Ledger Wallet Mystery Deepens as Suspected Losses Hit $93.4M

Unraveling the $93.4 Million Ledger Mystery
Imagine buying a brand-new high-tech vault for your savings, setting it up in your living room, and waking up one morning to find it emptied without any sign of forced entry. That is the troubling situation facing hundreds of cryptocurrency owners as reports of missing funds continue to grow.
On October 9, 2026, the crypto community was hit with alarming news regarding hardware wallet manufacturer Ledger. Initial reports estimated that around $86 million in digital assets had vanished from user accounts. However, as onchain sleuths dug deeper into blockchain records, the suspected total jumped to a staggering $93.4 million.
At the time of these reports, BitcoinBTC+0.77% was trading at $82,499 (+0.92%) and EthereumETH+0.25% sat at $2,487 (+0.49%). Please note that past performance of digital assets is not an indicator of future returns.
What the Onchain Numbers Tell Us
Independent blockchain researchers have been working overtime to figure out how so much money moved without triggering standard security alarms. The most detailed breakdown comes from John Kamal, a reporter and analyst at Yfarmx.
According to Kamal's extensive onchain deep dive, the total losses linked to this mystery may have reached $93.4 million spread across 471 unique crypto addresses. While these numbers are compelling, Ledger has not yet officially verified these findings or confirmed the total amount lost.
Another major data firm, Bitquery, conducted its own parallel investigation and arrived at a remarkably similar number. Bitquery estimates the total theft at approximately $92.9 million across 311 distinct addresses.
One thief had all the keys, Bitquery explained in their analysis of the onchain movement.
The fact that two separate analytics platforms reached nearly identical totals gives strong weight to the idea that a single coordinated operation was at play.
The Southeast Asia Connection and Reseller Risk
Where did all of this begin? Early reports from Bitcoin.com News revealed that Ledger was actively investigating reports of missing funds specifically coming from users in Southeast Asia.
A key common denominator among many affected users was where they purchased their devices. Many victims had bought their hardware wallets from a reseller named Crypto Billis.
While buying hardware wallets from third-party vendors is common when direct shipping is unavailable, it opens up a critical vulnerability known as a supply chain attack.
What Is a Supply Chain Attack?
To understand what likely happened, it helps to use a simple everyday analogy. Imagine ordering a brand-new padlock online.
Before it reaches your doorstep, someone intercepts the package, alters the internal pins, records a duplicate key, and carefully reseals the box. When you open the package, everything looks completely untouched.
You set up your lock, assuming your belongings are safe, completely unaware that someone else already holds a master key. In crypto, if a physical device is tampered with before you open the box, your offline seed phrase can be compromised.
The Hidden Hardware Discovery by Mark Karpeles
Adding a crucial layer to this mystery is a recent discovery made by Mark Karpeles, the former CEO of Mt Gox.
Karpeles documented specific Ledger devices containing hidden surveillance hardware inside their physical casings. This rogue hardware was designed to intercept recovery seed phrases right when users initialized their devices for the first time.
While hardware analysts have proven that this physical modification technique is technically possible, investigators have not yet conclusively proven that these modified units caused the $93.4 million in losses. Neither Ledger nor independent sleuths have established a confirmed direct link yet.
How the Stolen Funds Were Drained and Moved
The way the funds were drained provides valuable clues. John Kamal's report highlights that the transactions appeared as if they were authorized using the victims' actual signing credentials.
On the Bitcoin network, several target addresses were wiped completely clean. The transactions left zero change UTXOs behind in the original wallets, meaning the thief swept every coin out in one complete movement.
The attack involved at least seven major blockchain networks:
Once the funds were swept, the attacker funneled the crypto through cross-chain protocols and privacy tools. Platforms like Thorchain and Tornado Cash were used to obscure movement and complicate recovery efforts.
What Chainalysis and Experts Are Observing
Major blockchain intelligence firm Chainalysis publicly acknowledged the ongoing investigation on platform X. The firm confirmed that its team is actively tracking the movement of stolen funds associated with Ledger product owners.
Chainalysis noted that its analysts identified a sophisticated cross-chain laundering operation. The complex web of cross-chain swaps makes tracking and freezing the assets exceptionally difficult.
Cybersecurity experts emphasize what this attack is not. Current evidence suggests this was not a remote zero-day software exploit over the internet, nor was it a firmware bug like the one previously seen with Coldcard devices.
A Troubling Pattern in Hardware Wallet E-Commerce
This situation occurs against a broader backdrop of security concerns in the hardware supply chain. Recently, customer data breaches hit other leading hardware wallet providers like Trezor and Safepal.
In one incident, Safepal suffered a data breach affecting 39,798 customers after unauthorized actors gained access to customer order details through a malfunctioning e-commerce plugin.
John Kamal's analysis notes that the reseller involved in this Ledger case, Crypto Billis, sold multiple major brands, including:
- Trezor
- Safepal
- Tangem
- Onekey
- Ledger
What Happens Next?
The crypto community is waiting for an official, formal postmortem report from Ledger's internal security team to provide clarity.
Until Ledger confirms the exact mechanism behind the missing funds, crypto users are strongly advised to purchase hardware devices directly from official manufacturers rather than unverified third-party sellers.
Latest blog posts

Brazil's B3 Targets Tokenized Stock Trading for 2027
Brazil's main stock exchange, B3, plans to launch a tokenized asset platform by early 2027 while navigating local regulatory requirements.

BNB Chain Hits 2 Million RWA Holders in Onchain First
BNB Chain has become the first blockchain to pass 2 million RWA holders, capturing 40% of all tokenized asset wallets.

US Plans $1B Crypto Seizure Linked to Iran
Treasury Secretary nominee Scott Bessent announced US plans to seize $1 billion in cryptocurrency tied to Iran sanction evasions.