Ledger Says Southeast Asia Reseller Linked to $86 Million Drain
Ledger ties reseller CryptoBilis to massive wallet drain
Ledger has linked a Southeast Asia reseller called CryptoBilis to an ongoing hack that has drained over $80 million from hardware wallets. The devices were sold through this reseller, which claims to be the authorized Ledger partner in Malaysia.
Crypto analysts Specter and Tanuki42 first noticed reports of affected users and traced the stolen funds. They estimated losses between $72 million and more than $86 million.
What Ledger told customers
Ledger confirmed it was investigating the issue and said CryptoBilis has been ordered to pause all sales and shipments of its devices. Users who bought wallets from CryptoBilis in the past 90 days were told not to set them up. Those who already set up their devices were advised to move their assets to a new Ledger hardware wallet right away.
"We will continue to inform customers of updates as the investigation progresses," Ledger said in a statement on X.
About CryptoBilis
CryptoBilis is a hardware wallet seller based in Southeast Asia. Its website lists Ledger, Trezor, OneKey, Tangem, and SafePal among the brands it sells. It claims to be the authorized Ledger reseller for Malaysia. Protos reached out to CryptoBilis for comment but had not received a response at time of publication.
Broader tampering concerns
Former Mt Gox CEO Mark Karpelès pointed out that Ledger wallets sold through resellers have previously been found tampered with and implanted with spyware designed to steal passkeys — the secret words used to recover a crypto wallet.
Security experts warn against panic
Security researcher Taylor Monahan warned that reports of the drain are causing unnecessary fear. She said the situation does not appear to involve a zero-day vulnerability, which is a previously unknown software flaw. Instead, she highlighted the risk of phishing attempts, fake Google ads, and fraudulent apps targeting worried users who want to move their funds quickly.
Key numbers
- Over $80 million reportedly drained
- Loss estimates range from $72 million to over $86 million
- Users affected by purchases in the past 90 days
What is confirmed
Ledger is investigating and has ordered CryptoBilis to pause sales and shipments. Analysts traced stolen funds to devices sold through CryptoBilis. Loss estimates sit between $72 million and over $86 million.
What is still unclear
It remains unclear how many wallets were tampered with or exactly how the spyware was installed. CryptoBilis has not responded to requests for comment.
Why this matters for wallet buyers
The incident highlights the risks of buying hardware wallets from unauthorized resellers. Ledger devices sold through unofficial channels may be tampered with before reaching the buyer. Anyone who purchased from CryptoBilis recently should follow Ledger's guidance and consider moving funds to a newly purchased wallet from an authorized seller.