Community Trust ScoreVerified
A crypto trader is out $6.6 million. Eighty Bitcoin, gone in a single transaction, just 10 days after the coins landed in a brand-new Ledger hardware wallet bought from a Southeast Asian reseller called CryptoBilis.
Why It Matters
This incident highlights the ongoing vulnerabilities in the crypto ecosystem, particularly concerning hardware wallets, which are often considered a secure option for storing digital assets. The rapid loss of such a significant amount of Bitcoin raises concerns about the safety of third-party resellers and the potential risks associated with hardware wallet purchases. As the market matures, incidents like this could impact trader confidence and prompt further scrutiny of security practices within the cryptocurrency space.
The theft hit at 05:54 UTC on October 9. Blockchain tracker Lookonchain pieced together the timeline: the trader had been accumulating those 80 Bitcoin over roughly four months, paying around $65,000 per coin — a total outlay of about $5.2 million. By September 29, all 80 coins were sitting safely in the wallet. Or so it seemed. With Bitcoin trading above $83,000 at the moment of the theft, the trader was sitting on an unrealized gain of around $1.38 million before everything vanished. Ten days. That’s all it took.
How Big Is the Damage, Really?
The $6.6 million figure for this one trader is jarring enough. But the broader picture is worse — a lot worse. Blockchain analytics firm Arkham put total losses from the incident above $80 million. Security tracking service MistTrack went further, saying losses could hit $90 million across all affected users. MistTrack said it’s been in direct contact with multiple victims, which pretty much confirms this isn’t a single isolated case. There’s a pattern here, and it’s ugly.
Blockchain analysts found at least six other large transfers in the same block as the trader’s lost coins. Six. That kind of clustering doesn’t happen by accident. It points to something coordinated — a deliberate effort targeting multiple wallets at once, not a random opportunistic grab.
And then there’s Tether. The stablecoin issuer froze USDT tied to addresses connected to the theft. Tether has the technical ability to blacklist specific token holdings, preventing any movement, and it used that power here. It’s a significant response, and it probably saved some funds from moving further down the chain.
Ledger’s Response and What’s Still Unknown
Ledger moved fast after the news broke. The company told CryptoBilis to suspend sales immediately and warned customers who recently bought devices not to set them up — not until the investigation wraps. That’s a pretty serious advisory. You don’t tell people to stop using your product unless you’re genuinely worried something is wrong.
What Ledger hasn’t done is confirm whether the devices themselves were compromised. That’s the central question nobody can answer yet. Was the hardware tampered with before it shipped? Was there something wrong in the supply chain between manufacturer and reseller? Or is the vulnerability somewhere else entirely? Unclear. The specific mechanism behind the transfer remains murky, and Ledger hasn’t said anything definitive about tampering.
The halt on sales through CryptoBilis and the setup warnings are cautious moves, but they don’t tell us what actually happened. And that gap — between what Ledger has done and what Ledger has confirmed — is where a lot of anxiety is sitting right now for anyone who bought a device recently.
MistTrack’s tracking is ongoing. The firm says the loss total keeps climbing toward $90 million as more affected users come forward. That number may not be final.
Hardware Wallets Have Had a Rough Year
It’s worth stepping back for a second. Hardware wallets are supposed to be the safe option — the way serious crypto holders protect large positions from exchange hacks, phishing attacks, and online vulnerabilities. The whole pitch is that your private keys never touch the internet. Cold storage. Secure by design.
But 2025 has been rough for that reputation. Back in August, a firmware flaw in Coldcard’s hardware wallet led to roughly $70 million worth of Bitcoin being stolen. That was a different product, a different vulnerability, a different company — but the same category. And now this.
Two major hardware wallet incidents in the same year, both involving Bitcoin losses in the tens of millions. That’s not a coincidence people in the crypto community are going to brush off easily. Trust in cold storage devices is taking real hits, and the questions being asked now — about supply chains, about firmware integrity, about reseller vetting — are legitimate ones that manufacturers haven’t fully answered.
Ledger said it will keep updating users as the investigation moves forward. That’s the standard line, and it’s probably genuine. But the crypto community has been burned before by slow disclosures and incomplete post-mortems. People want specifics: what went wrong, when it went wrong, and whether anyone who bought a Ledger device through a third-party reseller should be worried.
No answers yet. What’s confirmed: 80 Bitcoin moved out at 05:54 UTC on October 9, CryptoBilis has been told to stop selling, and Tether froze USDT at addresses tied to the theft. MistTrack puts the wider damage near $90 million.
Frequently Asked Questions
How much did the trader lose and how long had the Bitcoin been in the wallet?
The trader lost 80 Bitcoin worth approximately $6.6 million. The coins had been in the new Ledger hardware wallet for just 10 days before the theft occurred on October 9.
What is the total estimated loss across all victims of this incident?
Arkham put total losses above $80 million, while MistTrack said the figure could reach $90 million as more affected users have come forward seeking assistance.





