Key Insights:
- The Ledger wallet hack involves over $86 million in suspected losses affecting Southeast Asian users who bought devices from CryptoBilis.
- On-chain traces show funds drained across Bitcoin, Ethereum, and TRON, prompting Ledger to order the reseller to halt sales and shipments.
- Ledger advises customers who bought devices from CryptoBilis within the past 90 days to avoid setup or, if already initialized, move funds to a new Ledger using a fresh seed phrase.
The Ledger wallet hack probe began on October 9, 2026, following reports of more than $86 million in suspected crypto theft. Ledger has asked Southeast Asian reseller CryptoBilis to halt device sales and shipments while the investigation continues.
Blockchain investigator Specter tracked funds linked to hundreds of wallets across Bitcoin, Ethereum and TRON. Ledger has yet to independently confirm the total losses or determine how the funds were drained.
Ledger Wallet Hack Investigation Focuses on One Reseller
In a post on social media platform X, Ledger Support announced it had asked CryptoBilis to stop the sales and shipments of its devices while the company investigated the alleged loss of customer funds.
The notice notes that the advice applies to buyers of Ledger products from the reseller within the last 90 days. Customers who bought devices from CryptoBilis but have not yet initialized the devices are being urged not to do so.

Those who have already initialized devices are being asked to transfer the assets on their Ledger devices to a new Ledger device with a new recovery phrase. The notice does not establish how the alleged crypto thefts occurred, nor does it confirm that a security flaw in the devices is the cause.
Ledger security breach reports have so far pointed to a possible issue specific to one distributor. An issue limited to the supply chain would have different implications than if the reported security problem affected all Ledger devices.
What the Ledger Crypto Theft Figures Show
The blockchain investigator Specter estimated the losses to be higher than $86 million, with hundreds of wallets affected on Bitcoin, Ethereum, and TRON.
The figures are nevertheless an estimate belonging to an independent investigator. They do not constitute a figure acknowledged by Ledger or a formal accounting of customer losses.

It is not established whether the reported crypto wallet security breach was the result of compromised recovery phrases, tampered devices, malware, or other factors.
A hardware wallet keeps private keys offline, reducing exposure to online threats. However, its security also depends on the device’s integrity and how safely the recovery phrase is stored.
Until investigators identify the method of attack, it would be premature to conclude that Ledger products, in general, are compromised.
Why CryptoBilis Ledger Buyers Get a Warning?
As mentioned, Ledger’s notice does not apply to all Ledger buyers, only those who bought Ledger devices from CryptoBilis in the last 90 days. Anyone who bought a Ledger product from this Southeast Asian reseller in the last 90 days should take the measures described in the company’s notice.
Specifically, those who bought a Ledger product from CryptoBilis in the last 90 days but have not yet initialized the device must not do so until further notice. Customers who have already initialized the device in the meantime are advised to transfer the assets on their Ledger devices to a new device with a new recovery phrase.
Using a new recovery phrase is essential. Transferring funds to a new device with the same compromised phrase would leave the assets at risk. Customers should also turn to Ledger’s official support channels for further information and instructions and refrain from providing recovery phrases to unsolicited third parties.
Ledger wallet hack investigation does not provide grounds to believe that all devices crypto wallet security purchased from CryptoBilis are compromised. Rather, the notice applies to those customers who bought the company’s Ledger devices in the last 90 days from this particular reseller while the investigation is ongoing.
A Wider Problem for Crypto Security
The alleged Ledger security breach follows a wave of setbacks for the cybersecurity industry in general and the crypto industry in particular. According to an August 13 report by The Coin Republic, Trump signed an order on cybercrime as crypto theft accounted for a third of losses.
The article stated that more than $20.8 billion was lost due to cybercrime in 2025, according to the U.S. administration. In another October 2 report, Bitget CEO Gracy Chen expects limited recovery of funds after the cyberattack, in which approximately $387.5 million in assets were stolen.
Around $1.1 million had been frozen, but the frozen funds do not necessarily belong to the company and may not be returned. Crypto scams and thefts of various sizes regularly make headlines, but individual cases often involve complications in establishing the manner of the attack, tracing, and recovering funds.
On September 25, The Coin Republic reported that 3,832 NFTs were transferred from hundreds of wallets in a suspected security breach at Magic Eden. As the matter is still under investigation, the funds were secured by a white-hat participant.
The Ledger security probe must first establish how the $86 million in alleged losses occurred. Only then can investigators determine whether a device vulnerability was to blame.








