Hardware wallet manufacturer Ledger has instructed Southeast Asian reseller CryptoBilis to halt all sales and shipments of its devices following reports from on-chain researchers claiming over $86 million in user funds have been drained.
Key Takeaways
- Ledger asked Malaysian reseller CryptoBilis to suspend hardware wallet sales and shipments pending an investigation.
- Buyers who purchased devices from CryptoBilis in the last 90 days are advised not to set them up, or to transfer funds to a new seed phrase immediately.
- On-chain analyst Specter claims to have traced $86 million+ in thefts across Ethereum, TRON, and Bitcoin addresses.
- Public mempool data confirms three designated Bitcoin addresses hold roughly 211 BTC as of 13:44 UTC on Friday.
Sales Suspended Following $86 Million Theft Claims
On Friday, Ledger Support advised customers who purchased hardware wallets from CryptoBilis—a reseller founded in 2020 operating across Malaysia, Indonesia, and the Philippines—within the past 90 days to refrain from initializing their devices. Users who have already configured a wallet bought from the store were instructed to transfer their crypto to a fresh device using a newly generated 24-word seed phrase.
The directive arrived roughly an hour after on-chain investigator Specter reported tracking drained funds across hundreds of victim wallets. Specter identified inflows totaling more than $86 million spanning Ethereum, TRON, and Bitcoin. While Ledger has not formally verified the $86 million loss figure or confirmed hardware tampering, public mempool records show three Bitcoin wallets identified by Specter hold approximately 211 BTC combined, with no outgoing transfers logged as of 13:44 UTC on Friday.
This supply chain scare follows previous hardware wallet security incidents, such as when a trader lost $6.6 million in Bitcoin after buying a new Ledger wallet or reported Ledger hack losses near $90 million. Security risks with third-party vendors are not unprecedented; in April, researchers identified counterfeit Ledger units on a Chinese marketplace designed to extract PINs and seed phrases. In August, a separate firmware flaw in competitor Coldcard resulted in a $70 million loss for Bitcoin holders.
Why It Matters
Supply chain compromises represent one of the most severe vectors of attack against self-custody infrastructure. Even if core cryptographic protocols remain secure, secondary distribution networks in regional markets can bypass device integrity controls. If confirmed, hardware tampering by localized resellers highlights a critical vulnerability in global hardware wallet retail chains that requires stricter physical verification mechanisms.



