Ledger Probes $86M Wallet Drains via Reseller

Ledger Probes Fund Losses Linked to Regional Reseller
Hardware wallet maker Ledger has opened an investigation into reports of customer funds being drained in Southeast Asia. The affected users reportedly purchased their devices through CryptoBilis, a prominent regional reseller of crypto security hardware.
Preliminary estimates indicate that the total losses reported by victimized buyers could top $86 million. The incident highlights potential supply chain vulnerabilities in the distribution of cold storage hardware.
Understanding the CryptoBilis Connection
CryptoBilis operates as an authorized distributor of crypto hardware wallets in Southeast Asia, catering to retail investors looking for local delivery and support. The reseller stocks devices from several major manufacturers, including Ledger.
Reports began emerging after multiple users in the region discovered that their crypto assets were transferred out of their newly set up wallets without authorization. The concentrated pattern of losses quickly pointed toward purchases made through this specific retail channel.
How Supply Chain Attacks Threaten Hardware Security
Hardware wallets are designed to keep private keys entirely offline, protecting user assets from online malware and remote hacking. However, if a device is tampered with before reaching the end customer, those offline security guarantees can be bypassed.
Imagine buying a high-security lockbox for your home. If a dishonest middleman opens the package, makes a copy of the key, and repackages it to look brand new, putting your valuables inside is no longer secure.
Common Attack Vectors in Hardware Distribution
- Pre-generated recovery phrases included in fake instruction cards inside the box.
- Modified firmware flashed onto the device to leak generated private keys.
- Physical chip replacement or tampering on the device circuit board.
Ledger Response and Verification Safeguards
Ledger confirmed that it is actively investigating the reports alongside security researchers to pinpoint the precise mechanism used to drain customer funds.
The company reminded users that genuine Ledger devices generate a random 24-word recovery seed directly on the hardware screen during initial setup. A authentic device will never arrive with a pre-filled paper card showing secret seed words.
Essential Steps for Hardware Wallet Safety
To protect digital assets from supply chain risks, crypto users should follow rigorous setup and purchasing protocols.
Best Practices for Device Setup
- Purchase devices directly from the official manufacturer whenever possible.
- Never use a recovery phrase provided on a pre-printed piece of paper inside the package.
- Verify device authenticity using official companion software like Ledger Live during setup.
- Reset and re-generate a new seed phrase if you have any doubts about device integrity.
Balancing Self-Custody Control and Responsibility
Self-custody offers crypto holders direct ownership of their assets, removing reliance on centralized exchanges. However, taking full control requires remaining alert to security threats across the entire lifecycle of a device.
While cold storage remains one of the standard methods for securing digital assets, understanding hardware verification procedures is critical to keeping funds safe.
Latest blog posts

US Targets $1 Billion Iran-Linked Crypto Seizure
US officials are pursuing $1 billion in Iran-linked cryptocurrency following months of sanctions and asset freezes.

Stove Finance and Uniswap Labs Bring Global Equities Onchain
Stove Finance has partnered with Uniswap Labs to bring tokenized U.S. and South Korean stocks to Uniswap X.

Ledger Probes $86M Theft Linked to Asian Reseller
Ledger is investigating reports that $86 million in crypto was stolen from devices sold by Southeast Asian reseller Crypto Bilis.