Community Trust ScoreVerified
Ledger is investigating cryptocurrency losses linked to devices sold through a Southeast Asian reseller called CryptoBilis. The company has already told CryptoBilis to stop selling and shipping its hardware wallets.
Why It Matters
The investigation into Ledger's losses associated with CryptoBilis highlights ongoing vulnerabilities in the hardware wallet market, particularly regarding third-party resellers. This situation underscores the importance of purchasing crypto hardware wallets directly from manufacturers to mitigate risks of counterfeit products, which can lead to significant financial losses for users. As the cryptocurrency ecosystem continues to evolve, such incidents can impact consumer trust and adoption rates, emphasizing the need for stringent security measures within the industry.
Customers who bought a device from CryptoBilis in the past 90 days are being told not to set it up. Anyone who already set one up should move their assets to a new wallet immediately — one with a freshly generated recovery phrase. CryptoBilis operates across Indonesia, Malaysia, and the Philippines, and it was listed as an authorized Ledger reseller in those markets. The number of affected customers hasn’t been disclosed. Neither has the total confirmed loss amount. Ledger hasn’t confirmed whether the devices were physically tampered with, whether they shipped with compromised firmware, or whether something else entirely went wrong in the supply chain. The cause is still murky.
Researchers Put Losses Between $72M and $86M
Separate from Ledger’s official probe, onchain researchers have been digging through wallet data on their own. Researcher tanuki42 flagged eight wallet addresses probably connected to more than $72 million in losses. Another investigator, Specter, put the figure higher — estimating losses could top $86 million across Bitcoin, Ethereum, and Tron. Those are big numbers. And Ledger hasn’t confirmed either estimate, so it’s unclear yet whether those wallets are actually tied to the CryptoBilis situation or represent something broader.
The crypto security organization SEAL — Security Alliance — got involved after tanuki42’s findings surfaced. SEAL shared the research and urged anyone who sent funds to those flagged addresses to contact its incident-response team directly. SEAL hasn’t put out its own loss estimate, and it hasn’t identified the exact nature of the breach either. But it’s clearly treating this seriously.
Hardware wallet security incidents don’t come along every week. When they do, they tend to shake user confidence fast — especially when the losses being floated run into the tens of millions. The reseller model, where a manufacturer relies on third-party distributors to get devices into regional markets, has always carried some risk. A device can be intercepted, repackaged, or pre-compromised before it ever reaches the end buyer. Ledger hasn’t said which of those scenarios, if any, is what happened here.
Ledger Says Its Core Systems Are Clean
Ledger’s own statement, shared with Cointelegraph, was pretty clear on one point: no reports have come in involving devices bought directly from Ledger. The company’s infrastructure, systems, and services haven’t been compromised. The problem — whatever it turns out to be — seems confined to the reseller and the affected region.
That’s somewhat reassuring, but it doesn’t answer the bigger question of how devices sold through an authorized channel ended up connected to suspected thefts of this scale. Ledger didn’t give a timeline for when the investigation might wrap up or what steps come after. No details on that yet.
The involvement of tanuki42 and Specter has been important. Onchain analysis moves faster than most corporate investigations, and in cases like this, researchers often surface the scope of a problem before the company does. The connection between those eight flagged addresses and CryptoBilis is still being worked out, though — it’s not confirmed.
For users in Indonesia, Malaysia, and the Philippines who bought a Ledger device recently, the advice is simple and urgent: don’t use it. Generate a new recovery phrase on a clean device. Move your assets. Don’t wait for Ledger to finish its investigation before acting.
SEAL’s offer to help affected users is probably worth taking seriously. Incident-response teams in the crypto security space can sometimes trace fund flows and, in rare cases, help recover assets — though recovery isn’t guaranteed and the window for it tends to close fast.
Ledger says it’s committed to transparency as the investigation moves forward. It’s also made clear that halting CryptoBilis sales was a precautionary call, not a confirmation of wrongdoing. But when you’re talking about potential losses somewhere between $72 million and $86 million, precaution is kind of the bare minimum.
The company is still gathering information. No definitive findings have been shared publicly. And the gap between what researchers think happened and what Ledger has officially confirmed remains wide.
Specter’s $86 million estimate — spread across Bitcoin, Ethereum, and Tron — is the highest figure on the table right now.
Hub: Bitcoin price, news, and analysis
Frequently Asked Questions
What should CryptoBilis customers do right now?
Ledger says anyone who bought a device from CryptoBilis in the past 90 days should not set it up, and anyone who already did should transfer their assets to a new wallet with a freshly generated recovery phrase immediately.
How much cryptocurrency may have been stolen in the CryptoBilis incident?
Researcher tanuki42 flagged over $72 million in potential losses across eight wallet addresses, while researcher Specter estimated losses could exceed $86 million across Bitcoin, Ethereum, and Tron — though Ledger has not confirmed either figure.





