Ledger, the Paris-based manufacturer of popular hardware wallets, has opened an inquiry after claims surfaced that more than $86 million in digital assets may have been taken from accounts linked to devices sold through the Southeast Asian reseller CryptoBilis. The alleged loss involves hundreds of wallets across Bitcoin, Ethereum and Tron, though the exact figures and the cause remain unverified.

Background

A pseudonymous analyst known as Specter posted on X that suspicious activity was observed on addresses tied to victims who purchased Ledger devices from the reseller. The analyst said the stolen funds spanned three major blockchain networks, but independent confirmation of the total amount or the number of affected users has not been provided. Ledger has not confirmed the loss amount and has indicated that the investigation is ongoing.

Ledger’s response

In reaction to the reports, Ledger instructed CryptoBilis to halt all further sales and shipments of its devices while the probe continues. The company also issued guidance to customers who bought a Ledger product from the reseller within the last 90 days, recommending that they refrain from initializing the hardware. For those who have already set up a wallet, Ledger advises transferring all holdings to a brand-new device that generates a unique recovery seed, thereby eliminating any potential backdoor that could have been introduced during manufacturing or distribution.

Possible supply-chain compromise

One scenario being examined is a supply-chain attack, where the hardware arrives pre-loaded with a recovery phrase known to the attacker. Such a compromise would give the malicious party the ability to access any assets deposited into the wallet after the user begins using it. This differs from a breach of Ledger’s internal systems, which the company has not indicated has occurred.

Context within a turbulent security landscape

The alleged theft adds to a series of high-profile security breaches that have plagued the crypto sector this year. Recent incidents include a Bitget exploit that resulted in more than $350 million in losses, as well as attacks on the Liquid Network, Drift and Kelp platforms, each costing close to $300 million. The cumulative impact of these events has heightened concerns over the safety of custodial and non-custodial solutions alike.

Why it matters

Ledger’s hardware wallets are widely used by investors seeking to store private keys offline, and the company reports sales exceeding seven million units globally. Any confirmed vulnerability—especially one that could affect the supply chain—would have ramifications for user confidence and could prompt broader scrutiny of third-party distributors in the crypto hardware market. The outcome of Ledger’s investigation will likely influence best-practice recommendations for hardware wallet procurement and may shape future regulatory focus on device integrity.

Why it matters

The case underscores the importance of verifying the provenance of security-critical devices and highlights how supply-chain weaknesses can expose large sums of cryptocurrency to theft, potentially eroding trust in one of the industry’s most relied-upon protection mechanisms.