Ledger investigates losses tied to Southeast Asia reseller CryptoBilis
Ledger asked reseller CryptoBilis to pause sales while researchers estimate $72 million to $86 million in suspected thefts.
Key takeaways
- Sales are paused. Ledger asked CryptoBilis to pause sales and shipments of its devices as a precaution.
- Estimates differ. Researchers cite more than $72 million and over $86 million in suspected losses, and Ledger has confirmed neither figure.
- The 90-day window. Customers who bought devices from CryptoBilis in the past 90 days were advised not to set them up.
What happened
Ledger said it is investigating reports of cryptocurrency losses involving devices bought from a Southeast Asian reseller. CryptoBilis is listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines.
Ledger asked CryptoBilis to suspend sales and shipments of its devices as a precaution. Customers who bought devices from the reseller within the past 90 days were advised not to set them up. Those who already had were advised to consider transferring their assets to a new Ledger signer with a newly generated recovery phrase.
Ledger told Cointelegraph that the incident appeared to be isolated to the reseller and the affected market, and that it had received no reports involving devices bought directly from the company.
Why it matters
The advice covers wallets bought through a reseller rather than directly from Ledger, so buyers in the region have to decide whether to move funds to newly generated wallets.
Security Alliance amplified tanuki42's findings on X and urged anyone whose funds were transferred to the identified addresses to contact its incident-response team.
Ledger said its infrastructure, systems and services were not compromised, and it says its investigation is ongoing.
What the data shows
Loss estimates from researchers differ. Researcher tanuki42 identified eight wallet addresses allegedly linked to more than $72 million in losses. Investigator Specter estimated losses exceeding $86 million across Bitcoin, Ethereum and Tron.
Protos reported that Ledger users in Southeast Asia who bought their wallets from CryptoBilis had been drained of over $80 million in an ongoing hack.
Background
CryptoBilis describes itself as a crypto wallet hardware seller and a trusted Web3 brand in Southeast Asia, selling Ledger, Trezor, OneKey, Tangem and SafePal wallets, among other brands. It also claims to be the authorized reseller of Ledger products in Malaysia.
Former Mt Gox CEO Mark Karpelès said that Ledger wallets sold through resellers have been found tampered with and carrying spyware meant to steal passkeys.
Security researcher Taylor Monahan pointed to phishing attempts, fake Google ads and phony apps that could drain users who rush to migrate funds.
What is still unclear
- Ledger has not said how many customers may be affected or the value of the reported losses.
- Ledger has also not identified the cause of the incidents, nor confirmed whether the devices were compromised.
- Ledger has not confirmed either loss estimate, and how far the case connects to the CryptoBilis investigation is unclear.
Questions readers ask
Which Ledger reseller is under investigation?
CryptoBilis, which is listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines. Ledger asked it to suspend sales and shipments of its devices as a precaution.
How much crypto was lost?
Ledger has not disclosed a figure. Researcher tanuki42 linked eight addresses to more than $72 million in losses, while investigator Specter estimated losses exceeding $86 million. Protos reported over $80 million, and Ledger has not confirmed these estimates.
Were Ledger's own systems compromised?
Ledger said its infrastructure, systems and services were not compromised. It also said the incident appeared to be isolated to the reseller and the affected market.
What should buyers from CryptoBilis do?
Customers who bought devices within the past 90 days were advised not to set them up. Those who already set them up were advised to consider moving assets to a new Ledger signer with a newly generated recovery phrase.