InvestReports disagree8 publishers2 min readPublished
Specter traces more than $86 million drained from hundreds of Ledger wallets
On-chain analyst Specter traced more than $86 million drained from hundreds of Ledger hardware-wallet users across Ethereum, TRON and Bitcoin. With the cause unconfirmed, holders cannot yet tell whether moving coins to a new device would help at all.
The Investor · Invest desk

What happened
- Ledger had not commented publicly or confirmed any flaw in its devices or firmware as of the report date.
- One Bitcoin address tied to the theft has received more than 211 BTC, and those coins had not moved when the report was published.
- Earlier this year a fake Ledger Live app on Apple's App Store took about $9.5 million from more than 50 users before it was caught.
- In August a reported seed-generation flaw in Coldcard hardware wallets cost users more than $88 million in Bitcoin.
Why it matters
- decision Holders have to decide whether to migrate before the cause is known, and migration only protects them if Ledger's hardware or firmware turns out to be at fault.
- constraint If seed phrases were stolen, a firmware patch protects none of the affected users, because the words rebuild the wallet on any device.
- precedent After Coldcard's device-side loss two months earlier, nobody can safely assume that a hardware-wallet drain this large was caused by user error.
The theories circulating on X and Reddit each put the fault somewhere different [3]. A hardware or firmware flaw would put it in the device itself. In that case, Crypto Briefing reported, the response could mean firmware updates or moving funds to new wallets entirely [7]. A stolen seed phrase puts the fault wherever the words were kept, because those words can recreate the wallet anywhere [3]. Phishing through fake apps or websites puts it in user habits, and the fix there is to keep the seed off any phone or computer and check every transaction before signing [6].
At more than $86 million, the Ledger drain is about nine times the loss from the fake Ledger Live app, where the average victim lost at most about $190,000 [11][12]. Add Coldcard's August loss and hardware-wallet users have reportedly lost more than $174 million in two incidents about two months apart [16]. If the estimate reaches the $100 million some reports suggest, the Ledger figure grows by $14 million, or about 16% [13][15].
How this resolves depends on what Ledger eventually names. If it names phishing or a third-party app, the drain sits alongside the App Store case, and holders who never typed their words into anything have nothing to move [6]. If it names a device or firmware flaw, Ledger joins Coldcard, and balances on affected devices stay at risk until they are patched or migrated [14][7]. Continued silence leaves holders choosing on partial information.
I think the evidence so far supports a narrower claim than a failure of cold storage. Specter's tracing shows a coordinated campaign against hundreds of wallets [5], but nothing published so far shows the attacker got in through the device [1]. The counter-case is strong. A victim list made up of one brand's customers is what a shared device flaw would produce, and Coldcard's seed-generation failure shows that such flaws can cost this much [14]. A phishing campaign aimed at Ledger owners would produce the same list.
Until a cause is named, holders bear the cost of guessing. Moving every balance to a new wallet is work spent on a fix that may turn out to be unnecessary [7], and leaving coins where they are is a bet that the device is sound. A Ledger statement confirming a hardware or firmware vulnerability would prove the narrower view wrong.
What to watch
- Ledger's first public statement, and whether it blames the device, leaked seed phrases or phishing.
- Any firmware update or migration advice from Ledger, which Crypto Briefing describes as the response a device fault would require.
- Newly identified victims pushing the loss estimate further above $86 million.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence58
Perspective Coverage
8 publishers- Builder
- Builder 31%
- Operator
- Operator 37%
- Investor
- Investor 32%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The cause has not been confirmed; Ledger has not confirmed any vulnerability related to its devices or firmware and had stayed silent publicly as of the report date.
ReportedSupportedSource: Crypto Briefing4 sources— create a free account to open themView cited source - [2]
On-chain analyst Specter flagged what appears to be a coordinated drain of funds from Ledger hardware wallet users on October 9, 2026.
