Ledger Says Southeast Asia Reseller Linked to $86 Million Drain

Oct 10, 2026 16:18 Written by Newisty Editorial Team ledger hack asia hardware wallet
Ledger Says Southeast Asia Reseller Linked to $86 Million Drain

Ledger ties reseller CryptoBilis to massive wallet drain

Ledger has linked a Southeast Asia reseller called CryptoBilis to an ongoing hack that has drained over $80 million from hardware wallets. The devices were sold through this reseller, which claims to be the authorized Ledger partner in Malaysia.

Crypto analysts Specter and Tanuki42 first noticed reports of affected users and traced the stolen funds. They estimated losses between $72 million and more than $86 million.

What Ledger told customers

Ledger confirmed it was investigating the issue and said CryptoBilis has been ordered to pause all sales and shipments of its devices. Users who bought wallets from CryptoBilis in the past 90 days were told not to set them up. Those who already set up their devices were advised to move their assets to a new Ledger hardware wallet right away.

"We will continue to inform customers of updates as the investigation progresses," Ledger said in a statement on X.

About CryptoBilis

CryptoBilis is a hardware wallet seller based in Southeast Asia. Its website lists Ledger, Trezor, OneKey, Tangem, and SafePal among the brands it sells. It claims to be the authorized Ledger reseller for Malaysia. Protos reached out to CryptoBilis for comment but had not received a response at time of publication.

Broader tampering concerns

Former Mt Gox CEO Mark Karpelès pointed out that Ledger wallets sold through resellers have previously been found tampered with and implanted with spyware designed to steal passkeys — the secret words used to recover a crypto wallet.

Security experts warn against panic

Security researcher Taylor Monahan warned that reports of the drain are causing unnecessary fear. She said the situation does not appear to involve a zero-day vulnerability, which is a previously unknown software flaw. Instead, she highlighted the risk of phishing attempts, fake Google ads, and fraudulent apps targeting worried users who want to move their funds quickly.

Key numbers

  • Over $80 million reportedly drained
  • Loss estimates range from $72 million to over $86 million
  • Users affected by purchases in the past 90 days

What is confirmed

Ledger is investigating and has ordered CryptoBilis to pause sales and shipments. Analysts traced stolen funds to devices sold through CryptoBilis. Loss estimates sit between $72 million and over $86 million.

What is still unclear

It remains unclear how many wallets were tampered with or exactly how the spyware was installed. CryptoBilis has not responded to requests for comment.

Why this matters for wallet buyers

The incident highlights the risks of buying hardware wallets from unauthorized resellers. Ledger devices sold through unofficial channels may be tampered with before reaching the buyer. Anyone who purchased from CryptoBilis recently should follow Ledger's guidance and consider moving funds to a newly purchased wallet from an authorized seller.

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!