Back to What's New in Crypto
October 10, 20268 min readSECURITY

Ledger investigates reported fund losses tied to Southeast Asian reseller as researchers trace tens of millions in suspected thefts

The hardware wallet maker asked one authorized reseller to pause sales and shipments and told recent buyers to pause setup or move funds to a new signer while the cause remains unconfirmed.

C
CryptosEyes Research

News Desk · Researched and written on site

What happened

Ledger said on Friday, October 9 that it is investigating reports of lost funds from users in Southeast Asia who bought its hardware wallets from a reseller called CryptoBilis, and that it has asked the reseller to pause all sales and shipments of Ledger devices while the investigation runs. The reseller is listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines. The warning was aimed at a defined group rather than at every owner of the same devices. Customers who bought from that reseller within the past 90 days were advised not to set the device up if they have not done so yet. Customers who have already set one up were advised to consider moving assets to a new Ledger signer with a newly generated recovery phrase. The company said it will continue to inform customers of updates as the investigation progresses.

The company has not disclosed how many customers may be affected or the value of the reported losses. It has not identified the cause of the incidents and has not confirmed whether the devices were compromised. In a statement to Cointelegraph, the company said the incident appeared to be isolated to the reseller and the affected market, and that it had received no reports involving devices purchased directly from the company. It added that its infrastructure, systems and services were not compromised, and that its investigation remains ongoing. Those boundaries matter because they separate three different claims that are easy to run together. There are reports of losses. There are onchain traces that researchers connect to those reports. And there is a company investigation that, so far, has confirmed the reports exist without confirming a total, a victim count, or a mechanism.

Separate onchain research produced the large figures now attached to the incident. Cointelegraph reported that one researcher identified eight wallet addresses allegedly linked to more than 72 million dollars in losses, while another estimated losses exceeding 86 million dollars across Bitcoin, Ethereum and Tron. CoinDesk reported the same top line from a different angle: more than 86 million dollars in crypto may have been stolen from hundreds of wallets linked to devices sold by the reseller, though the losses and the connection have not been independently verified. A crypto security organization amplified the address findings and urged anyone whose funds were transferred to the identified addresses to contact its incident response team. That organization did not provide an independent estimate of losses or identify a cause. By Friday afternoon, an onchain analytics account reported that wallets allegedly linked to the suspected thefts transferred approximately 270,000 dollars in USDT and TRX to a large exchange, with most of the funds subsequently forwarded to that exchange hot wallet, according to Cointelegraph.

CoinDesk placed the maker and the possible mechanism in plain context. The company was founded in 2014, is based in Paris, and says it has sold more than 7 million devices worldwide. Its products keep the private keys used to access crypto offline, which is why any possible security issue involving the products draws broad attention. In this case, however, the investigation concerns devices sold through a third party reseller, and CoinDesk stressed that there is no confirmed evidence that Ledger systems or wallet technology were compromised. One possible explanation discussed in the reporting is a supply chain attack, in which hardware wallets are tampered with before reaching customers. The example given was a device supplied with a recovery phrase that an attacker already knows, allowing later access to funds deposited into the wallet. The reporting is explicit that there is no confirmation that device tampering or pre generated recovery phrases caused the reported losses.

Why it matters

Hardware wallets rest on a simple promise: the keys stay on a device the owner controls, away from an exchange and away from a phone or computer that is always online. The reported incident tests a different part of that promise, the path the device takes before it reaches the owner. A genuine device bought through an authorized channel can still become a security question if the owner cannot be sure who handled it, what was in the box, or how the recovery phrase was first generated. That is why the authorized status of the reseller matters. Buyers in Indonesia, Malaysia and the Philippines who followed the normal advice to use a listed reseller are the group being told to pause setup or move funds. The warning does not say that authorized channels failed. It does show that channel trust is now part of the security model that customers are being asked to evaluate.

The gap between the two researcher totals also matters. A figure above 72 million dollars tied to eight addresses and a figure above 86 million dollars across three networks are not the same measurement. They may overlap. They may count different addresses, different time windows, or different assumptions about which transfers belong to the same incident. Neither figure has been confirmed by the hardware wallet maker, and the extent of any connection between the traced addresses and the reseller investigation remains unclear in the reporting. Readers should therefore treat the numbers as researcher tallies from public blockchain data, not as an audited loss total. The reliable facts at this stage are narrower: losses were reported, the reseller was asked to stop selling and shipping, recent buyers received specific safety guidance, and the cause is still unconfirmed.

