Skip to content

InvestNot yet confirmed elsewhere1 publisher3 min readPublished

Suspected Ledger wallet thefts near $90 million under investigation as buyers from reseller CryptoBilis report losses

Ledger paused sales through authorized reseller CryptoBilis after investigators put suspected losses among its customers near $90 million. How the wallets were breached is still unknown. Ledger's fix is a new device with a fresh recovery phrase, which puts the suspicion on the sales channel.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying Suspected Ledger wallet thefts near $90 million under investigation as buyers from reseller CryptoBilis report losses
Generated illustration

What happened

  • Former Mt. Gox chief Mark Karpeles asked CryptoBilis to open unsold units so their circuit boards could be inspected for spying implants.
  • On-chain investigator Specter traced inflows from hundreds of suspected victim wallets to addresses on Bitcoin, Ethereum and Tron, first putting the total above $86 million.
  • Tether has been freezing USDT linked to the incident, according to MistTrack, which said several affected users had asked it for help.

Why it matters

  • exposure A device altered outside its security chip can still pass Genuine Check, so buying from an authorized listing and running the check together protect buyers less than they assumed.
  • decision Treasuries holding keys on hardware wallets now have to establish each device's seller and purchase date, because Ledger drew its advisory by vendor and a 90-day window.
  • contradiction Zhao's account of a localized one-vendor attack is ahead of the evidence: investigators have confirmed neither the method nor that every wallet in the tally was hit by the same operation.

Ledger's remedy tells you more than its statement does. In its Oct. 9 statement the company said it was investigating losses among CryptoBilis buyers [4]. It told anyone who bought from that reseller in the past 90 days to leave unopened devices uninitialized, and urged those already using one to consider moving their crypto to a new Ledger set up with a fresh recovery phrase [6]. A company that suspected its own Secure Element or key-generation code would be unlikely to tell victims to buy another unit of the same product. The advisory covers one seller and about a quarter's worth of its sales [6].

The seller is an authorized one. CryptoBilis appears in Ledger's official reseller directory for Malaysia, Indonesia and the Philippines, and buying through such a listing is how customers usually guard against counterfeit or compromised hardware [7]. Ledger's security documentation says Genuine Check verifies the Secure Element but cannot necessarily detect physical modifications elsewhere in the device if the original chip is intact. A unit altered between the factory and the buyer could pass [10].

Changpeng Zhao, the Binance founder, wrote on X: "Based on information so far, it seems to be localized to a supply chain attack with one vendor." [8] Mark Karpeles, the former Mt. Gox chief executive, has asked CryptoBilis to open unsold wallets so their circuit boards can be checked for spying implants [9]. No confirmed evidence shows that implants caused the thefts. Ledger has not disclosed how many devices may be compromised, or whether the cause was counterfeit hardware, physical tampering or some other attack [11].

More than one explanation fits the record. If Karpeles finds added components on genuine boards, the limit of Genuine Check becomes the central fact. Every device that passed through a third party before reaching its owner would then carry the same exposure in principle [10]. If the devices were counterfeits, the question becomes how fakes got into an authorized reseller's stock. The third possibility is that the tally lumps separate thefts together. On-chain investigator Specter counted inflows from hundreds of suspected victim wallets into addresses on Bitcoin, Ethereum and Tron and first put the total above $86 million [12]. MistTrack later put it closer to $90 million [13]. The two figures are about $4 million apart, or roughly 5% [16]. Neither has been independently verified, and investigators have not established that every wallet in the count fell to the same operation [15].

The one recovery route on record is Tether's. MistTrack said it saw Tether freezing USDT linked to the incident [1]. Frozen USDT cannot move through ordinary transactions until the restriction is lifted [2]. Investigators have not determined how much of the money can be recovered [14].

I think the evidence points to a compromised channel more than a broken wallet, mainly because Ledger drew its own advisory so narrowly. That view is wrong if victims turn up who bought directly from Ledger or from other resellers. It is also wrong if the cause turns out to be in the firmware or the Secure Element. In either case a notice limited to one vendor and 90 days would be too small. Investigators still have not determined how the wallets were compromised [14].

What to watch

  • What Karpeles finds when CryptoBilis opens its unsold units: added components on genuine boards would expose the limit of Genuine Check.
  • Whether any victims turn out to have bought from Ledger directly or from other resellers. That would make the one-vendor, 90-day advisory too narrow.
  • How much USDT Tether ends up freezing against the near-$90 million tally, and whether the estimates are independently verified.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence40
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence35
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    MistTrack said it observed Tether freezing USDT linked to the incident and that several affected users contacted its team for help.

  2. [2]

    USDT includes administrative controls that let Tether restrict transfers from designated addresses; once frozen, the USDT cannot be moved through ordinary blockchain transactions unless the restriction is removed.

  3. [3]

    Blockchain investigators estimate losses from suspected Ledger wallet thefts are near $90 million.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. cryptoslate.com

    1 article · October 9, 2026

    Ledger hack scare nears $90 million as Tether moves to freeze stolen USDT

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories