Markets
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
BTC— —
ETH— —
SOL— —
XRP— —
BNB— —
ADA— —
DOGE— —
MCap— —
Tech

Ledger Asked CryptoBilis to Stop Shipping as It Investigates Drains

Ledger says it is looking into reports of lost funds from Southeast Asian customers who bought through the reseller, and has confirmed neither an amount nor a cause. Two independent researchers put the losses at more than $72 million and more than $86 million, figures that may not cover the same addresses.

By MiningPool Staff··3 min read
Ledger Asked CryptoBilis to Stop Shipping as It Investigates Drains

Key Points

  • Ledger says it is looking into reports of lost funds from Southeast Asian customers who bought through the reseller, and has confirmed neither an amount nor a cause.
  • Two independent researchers put the losses at more than $72 million and more than $86 million, figures that may not cover the same addresses.

Ledger said on Friday that it is investigating reports of lost funds from customers in Southeast Asia who bought its hardware wallets from a reseller named CryptoBilis, and that it has asked the reseller to pause all sales and shipments of Ledger devices while the investigation continues.

The company published the statement through its support account at 13:32 UTC. It advises anyone who bought a Ledger device from the reseller in the past 90 days not to begin setting it up, and tells customers who have already set one up to consider moving their assets to a new Ledger signer with a new seed. Ledger describes the halt on sales and shipments as a precaution pending the results of its investigation, which is not the same as a finding against the reseller.

What Ledger has not said is how much was taken, or how. The statement confirms neither a loss total nor a cause, and it makes no claim about tampering, counterfeit devices or any compromise of the company's own systems.

Advertisement

728×90

The figure now attached to the incident comes from outside the company. The pseudonymous on-chain researcher Specter posted at 12:24 UTC that they had traced theft addresses receiving inflows from hundreds of victim wallets across Bitcoin, Ethereum and Tron, put total losses above $86 million, and listed ten addresses across the three chains. A second researcher, Tanuki42, put more than $72 million moved into a group of suspected theft addresses, according to The Block, which reported that it is unclear whether the two estimates cover the same transactions and addresses, and that Specter later said the number of affected wallets is not yet known.

The two traces differ by roughly $14 million, and neither has been independently confirmed. Both rest on identifying addresses the researchers believe received stolen funds and then totaling what flowed in, which requires a judgment about who controlled the sending wallets. Publishing the addresses, as Specter did, makes that judgment checkable by others, which is also why the total should be read as a working estimate rather than a count.

The mechanism remains unestablished. A reseller supply-chain compromise is the explanation the available facts point toward, because a device delivered with a recovery phrase the attacker already knows would let that attacker spend anything later deposited to it, without needing to defeat the device's security or reach Ledger's infrastructure. Nothing published so far confirms that this is what happened. The Block reported that Mark Karpeles, the former Mt. Gox chief executive, asked affected users to open their devices and photograph the circuit board, which would show physical tampering if it occurred, and that Binance co-founder Changpeng Zhao said the available information suggested a supply-chain attack involving one vendor.

CryptoBilis is listed as an official Ledger reseller in Indonesia, Malaysia and the Philippines, according to The Block, which reported no statement from the reseller. CoinDesk reported that Ledger, founded in 2014 and based in Paris, says it has sold more than 7 million devices.

Hardware wallet owners have been reached through third parties in the distribution and communication chain before. A breach at an email provider in September let attackers send phishing from Trezor's own domain, a campaign that reached customers through a channel they had reason to trust. A compromised reseller would exploit the same trust at an earlier point, before the customer has done anything at all.

If the larger estimate holds, the losses would sit below the $351.6 million that Bitget said its own approval process released in September, though that compares a confirmed exchange loss with an unconfirmed total spread across individual self-custody users. Those users have less to fall back on. Where recovery efforts have been organized this year, the returns have been thin: Drift's recovery pool for April's exploit pays about a cent on every dollar lost, and none of the additional funding pledged by Tether and other partners had arrived.

Ledger says it will keep customers informed as the investigation progresses. Its guidance remains the only instruction the company has issued.

MiningPool content is intended for information and educational purposes only and does not constitute financial, investment, or legal advice.

Advertisement

728×90

Related Stories

Buterin Says AI Math Could Weaken Lattice Cryptography in Two Years
Tech

He named ML-DSA and fully homomorphic encryption as the new risk, and said Ethereum's lean roadmap has spent a year moving to hash-based schemes for that reason. His advice to holders was caution about migrating rather than haste: botched migrations have cost him more than every hack combined.

·MiningPool Staff
Cardano Put Issuer Freeze Powers Into the Ledger Without a Hard Fork
Tech

The Cardano Foundation says CIP-0113 is live on mainnet after independent audits, letting issuers of stablecoins and tokenized funds build identity checks, sanctions screening and seizure into the asset itself. The controls reach only tokens whose issuers adopt the standard, not ADA.

·MiningPool Staff
Sepolia Forked to 200 Million Gas, a Limit Validators Can Decline
Tech

Prysm shipped the Sepolia gas schedule about 16 hours before the fork; without it, validators on older builds would have kept proposing at 60 million. The 200 million figure is a target proposers signal rather than a value the protocol enforces, and it applies to Sepolia alone.

·MiningPool Staff
Buterin Expects Hegotá to Be Ethereum's Last Normal Fork
Tech

Buterin's post puts Ethereum's 2030 target at four to eight second slots and finality in eight to 32 seconds, against 12-second slots and about 13 minutes today. It also has nodes checking a proof instead of re-executing every block.

·MiningPool Staff

Stay informed

Verifiable crypto journalism, delivered to your inbox.

Weekday mornings. No hype. No financial advice. Just what happened and why it matters.

No spam. Unsubscribe anytime. Read our privacy policy.