Ledger Just Told Buyers Not to Set Up the Wallet They Paid For. Analysts Say $86M Is Already Gone
You buy a hardware wallet because you don’t trust exchanges. You buy it from an official reseller because you don’t trust Amazon.
On Friday, Ledger told some of those buyers: don’t plug it in.
On-chain investigators estimate more than $86 million has already been drained from wallets tied to devices sold through one Southeast Asian shop.
What Ledger Said
On October 9, Ledger’s support account posted that it is “investigating reports of loss of funds from users in South East Asia” who bought devices from CryptoBilis, a reseller Ledger lists as official in Indonesia, Malaysia and the Philippines, according to The Block.
Ledger has asked CryptoBilis to pause all sales and shipments while it investigates. Its advice to customers:
- Bought from CryptoBilis in the last 90 days and haven’t set up yet? Ledger says “not [to] initiate set up.”
- Already set up? “Consider moving assets to a new Ledger signer (with new seed).”
Ledger says it “will continue to inform customers of updates as the investigation progresses.” It has not confirmed a loss figure, a victim count, or a cause. According to reports, it says there’s no sign its own systems or wallet software were breached. CryptoBilis has not responded publicly.
The Numbers (All Unconfirmed)
| Source | Estimate |
|---|---|
| tanuki42 (on-chain researcher) | $72M+ moved to suspected theft addresses, and rising |
| Specter (on-chain investigator) | $86M+ traced across Bitcoin, Ethereum and Tron |
| MistTrack (via BlockchainReporter) | Approaching $90M |
| Bitquery (via BlockchainReporter) | ~$92.9M from 311 wallets across five chains |
Specter first said the money came from hundreds of victim wallets, then walked that back: the number of affected wallets isn’t known yet. It’s also unclear whether these estimates cover the same addresses. Treat every number here as a moving target.
MistTrack reports that Tether has been freezing USDT at linked addresses.
For scale: per DefiLlama data cited by CoinDesk, that would still trail the year’s biggest thefts: Bitget (~$350M, which we covered), Liquid Network, Drift and Kelp. The difference is that this wasn’t a protocol or an exchange. These were people’s cold wallets.
So What Happened?
Nobody knows for sure yet. The leading theory is a supply-chain attack: a device reaches the buyer already compromised, for example tampered with or shipped with a recovery phrase the attacker already knows. CoinDesk notes there’s no confirmation that’s what happened here.
What the people watching are saying:
- Changpeng Zhao said the info so far points to a supply-chain attack at one vendor, with a small number of users likely buying fake or tampered devices. “Self-custody comes with extra responsibilities,” he added.
- Taylor Monahan, a security researcher, has pushed back on talk of a Ledger zero-day.
- Mark Karpelès, ex-Mt. Gox CEO, said the reports may tie into something he was already investigating. He asked affected users to open their devices and send him photos of the circuit board, which could show physical tampering.
If it’s confirmed as a tampered-reseller attack, that’s arguably worse for the industry than a firmware bug. You can patch a bug. You can’t patch “the store Ledger told you to trust sold you a compromised device.”
What To Do If You Bought From CryptoBilis
- Not set up yet? Don’t. Wait for Ledger’s guidance.
- Already set up? Move funds to a new signer with a brand-new seed that you generate yourself. Don’t reuse the old phrase anywhere.
- Got drained? Contact SEAL 911, which tanuki42 is pointing victims toward, and keep the device. It’s evidence.
- Bought anywhere else? Rule of thumb: if a wallet arrives with a recovery phrase already printed or filled in, it’s compromised. A real device generates the seed on first setup.
Why This Matters for Crypto Jobs
Hardware and supply-chain security are now in the job description. For years, wallet security hiring focused on firmware, secure elements and app code. This incident, whatever the root cause turns out to be, puts the distribution chain on the threat model. Expect hardware-wallet makers to hire for reseller audits, anti-tamper packaging, device attestation, and field forensics.
On-chain investigators are the first responders. The first public numbers came from pseudonymous researchers like Specter and tanuki42, and from analytics firms like MistTrack and Bitquery, not from Ledger. Tracing across BTC, ETH and Tron in real time is a skill exchanges, stablecoin issuers and security firms are paying for.
Incident response and comms at consumer crypto companies. Ledger has 7M+ devices out there. Telling customers “don’t use the product you bought” is about as hard as customer comms get. Trust & safety, support escalation and crisis comms people with crypto experience are in demand.
APAC compliance and partner management. Companies selling into Indonesia, Malaysia and the Philippines through local distributors will be re-checking those partners. That means vendor-risk and regional ops roles.
The Bottom Line
The whole pitch of a hardware wallet is that you don’t have to trust anyone. It turns out you still have to trust whoever put it in the box.
Want to work on the security side of crypto? Security engineers, on-chain investigators and incident responders are hiring right now. Browse open roles on Cryptogrind →
Discussion
Comments are powered by GitHub. Sign in with your GitHub account to chime in.