The guidance itself reveals where the risk is thought to sit. Telling a buyer who has already set up a device to move assets to a new signer with a newly generated recovery phrase is not a software update instruction. It is a key replacement instruction. If a recovery phrase were known to someone else, keeping the same device would not solve the problem, because the phrase is what restores access. Moving funds to fresh keys generated on a new signer addresses that specific danger. The same step is disruptive and costly in time and fees, which is why the advice is scoped to buyers from one reseller in the past 90 days rather than issued to every owner. It is also why confirmation of the mechanism matters so much. A tampered device explanation, a pre generated phrase explanation, and unrelated user compromises that happen to cluster around one market would each call for a different response, even though the immediate safety step looks similar.

Scale gives the incident weight beyond the affected market. CoinDesk noted that the potential theft may add to a rough year for crypto security, citing an exchange exploit last month that resulted in over 350 million dollars in stolen assets and other major incidents at about 320 million dollars, 295 million dollars and 293 million dollars, according to DefiLlama data. Those were platform events. The reseller case, if the traces hold up, is a consumer custody event spread across hundreds of wallets. Remediation is then not a single company restoring a single balance sheet. It is many individual owners deciding whether to move funds, many addresses to verify, and a trust question that follows a physical product through shops and shipments. That difference is the reason a reseller investigation can lead a daily news package even while the confirmed facts are still thin.

What to watch

Watch for the maker to confirm or narrow the mechanism. A statement that says whether devices were compromised, whether recovery phrases were involved, or whether the losses trace to another cause would change the incident from a warning into an explanation. Until that statement arrives, the strongest evidence is the sequence of actions: sales and shipments paused, a 90 day buyer window named, and new signer guidance issued. Any expansion of that window, any addition of other resellers or markets, or any report involving devices bought directly from the company would widen the incident beyond the boundary the company described on Friday. Any narrowing, with a confirmed victim count and a confirmed total, would do the opposite and let readers retire the larger researcher estimates.

Watch the money after the first traces. The approximately 270,000 dollars reported moving to a large exchange on Friday afternoon is small next to estimates above 72 million and 86 million dollars. That does not make it unimportant. Exchange deposits are one of the few points where traced funds can meet account records, freezing processes, or law enforcement requests. Further transfers, freezes, returns, or public address updates from the security organization collecting victim reports would show whether the address set is growing, shrinking, or being corrected. A week with no new addresses and a company total well below the researcher figures would point to early over counting or to traces that mixed unrelated losses. New victim reports that all involve the same reseller would strengthen the connection that one researcher described as not certain but not coincidence.

Watch how channel controls change in public. The useful long term response to a reseller scare is not a general reminder to be careful. It is verifiable practice that buyers can check before setup: how a customer confirms a device is genuine, how the first recovery phrase is shown to be generated on the device, what a reseller is audited for, and how quickly a pause reaches shops in each market. None of those changes has been announced in the reporting read for this story, so they belong on the watch list rather than in the record. If the investigation closes without any channel change that customers can see, confidence will rest on the company assurance that its own systems were not compromised. If it closes with checks that buyers can perform and resellers must pass, the incident will have produced a clearer standard for the next purchase.

Finally, watch the language of confirmation. This story will be misread if researcher estimates harden into a company confirmed loss. They have not. It will also be misread if the absence of a confirmed mechanism is taken to mean nothing happened. The company acted on reports, named a reseller, stopped its sales and shipments, and told a defined group of buyers to protect their funds. Those are confirmed actions. The size, cause, and full victim set remain open questions, and the next update should be judged by how many of those three it answers.

Sources

This story was researched and written by the CryptosEyes news desk from the sources above. It is news reporting and market education, not investment advice and not a recommendation to buy or sell any asset.

More from the desk

Important: Educational Purposes OnlyThe data, charts, treasury tracking metrics (including mNAV and SPS), and research provided on CryptosEyes.com are for informational and educational purposes only. They do not constitute certified financial, investment, or trading advice. Digital assets like Bitcoin and Ethereum are highly volatile. Always conduct your own research and consult with a registered financial advisor before making investment decisions.