Ledger probes fund losses tied to Southeast Asian reseller CryptoBilis, asks it to pause sales

Ledger is investigating fund losses among customers of Southeast Asian reseller CryptoBilis and asked it to pause sales and shipments.
Buyers from the past 90 days should not set up their devices; existing users should consider moving assets to a new device with a new seed.
Onchain investigators put suspected losses at $72 million to $86 million; Ledger has not confirmed the size or cause.
Hardware wallet maker Ledger is investigating reports that users who bought its devices from a reseller in Southeast Asia have lost funds. In a post on X late on Oct. 9 KST, Ledger's support account said it had asked the reseller, CryptoBilis, to pause all sales and shipments of Ledger devices. CryptoBilis is listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines.
What CryptoBilis buyers should do
Ledger advised anyone who bought a device from the reseller in the last 90 days not to start setup if they have not done so yet. Those who have already set up a device should consider moving their assets to a new Ledger signer with a newly generated recovery phrase (seed). The company said questions should go only through its official support channel at support.ledger.com.
Ledger says its own systems were not breached
Ledger has not disclosed how many customers were affected, how much was lost or what caused the funds to leave the wallets. It also has not confirmed whether any devices were tampered with. In a statement to Cointelegraph, Ledger said the incident appeared to be isolated to the reseller and the affected market, and that it had received no reports involving devices bought directly from the company.
"Ledger's infrastructure, systems and services were not compromised."
Ledger (statement to Cointelegraph)
Hardware wallets keep private keys on a device that stays offline. Decrypt noted, however, that a device compromised before it reaches the buyer, such as one shipped with a recovery phrase an attacker already knows, can leave funds exposed. Binance co-founder Changpeng Zhao (CZ) also suggested on X that counterfeit or tampered devices may have been used in a supply-chain attack.
Onchain trackers put losses at $72 million to $86 million
Estimates of the damage have come from analysts tracing blockchain records. Onchain researcher tanuki42 identified eight wallet addresses linked to the thefts and put losses at more than $72 million. Specter said they traced theft addresses flagged in victim reports on X and Reddit and found inflows from hundreds of victim wallets, putting total losses across the Bitcoin, Ethereum and Tron networks above $86 million. Arkham data shared by Specter showed about $42 million in ether (ETH), $17.6 million in bitcoin and $16.5 million in tether (USDT) at those addresses.
Ledger has confirmed neither estimate, and it is not yet clear whether every theft is linked to CryptoBilis. tanuki42 told Cointelegraph: "Not with certainty, but I'm not aware of a victim report which does not involve this reseller," adding that there were too many reports for it to be a coincidence. Security Alliance (SEAL) urged anyone whose funds were moved to the identified addresses to contact its incident-response team.
Stolen ether heads to Tornado Cash
The funds have started to move. According to onchain analytics account Onchain Lens, a wallet suspected in the thefts sent 430.2 ETH (about $1.07 million) on Oct. 9 to Tornado Cash, a mixer that obscures the trail of funds, through four wallets. About $270,000 in USDT and TRX went to Binance. Onchain Lens said that after Tether froze some of the USDT, the attacker swapped the remaining USDT into USDD, a Tron-based stablecoin. Zhao wrote: "I expect and know all BNB ecosystem players (and all industry) to help trace and recover the funds."
This is not Ledger's first security incident. On Dec. 14, 2023, a former employee fell victim to phishing, giving an attacker access to a software package registry account and allowing malicious versions 1.1.5 through 1.1.7 of Ledger Connect Kit to be published. Ledger said the malicious file was live for around five hours, and that the window in which funds were drained lasted less than two hours. That incident came through the software distribution chain; this time, a sales channel is under investigation. Ledger said it would keep customers informed as the investigation progresses.