Community Trust ScoreVerified
Ledger cuts ties with CryptoBilis. The Paris-based hardware wallet manufacturer has instructed this Kuala Lumpur-based reseller to cease all sales and shipments of Ledger devices, following reports from Southeast Asian customers of massive fund losses.
Why It Matters
The halting of sales by Ledger, a leading hardware wallet manufacturer, underscores the ongoing vulnerabilities within the cryptocurrency ecosystem, particularly in the resale market. This incident not only raises concerns about the security measures employed by resellers but also highlights the potential impact on consumer trust in hardware solutions, which are often viewed as a safeguard against theft. As investigations unfold, the implications for regulatory scrutiny and market confidence in hardware wallets could be significant, shaping future security protocols and consumer behavior in the crypto space.
The investigation is underway. Ledger has not released an official figure, but a blockchain investigator operating under the pseudonym Specter posted on X that addresses linked to the theft have been traced — with the total exceeding $86 million. A painful amount. Ledger clarified that its infrastructure, internal systems, and cloud services were not affected. The incident seems to be concentrated on products sold through CryptoBilis, not those purchased directly from the company. However, the investigation remains open, and the exact details of the breach are still unclear.
CryptoBilis, when contacted, did not respond.
What Ledger Tells Affected Users
Ledger’s message is straightforward: if you’ve set up a device bought from CryptoBilis, move your assets now. The official recommendation is to transfer all funds to a new Ledger device, with a fresh recovery phrase generated on a device of known origin. No half-measures, no waiting.
This is where it becomes concerning for affected users. In such incidents, the compromise often occurs upstream — even before the device reaches the buyer’s hands. A device modified or preconfigured with a recovery phrase already known to the attacker can seem to function normally for weeks or even months. The user sends funds, believes they are in control, and one day the wallet is emptied. It happens quickly. Too quickly.
Ledger is following official updates on its channels. Users in Southeast Asia who purchased through CryptoBilis are advised not to configure anything new with these devices.
An Industry Under Pressure for Months
This incident does not occur in a vacuum. The hardware wallet industry has been taking hit after hit for several months.
In July, Coldcard — manufactured by Canadian company Coinkite — was at the center of an attack linked to a firmware bug. Hackers managed to steal nearly $120 million in bitcoin by exploiting this flaw, which allowed them to guess users’ recovery phrases. It’s the kind of vulnerability that sends chills down the spine: the hardware may appear intact, but the problem is invisible.
Trezor, another heavyweight in the sector, reported a data leak affecting nearly 81,000 customers. The cause? A compromise at its third-party logistics partner. Not a direct hack of the devices, but a breach in the supply chain — exactly the type of attack vector seen in the CryptoBilis incident.
And Ledger itself is not immune to such issues. Criminals have previously managed to extract customer data via Global-e, the payment processor used by the company, to launch targeted phishing campaigns. Names, addresses, phone numbers — all exploited to convince users to give up their recovery phrases. A low-tech but alarmingly effective type of attack.
In essence, attackers are no longer necessarily trying to break the hardware. They’re targeting the weak links around it: resellers, logistics partners, payment processors. This changes the nature of the risk.
No response from CryptoBilis yet. The Kuala Lumpur reseller remains silent as pressure mounts. Their lack of communication leaves users in total uncertainty — and likely panicked for those with funds on these devices.
Ledger continues its investigation. Users who purchased directly from ledger.com or through official resellers other than CryptoBilis have no reason to panic for now, according to the company. But the list of authorized resellers is probably worth checking — especially for those who bought in Southeast Asia in recent months.
Specter, the blockchain investigator, has traced the addresses. $86 million, that’s the figure circulating.
Frequently Asked Questions
How much money was lost in the CryptoBilis incident?
The blockchain investigator Specter posted on X that addresses linked to the theft total more than $86 million. Ledger has not confirmed an official figure.
What should I do if I bought a Ledger from CryptoBilis?
Ledger recommends not configuring the device and immediately transferring assets to a new Ledger device with a new recovery phrase generated on a device of secure origin.
Are Ledger devices purchased directly from ledger.com affected?
No. Ledger states that the incident appears limited to products sold through CryptoBilis, and that its infrastructure and internal systems have not been compromised.





