Crypto hardware wallet maker Ledger said Friday it is investigating reports of missing funds from customers who purchased devices through CryptoBilis, a reseller in Southeast Asia, after a pseudonymous blockchain investigator estimated that more than $86 million may have been stolen from hundreds of wallets.
The company said it asked CryptoBilis to pause all sales and shipments while the investigation continues, and advised customers who bought devices from the reseller within the past 90 days not to begin setting them up. Customers who have already activated wallets purchased through the reseller should consider moving their assets to a new Ledger device with a newly generated recovery phrase, the company said.
None of the core numbers are confirmed. The $86 million figure comes from investigator Specter, who said they traced suspected theft addresses across Bitcoin, Ethereum and Tron after seeing reports from Ledger users on X and Reddit. There has been no independent confirmation of the amount affected, the number of victims, whether the reported thefts are connected, or what caused the losses.
What Ledger Has and Hasn't Confirmed
Ledger's statement, reported by CoinDesk and corroborated by Cryptopolitan and cryptonews.net, acknowledges the reports of missing funds and identifies CryptoBilis as the common sales channel. It does not confirm the loss amount, name a cause, or state how many users are affected.
Notably, there is no confirmed evidence that Ledger's own systems or wallet technology were compromised. The investigation concerns devices sold through a third-party reseller — a distribution channel the company had authorized.
The Tampering Hypothesis
One possible explanation, discussed by CoinDesk, is a supply-chain attack in which devices are tampered with before reaching customers — for example, supplied with a recovery phrase the attacker already knows, allowing funds to be drained once the wallet is funded and the owner stops watching.
That scenario is distinct from a breach of Ledger's manufacturing or software. It also matches a known fraud pattern in the region: reseller-shipped devices accompanied by pre-printed "setup" cards, when Ledger's genuine devices always generate their recovery phrase on-device. But no confirmation exists that tampering or pre-generated phrases caused the reported losses, and Ledger has not endorsed any specific explanation.
Scale Context
Ledger, founded in 2014 and based in Paris, says it has sold more than 7 million devices worldwide. A compromised reseller channel affecting even a small fraction of buyers would rank among the largest user-level losses of the year — a year in which the Bitget exchange breach alone exceeded $350 million in September and the Liquid Network incident affected roughly $320 million.
For now, the incident sits in the verified-middle: the reseller halt and Ledger's guidance are confirmed company actions; the $86 million remains a single investigator's on-chain estimate. Buyers of Ledger devices from non-official channels in recent months should check the source of their device and treat any pre-supplied recovery phrase as disqualifying.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.