Skip to content

InvestReports disagree8 publishers2 min readPublished

Specter traces more than $86 million drained from hundreds of Ledger wallets

On-chain analyst Specter traced more than $86 million drained from hundreds of Ledger hardware-wallet users across Ethereum, TRON and Bitcoin. With the cause unconfirmed, holders cannot yet tell whether moving coins to a new device would help at all.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying Specter traces more than $86 million drained from hundreds of Ledger wallets
Generated illustration

What happened

  • Ledger had not commented publicly or confirmed any flaw in its devices or firmware as of the report date.
  • One Bitcoin address tied to the theft has received more than 211 BTC, and those coins had not moved when the report was published.
  • Earlier this year a fake Ledger Live app on Apple's App Store took about $9.5 million from more than 50 users before it was caught.
  • In August a reported seed-generation flaw in Coldcard hardware wallets cost users more than $88 million in Bitcoin.

Why it matters

  • decision Holders have to decide whether to migrate before the cause is known, and migration only protects them if Ledger's hardware or firmware turns out to be at fault.
  • constraint If seed phrases were stolen, a firmware patch protects none of the affected users, because the words rebuild the wallet on any device.
  • precedent After Coldcard's device-side loss two months earlier, nobody can safely assume that a hardware-wallet drain this large was caused by user error.

The theories circulating on X and Reddit each put the fault somewhere different [3]. A hardware or firmware flaw would put it in the device itself. In that case, Crypto Briefing reported, the response could mean firmware updates or moving funds to new wallets entirely [7]. A stolen seed phrase puts the fault wherever the words were kept, because those words can recreate the wallet anywhere [3]. Phishing through fake apps or websites puts it in user habits, and the fix there is to keep the seed off any phone or computer and check every transaction before signing [6].

At more than $86 million, the Ledger drain is about nine times the loss from the fake Ledger Live app, where the average victim lost at most about $190,000 [11][12]. Add Coldcard's August loss and hardware-wallet users have reportedly lost more than $174 million in two incidents about two months apart [16]. If the estimate reaches the $100 million some reports suggest, the Ledger figure grows by $14 million, or about 16% [13][15].

How this resolves depends on what Ledger eventually names. If it names phishing or a third-party app, the drain sits alongside the App Store case, and holders who never typed their words into anything have nothing to move [6]. If it names a device or firmware flaw, Ledger joins Coldcard, and balances on affected devices stay at risk until they are patched or migrated [14][7]. Continued silence leaves holders choosing on partial information.

I think the evidence so far supports a narrower claim than a failure of cold storage. Specter's tracing shows a coordinated campaign against hundreds of wallets [5], but nothing published so far shows the attacker got in through the device [1]. The counter-case is strong. A victim list made up of one brand's customers is what a shared device flaw would produce, and Coldcard's seed-generation failure shows that such flaws can cost this much [14]. A phishing campaign aimed at Ledger owners would produce the same list.

Until a cause is named, holders bear the cost of guessing. Moving every balance to a new wallet is work spent on a fix that may turn out to be unnecessary [7], and leaving coins where they are is a bet that the device is sound. A Ledger statement confirming a hardware or firmware vulnerability would prove the narrower view wrong.

What to watch

  • Ledger's first public statement, and whether it blames the device, leaked seed phrases or phishing.
  • Any firmware update or migration advice from Ledger, which Crypto Briefing describes as the response a device fault would require.
  • Newly identified victims pushing the loss estimate further above $86 million.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence58

Perspective Coverage

8 publishers
Builder
Builder 31%
Operator
Operator 37%
Investor
Investor 32%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The cause has not been confirmed; Ledger has not confirmed any vulnerability related to its devices or firmware and had stayed silent publicly as of the report date.

  2. [2]

    On-chain analyst Specter flagged what appears to be a coordinated drain of funds from Ledger hardware wallet users on October 9, 2026.

    ReportedSupportedSource: Crypto Briefing, citing Specter (@SpecterAnalyst)3 sources— create a free account to open themView cited source
  3. [3]

    Theories on X and Reddit include a device or firmware flaw, seed phrase compromise (the seed phrase can recreate a wallet anywhere, making the device irrelevant if attackers obtain it), and phishing via fake apps or websites that trick users into signing malicious transactions or handing over recovery words.

    ReportedSupportedSource: Crypto Briefing, summarising community discussion4 sources— create a free account to open themView cited source

Sources

8 independent publishers whose own reporting we read for this story.

  1. coindesk.com

    1 article · October 9, 2026

    Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen
  2. cointelegraph.com

    1 article · October 9, 2026

    Ledger investigates fund losses linked to Southeast Asian reseller, warns users
  3. crowdfundinsider.com

    1 article · October 9, 2026

    Ledger Hack: Reports Indicate Hardware Wallets Being Drained of Funds
  4. cryptobriefing.com

    4 articles · October 9, 2026

    Ledger users reportedly drained of over $86 million in suspected exploit
  5. cryptopolitan.com

    1 article · October 9, 2026

    Ledger probes $86M theft linked to one of its own listed resellers
  6. decrypt.co

    1 article · October 9, 2026

    Ledger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller
  7. gizmodo.com

    1 article · October 9, 2026

    Ledger’s Crypto Wallets Reportedly Backdoored, $71 Million in Crypto Already Moved
  8. news.bitcoin.com

    2 articles · October 9, 2026

    Ledger Investigating Reports of Drained Crypto Wallets as Estimated Losses Hit $86M

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories