Blockchain AcademicsBlockchain Academics
Ledger Probes $86 Million Theft Tied to Malaysian Reseller CryptoBilis

Ledger Probes $86 Million Theft Tied to Malaysian Reseller CryptoBilis

Ledger is investigating reports of approximately $86 million in suspected cryptocurrency thefts linked to CryptoBilis, an authorized reseller based in Malaysia. The company has asked the reseller to pause sales and advised recent buyers not to set up their devices.

Hadi GhadbanEdited by Wael RajabOctober 9, 20263 min read
Share

$86 million in suspected stolen cryptocurrency has been traced to devices sold by CryptoBilis, a Ledger-authorized reseller based in Malaysia, in what may be the largest supply chain compromise ever recorded in the hardware wallet industry.

Ledger confirmed this week that it is actively investigating the reports. The company has asked CryptoBilis to pause all sales immediately and issued a public advisory urging anyone who recently purchased a device through that reseller not to set up or use their hardware wallet. On-chain investigators tracking the suspected theft have logged more than $86 million in funds linked to affected devices, though the final figure could rise as the investigation continues.

The central question is how the devices were compromised. Hardware wallet tampering at the reseller level, sometimes called a supply chain attack, involves intercepting devices after they leave the manufacturer and before they reach end users. An attacker with physical access to inventory can replace firmware, clone seed phrases during setup, or insert malicious hardware components. If that occurred, victims may have believed their funds were secured in cold storage, a term for cryptocurrency held offline on a physical device, while a compromised device silently exposed their private keys from the moment of setup. Ledger has not publicly confirmed the exact attack vector, and the investigation is ongoing.

The scale separates this incident from prior hardware wallet security events. The 2020 Ledger data breach exposed the names, email addresses, and phone numbers of roughly 270,000 customers, causing significant reputational damage but resulting in no direct fund theft. Earlier Trezor vulnerabilities in 2018 required physical access to individual devices and affected users one at a time. An $86 million loss attributed to a single authorized reseller suggests either a systematic tampering operation or a compromise of the reseller's inventory management affecting a large volume of units simultaneously.

"Ledger asked reseller CryptoBilis to pause sales and urged recent buyers not to set up their devices, as an onchain investigator tracked more than $86 million in suspected thefts."

The investigation raises questions about how Ledger vets and monitors its authorized reseller network. Ledger sells through a global network of third-party retailers, a standard distribution model for consumer hardware. That model creates security gaps between the factory and the customer that are difficult to audit at scale. Ledger's own guidance has long advised customers to purchase devices directly from its official website to reduce supply chain risk, a recommendation that will almost certainly receive renewed emphasis following this incident.

For affected users, the immediate priority is clear: do not initialize any recently purchased CryptoBilis device, and do not transfer funds onto it. Users who have already set up such a device and hold funds on it should consider those funds at risk and consult Ledger's official support channels for guidance on safe migration to a verified device. Moving funds requires access to the original seed phrase, a 12 or 24-word recovery phrase generated at setup, which is the master key to any wallet. If the device was tampered with before that seed phrase was generated, the attacker may already hold a copy.

The broader cold storage security model is not invalidated by this incident, but the episode is a pointed reminder that hardware security is only as strong as the custody chain behind it. Purchasing from unverified secondary markets or unauthorized resellers has always carried risk. The CryptoBilis case suggests that even authorized resellers can represent a meaningful attack surface when physical inventory controls are insufficient. Until Ledger completes its investigation and discloses findings, the full scope of losses and the precise mechanism of compromise remain open questions.

Discussion

Loading comments...