Ledger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller

Ledger asked reseller CryptoBilis to pause sales and urged recent buyers not to set up their devices, as an onchain investigator tracked more than $86 million in suspected thefts.

By Decrypt Agent

3 min read

Ledger is telling some customers to hold off on setting up their hardware wallets.

The Paris-based wallet maker said Friday it is investigating reports that users in Southeast Asia who bought devices from a reseller called CryptoBilis have lost funds.

Myriad: Where does Ethereum go next? Click to make your prediction.

“As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices,” the company’s support account wrote on X.

Ledger urged anyone who bought from the reseller in the past 90 days not to set up their device if they haven’t already. Those who have should consider moving their assets to a new Ledger signer with a new seed phrase, the master backup that can regenerate a wallet’s private keys.

Ledger didn’t say what caused the losses or how many customers were affected. Hardware wallets are designed to keep private keys offline, but a device compromised before it reaches the buyer, such as one shipped with a recovery phrase an attacker already knows, can leave funds exposed. No tampering has been confirmed.

The losses may be large, potentially in the tens of millions of dollars. Pseudonymous crypto investigator Specter said they traced theft addresses flagged in reports from Ledger users on X and Reddit and found inflows from hundreds of victim wallets across Ethereum, Tron, and Bitcoin.

“Total losses $86M+,” Specter wrote. Arkham data shared by the investigator shows nearly $87 million at those addresses, including about $42 million in ETH, $17.6 million in BTC and $16.5 million in USDT. Ledger hasn’t confirmed the figure, and it’s unclear whether every theft is linked to the reseller.

Rival Trezor has faced its own security headaches, including customer data exposed in a shipping partner breach and a breach of its email just last month.

The episode adds to a brutal stretch for crypto security. Last month, Bitget lost roughly $387 million in a hack that investigators have tied to North Korea, and blockchain tracking firms Chainalysis and Elliptic have since traced part of the haul.

North Korean hackers also spent six months infiltrating Solana exchange Drift before a $285 million exploit, and Drift has since laid out a plan to repay users. In September, self-described white hat hackers withdrew $320 million in Bitcoin from Blockstream’s Liquid sidechain before negotiating with the company.

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News