Investigation into $86 Million Theft from Ledger Wallets Focuses on Reseller
Written with artificial intelligence.

Reports indicate that Ledger wallet users have experienced unauthorized fund withdrawals, totaling over $86 million. The company has identified a reseller in Southeast Asia, CryptoBillis, as a potential source and has suspended its operations pending further investigation.
Overview of the Situation
On October 8, users of Ledger wallets reported extensive unauthorized withdrawals of funds. An on-chain analyst, Specter, estimates that the total losses could exceed $86 million across cryptocurrencies such as Ethereum, Tron, and Bitcoin. Some estimates on social media suggest losses could approach $100 million. As of now, the stolen Bitcoin is reportedly held in three addresses that accumulated around 211 BTC between October 8 and 9.
Ledger's Response
In response to these incidents, Ledger has launched an investigation focusing on users in Southeast Asia who purchased devices from a reseller named CryptoBillis. Ledger has asked CryptoBillis to suspend all sales and shipments until the investigation concludes. They also issued a warning for users who bought from this reseller in the past 90 days, advising them not to set up their devices if they haven't done so yet.
Recommendations for Affected Users
Affected Ledger users are advised to:
- Do not initialize your device if purchased from CryptoBillis within the last 90 days.
- If already set up, migrate assets to a new Ledger device with a fresh seed phrase.
This highlights the importance of securing the seed phrase as the ultimate safeguard for hardware wallets.
Broader Implications
Changpeng Zhao, the CEO of Binance, supports Ledger's findings, suggesting the issue appears to be a supply chain attack linked to a single reseller. This incident raises significant concerns about the integrity of hardware wallets and the potential for counterfeit devices in the market. In September, a similar breach occurred with the D'CENT wallets, resulting in losses of $18.7 million. However, there is currently no evidence that Ledger's own devices have been compromised, and the investigation will address these critical distinctions.
