MCAP $2.79T ▼ 2.63% 24H VOL $44.2B BTC.D 59.7% FEAR & GREED 61 Greed BTC FEE 1 sat/vB BTC $82,976 ▲ 0.16% ETH $2,500 ▲ 0.17% USDT $0.9991 ▼ 0.01% BNB $746.93 ▼ 0.36% XRP $1.39 ▼ 1.08% USDC $0.9996 ▼ 0.01% SOL $109.35 ▼ 0.58% TRX $0.3302 ▼ 0.20% FIGR_HELOC $1.07 ZEC $1,236 ▲ 0.97%

Technology

Ledger Investigates $92.9 Million Wallet Drain Tied to Reseller CryptoBilis

Ledger confirmed an unauthorized implant in one customer device as investigators trace about $92.9 million in reported losses tied to a reseller.

CoinDesk AI Desk
· 4 min read
✓ 2 SOURCES CHECKED
Ledger Investigates $92.9 Million Wallet Drain Tied to Reseller CryptoBilis
Image: U.Today

Key takeaways

  1. Loss figures vary. Bitquery reported about $92.9 million across 311 addresses, Yfarmx $93.4 million across 471 addresses, and Specter more than $86 million.
  2. Tampering confirmed once. Ledger confirmed that one affected customer's hardware wallet contained an unauthorized implant, its first confirmed physical tampering case.
  3. Funds held up. Tether froze approximately $10 million in USDT across 20 wallets, while about 14,810 ETH stayed in suspected attacker wallets.

What happened

Ledger is investigating reported losses among customers in Southeast Asia who bought hardware wallets from CryptoBilis, a reseller serving Indonesia, Malaysia and the Philippines. The incident came to light on Friday, Oct. 9, as blockchain researchers followed funds from suspected victim wallets. Early estimates put losses above $72 million. Bitquery's analysis later put the total at $92.9 million across 311 wallets on Bitcoin, Ethereum, TRON, BNB Chain and Polygon.

Bitquery found small test transactions over about two weeks before the main outflows, then coordinated transfers across several networks. Researchers also saw groups of wallets signing similar requests within seconds of each other. Ledger asked CryptoBilis to suspend all sales and shipments during its investigation, and the reseller has stopped selling hardware wallets until the probe ends.

On Saturday, Oct. 10, Ledger confirmed that a hardware wallet belonging to one affected customer contained an unauthorized implant. The finding was the company's first confirmation of physical tampering with an affected device. Some users on X asked whether Ledger will refund victims. The company has not announced any compensation.

Why it matters

The gap between a wallet drain and a confirmed breach of Ledger's own systems matters for hardware wallet owners. Ledger devices keep private keys offline, but a modified device or a compromised supply chain can undermine that protection. Ledger said the attack method remains unconfirmed and that available evidence does not establish a breach of its core infrastructure.

Recovery is uncertain. Tether reportedly froze approximately $10 million in USDT across 20 wallets, which blocks those addresses from moving the funds but does not return them to victims. Approximately 14,810 ETH remained in a group of suspected attacker-controlled wallets at the analysis cutoff. Investigators have not set a final count of affected wallets, and Ledger has not confirmed any loss figures.

Supply chain tampering is not the only risk. A researcher warned that a fake Ledger site and app appeared near the top of Google results and asked visitors for their 24-word recovery phrases. Reports said the site showed more than 1 million visits over 30 days, though Zscaler found that claim appeared to refer to google.com, not the phishing page.

What the data shows

Loss estimates differ by researcher. Bitquery reported about $92.9 million across 311 addresses, Yfarmx put suspected losses at $93.4 million across 471 addresses, and Specter said losses topped $86 million. Investigator tanuki42 identified more than $72 million sent to addresses believed tied to the thefts. Ledger has not confirmed these numbers.

Tether reportedly froze approximately $10 million in USDT across 20 wallets, while approximately 14,810 ETH remained in a group of suspected attacker-controlled wallets at the analysis cutoff.

What is still unclear

  • The precise attack method remains unconfirmed, and investigators have not shown that every affected wallet held similar parts.
  • Investigators have not set a final count of affected wallets.
  • The phishing site's visit figure has not been confirmed, and no victim count or amount stolen has been established for it.

Questions readers ask

Was Ledger hacked?

Ledger has said the precise attack method remains unconfirmed and that available evidence does not establish that its core infrastructure was breached. The reported cases center on devices bought from reseller CryptoBilis.

How much was stolen?

Estimates differ. Bitquery reported about $92.9 million across 311 addresses, Yfarmx $93.4 million across 471 addresses, Specter above $86 million, and tanuki42 more than $72 million. Ledger has not confirmed any of these numbers.

What should affected users do?

Ledger advised customers who bought from the reseller in the previous 90 days not to proceed with setup on uninitialized devices, and said those who had already configured devices should consider moving assets to a new Ledger signer with a new seed.

Will Ledger refund victims?

Ledger has not announced any compensation. Some users on X asked whether Ledger will refund victims.

Sources · 2 publishers

  1. U.Today TIER 2 FIRST REPORT
    Ledger's $93 Million Exploit: Here's What Really Happened
  2. CoinCentral TIER 3
    Ledger Confirms Hidden Implant in Hardware Wallet as $93 Million Theft Probe Grows