device delivered with a recovery phrase the attacker already knows would let that attacker spend anything later deposited to it, without needing to defeat the device's security or reach Ledger's infrastructure. Nothing published so far confirms that this is what happened. The Block reported that Mark Karpeles, the former Mt. Gox chief executive, asked affected users to open their devices and photograph the circuit board, which would show physical tampering if it occurred, and that Binance co-founder Changpeng Zhao said the available information suggested a supply-chain attack involving one vendor.
CryptoBilis is listed as an official Ledger reseller in Indonesia, Malaysia and the Philippines, according to The Block, which reported no statement from the reseller. CoinDesk reported that Ledger, founded in 2014 and based in Paris, says it has sold more than 7 million devices.
Hardware wallet owners have been reached through third parties in the distribution and communication chain before. A breach at an email provider in September let attackers send phishing from Trezor's own domain, a campaign that reached customers through a channel they had reason to trust. A compromised reseller would exploit the same trust at an earlier point, before the customer has done anything at all.
If the larger estimate holds, the losses would sit below the $351.6 million that Bitget said its own approval process released in September, though that compares a confirmed exchange loss with an unconfirmed total spread across individual self-custody users. Those users have less to fall back on. Where recovery efforts have been organized this year, the returns have been thin: Drift's recovery pool for April's exploit pays about a cent on every dollar lost, and none of the additional funding pledged by Tether and other partners had arrived.
Ledger says it will keep customers informed as the investigation progresses. Its guidance remains the only instruction the company has issued.