InvestNot yet confirmed elsewhere1 publisher3 min readPublished
Suspected Ledger wallet thefts near $90 million under investigation as buyers from reseller CryptoBilis report losses
Ledger paused sales through authorized reseller CryptoBilis after investigators put suspected losses among its customers near $90 million. How the wallets were breached is still unknown. Ledger's fix is a new device with a fresh recovery phrase, which puts the suspicion on the sales channel.
The Investor · Invest desk

What happened
- Former Mt. Gox chief Mark Karpeles asked CryptoBilis to open unsold units so their circuit boards could be inspected for spying implants.
- On-chain investigator Specter traced inflows from hundreds of suspected victim wallets to addresses on Bitcoin, Ethereum and Tron, first putting the total above $86 million.
- Tether has been freezing USDT linked to the incident, according to MistTrack, which said several affected users had asked it for help.
Why it matters
- exposure A device altered outside its security chip can still pass Genuine Check, so buying from an authorized listing and running the check together protect buyers less than they assumed.
- decision Treasuries holding keys on hardware wallets now have to establish each device's seller and purchase date, because Ledger drew its advisory by vendor and a 90-day window.
- contradiction Zhao's account of a localized one-vendor attack is ahead of the evidence: investigators have confirmed neither the method nor that every wallet in the tally was hit by the same operation.
Ledger's remedy tells you more than its statement does. In its Oct. 9 statement the company said it was investigating losses among CryptoBilis buyers [4]. It told anyone who bought from that reseller in the past 90 days to leave unopened devices uninitialized, and urged those already using one to consider moving their crypto to a new Ledger set up with a fresh recovery phrase [6]. A company that suspected its own Secure Element or key-generation code would be unlikely to tell victims to buy another unit of the same product. The advisory covers one seller and about a quarter's worth of its sales [6].
The seller is an authorized one. CryptoBilis appears in Ledger's official reseller directory for Malaysia, Indonesia and the Philippines, and buying through such a listing is how customers usually guard against counterfeit or compromised hardware [7]. Ledger's security documentation says Genuine Check verifies the Secure Element but cannot necessarily detect physical modifications elsewhere in the device if the original chip is intact. A unit altered between the factory and the buyer could pass [10].
Changpeng Zhao, the Binance founder, wrote on X: "Based on information so far, it seems to be localized to a supply chain attack with one vendor." [8] Mark Karpeles, the former Mt. Gox chief executive, has asked CryptoBilis to open unsold wallets so their circuit boards can be checked for spying implants [9]. No confirmed evidence shows that implants caused the thefts. Ledger has not disclosed how many devices may be compromised, or whether the cause was counterfeit hardware, physical tampering or some other attack [11].
More than one explanation fits the record. If Karpeles finds added components on genuine boards, the limit of Genuine Check becomes the central fact. Every device that passed through a third party before reaching its owner would then carry the same exposure in principle [10]. If the devices were counterfeits, the question becomes how fakes got into an authorized reseller's stock. The third possibility is that the tally lumps separate thefts together. On-chain investigator Specter counted inflows from hundreds of suspected victim wallets into addresses on Bitcoin, Ethereum and Tron and first put the total above $86 million [12]. MistTrack later put it closer to $90 million [13]. The two figures are about $4 million apart, or roughly 5% [16]. Neither has been independently verified, and investigators have not established that every wallet in the count fell to the same operation [15].
The one recovery route on record is Tether's. MistTrack said it saw Tether freezing USDT linked to the incident [1]. Frozen USDT cannot move through ordinary transactions until the restriction is lifted [2]. Investigators have not determined how much of the money can be recovered [14].
I think the evidence points to a compromised channel more than a broken wallet, mainly because Ledger drew its own advisory so narrowly. That view is wrong if victims turn up who bought directly from Ledger or from other resellers. It is also wrong if the cause turns out to be in the firmware or the Secure Element. In either case a notice limited to one vendor and 90 days would be too small. Investigators still have not determined how the wallets were compromised [14].
What to watch
- What Karpeles finds when CryptoBilis opens its unsold units: added components on genuine boards would expose the limit of Genuine Check.
- Whether any victims turn out to have bought from Ledger directly or from other resellers. That would make the one-vendor, 90-day advisory too narrow.
- How much USDT Tether ends up freezing against the near-$90 million tally, and whether the estimates are independently verified.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence35
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
MistTrack said it observed Tether freezing USDT linked to the incident and that several affected users contacted its team for help.
- [2]
USDT includes administrative controls that let Tether restrict transfers from designated addresses; once frozen, the USDT cannot be moved through ordinary blockchain transactions unless the restriction is removed.
- [3]
Blockchain investigators estimate losses from suspected Ledger wallet thefts are near $90 million.
- [4]
In an Oct. 9 statement, Ledger said it was investigating reports that customers lost funds after buying devices from CryptoBilis, an authorized reseller operating in Southeast Asia.
- [5]
Ledger asked CryptoBilis to immediately pause sales and shipments of its hardware wallets while the investigation continues.
- [6]
Ledger advised customers who bought devices from CryptoBilis in the past 90 days not to initialize them if they had not completed setup, and urged those who had configured wallets to consider transferring their crypto to a new Ledger device initialized with a fresh recovery phrase.
- [7]
CryptoBilis appears in Ledger's official reseller directory for Malaysia, Indonesia and the Philippines; customers buying through authorized distribution channels generally rely on those relationships to reduce the risk of receiving counterfeit or compromised hardware.
- [8]
Based on information so far, it seems to be localized to a supply chain attack with one vendor.
- [9]
Former Mt. Gox CEO Mark Karpeles asked CryptoBilis to open some of its unsold Ledger wallets so their internal circuit boards could be inspected for possible spying implants or other unauthorized modifications.
- [10]
Ledger's security documentation acknowledges that its Genuine Check system verifies a device's Secure Element but cannot necessarily identify physical modifications elsewhere in the hardware if the original security chip remains intact, so a physically altered device could pass authentication.
- [11]
No confirmed evidence shows that malicious hardware implants caused the thefts; Ledger has not disclosed how many devices may have been compromised or established whether the incident resulted from counterfeit hardware, physical tampering or another attack method.
- [12]
On-chain investigator Specter said transaction analysis identified inflows from hundreds of suspected victim wallets into addresses across Bitcoin, Ethereum and Tron, and initially estimated the suspected thefts exceeded $86 million.
- [13]
Blockchain security firm MistTrack later placed the reported losses closer to $90 million.
- [14]
Investigators have yet to determine how the wallets were compromised or how much of the suspected stolen funds can be recovered.
- [15]
The loss estimates have not been independently verified, and investigators have not established whether every wallet included in the calculations was compromised through the same operation.
- [16]
MistTrack's estimate is about $4 million, or roughly 5%, above Specter's initial figure.
Sources
1 independent publisher whose own reporting we read for this story.
- cryptoslate.comLedger hack scare nears $90 million as Tether moves to freeze stolen USDT
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.