Ledger, the French hardware-wallet maker, has asked customers who obtained its devices from the Kuala Lumpur-based reseller CryptoBilis to stop setting up the products and to relocate any holdings to a fresh Ledger signer. The advisory follows reports that users in Southeast Asia lost a combined total exceeding $86 million after interacting with the compromised units.

Incident Details

CryptoBilis sold Ledger hardware to buyers in the region during the previous 90-day window. Shortly after, users posted on social media that their funds had been drained. A blockchain analyst known as Specter traced the outgoing transactions and estimated the total loss at more than $86 million. Ledger’s official channels confirmed that the problem appears confined to devices sourced from this particular vendor.

Ledger's Response

The company announced that it has requested CryptoBilis to suspend all sales and shipments of Ledger products while the investigation proceeds. Ledger also recommended that anyone who has already initialized a device should create a new seed phrase on a different Ledger unit and transfer their assets there. In its statement, Ledger emphasized that no incidents have been linked to devices purchased directly from the manufacturer, and that its internal infrastructure has not been breached.

Broader Context

The warning arrives amid a series of hardware-wallet security incidents this year. In July, a firmware flaw in Coldcard devices allowed attackers to reconstruct seed phrases, resulting in roughly $120 million in Bitcoin being stolen. Earlier, Trezor disclosed that data belonging to about 81,000 customers had been exposed after a third-party fulfillment partner suffered a breach. These events highlight the heightened risk landscape for hardware-wallet users, especially when third-party sellers are involved.

Why it matters

Ledger’s alert underscores the importance of sourcing security-critical devices directly from manufacturers or authorized distributors. As hardware wallets remain a primary defense for crypto holders, any compromise—whether through a reseller’s supply chain or a firmware bug—can lead to substantial financial losses. The episode also illustrates how attackers continue to exploit peripheral weaknesses, reinforcing the need for vigilant asset management and supply-chain oversight in the cryptocurrency ecosystem.