ReportedSupportedSource: Crypto Briefing, citing Specter (@SpecterAnalyst)3 sources— create a free account to open themView cited source - [3]
Theories on X and Reddit include a device or firmware flaw, seed phrase compromise (the seed phrase can recreate a wallet anywhere, making the device irrelevant if attackers obtain it), and phishing via fake apps or websites that trick users into signing malicious transactions or handing over recovery words.
ReportedSupportedSource: Crypto Briefing, summarising community discussion4 sources— create a free account to open themView cited source - [4]
Cumulative losses from the Ledger user drain are estimated at over $86 million.
ReportedSupportedSource: Crypto Briefing, citing Specter3 sources— create a free account to open themView cited source - [5]
The theft spans Ethereum, TRON and Bitcoin; Specter traced several theft addresses that received inflows from hundreds of victim wallets, pointing toward a coordinated campaign.
ReportedSupportedSource: Crypto Briefing, citing Specter's analysis3 sources— create a free account to open themView cited source - [6]
If the root cause is phishing or a compromised third-party app, the fix is behavioral: verify software sources, never type a seed phrase into a computer or phone, and scrutinize every transaction before signing.
ReportedSupportedSource: Crypto Briefing4 sources— create a free account to open themView cited source - [7]
If the cause is a device or firmware problem, the response becomes more complicated, potentially involving firmware updates or migrating funds to new wallets entirely.
ReportedSupportedSource: Crypto Briefing4 sources— create a free account to open themView cited source - [8]
One Bitcoin address linked to the theft has reportedly received over 211 BTC, and as of the report those coins had not moved.
ReportedSupportedSource: Crypto Briefing2 sources— create a free account to open themView cited source - [9]
Earlier in 2026, a fake Ledger Live app on the Apple App Store drained approximately $9.5 million from more than 50 users.
ReportedSupportedSource: Crypto Briefing2 sources— create a free account to open themView cited source - [10]
A flaw in the Zilliqa Ledger app led to considerable losses for users holding ZIL.
- [11]
The reported Ledger loss of more than $86 million is about nine times the roughly $9.5 million taken by the fake Ledger Live app.
- [12]
The fake Ledger Live app's average loss per victim was at most about $190,000.
- [13]
Some reports suggest the final loss figure could approach $100 million.
ReportedContestedSource: Crypto Briefing4 sources— create a free account to open themView cited source - [14]
In August 2026, a reported seed-generation flaw in Coldcard hardware wallets resulted in losses exceeding $88 million in Bitcoin, about two months before the Ledger incident.
ReportedContestedSource: Crypto Briefing3 sources— create a free account to open themView cited source - [15]
A final figure of $100 million would be $14 million, or about 16%, above the $86 million estimate.
- [16]
The Coldcard and Ledger incidents together account for more than $174 million in reported losses about two months apart.
Sources
8 independent publishers whose own reporting we read for this story.
- coindesk.comLedger investigates potential wallet tampering after reports of $86 million in crypto stolen
1 article · October 9, 2026
- cointelegraph.comLedger investigates fund losses linked to Southeast Asian reseller, warns users
1 article · October 9, 2026
- crowdfundinsider.comLedger Hack: Reports Indicate Hardware Wallets Being Drained of Funds
1 article · October 9, 2026
- cryptobriefing.comLedger users reportedly drained of over $86 million in suspected exploit
4 articles · October 9, 2026
- cryptopolitan.comLedger probes $86M theft linked to one of its own listed resellers
1 article · October 9, 2026
- decrypt.coLedger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller
1 article · October 9, 2026
- gizmodo.comLedger’s Crypto Wallets Reportedly Backdoored, $71 Million in Crypto Already Moved
1 article · October 9, 2026
- news.bitcoin.comLedger Investigating Reports of Drained Crypto Wallets as Estimated Losses Hit $86M
2 articles · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Hardware Wallet SecurityFollow
- On-chain forensicsFollow
- Cryptocurrency TheftFollow
- Software supply chain attacksFollow