Business

Ledger Investigates Crypto Losses Linked to Southeast Asian…

Hardware wallet maker Ledger has asked authorized Southeast Asian reseller CryptoBilis to suspend sales and shipments while it investigates reports of cryptocurrency losses that onchain researchers estimate could exceed $86 million.Ledger advised customers who bought one of its devices from CryptoBilis within the past 90 days not to set it up if they have not already done so. Customers who have initialized a device were told to consider transferring their assets to a new Ledger signer using an entirely new recovery phrase.The company has not disclosed how many customers are affected, confirmed the value of the losses or identified how the assets were taken.“Ledger’s infrastructure, systems and services were not compromised,” the company said, adding that the investigation currently appears isolated to the reseller and affected market.

How Much Crypto May Have Been Lost?

Separate onchain researchers have identified groups of addresses that they believe received assets from affected wallet users, although Ledger has not confirmed that the transactions are connected to CryptoBilis devices.Researcher tanuki42 initially identified eight addresses associated with more than $72 million in suspected losses. A later analysis by researcher Specter expanded the address set and estimated more than $86 million had moved across Bitcoin, Ethereum and Tron.The estimates should not be treated as a confirmed loss figure. It remains unclear whether every transaction included in the analyses came from a Ledger customer, whether every affected Ledger was purchased through CryptoBilis or whether the two researchers’ totals capture the full incident.Security Alliance, or SEAL, subsequently circulated the addresses and asked people whose assets had moved to them to contact its incident-response service.

Investor Takeaway

The $86 million figure remains unverified. The immediate risk is concentrated among recent CryptoBilis buyers rather than evidence of a compromise across Ledger’s wider customer base.

Was Ledger Hardware Compromised?

That remains the central unanswered question. Ledger has not said that the devices were counterfeit, physically altered or compromised before reaching customers.A possible supply-chain compromise would be materially different from a vulnerability in Ledger’s hardware or internal systems. Hardware wallets are designed to keep private keys offline, but that protection depends on the user receiving a trusted device and securely generating a recovery phrase that has never been exposed to another party.A manipulated device or setup process could undermine that security before the wallet is ever used. Similar risks are not theoretical. Earlier this year, a security researcher documented a counterfeit Ledger Nano S Plus purchased through a Chinese marketplace that had been modified in an apparent attempt to capture recovery information.There is currently no confirmation that the CryptoBilis investigation involves the same technique or any physical modification at all.

Why Does CryptoBilis Being an Authorized Reseller Matter?

CryptoBilis appears on Ledger’s official reseller directory for Indonesia, Malaysia and the Philippines. That makes the case different from losses involving an obviously unofficial marketplace seller.For hardware-wallet users, buying through a manufacturer or authorized distributor is generally intended to reduce the risk of counterfeit or previously manipulated devices. If Ledger ultimately finds that devices were compromised somewhere in an authorized distribution chain, attention would shift toward where custody of the products changed hands between manufacturing and final delivery.Ledger has dealt with third-party risks before. In January, the company said customer information was exposed through e-commerce partner Global-e, while stressing that its own infrastructure and users’ wallet secrets had not been compromised.

Investor Takeaway

If an authorized distribution channel was compromised, hardware-wallet security would need to extend beyond the device itself to custody throughout the retail supply chain.

What Should CryptoBilis Customers Watch Next?

The most consequential finding will be Ledger’s explanation of how the affected users lost control of their assets. Evidence of counterfeit devices, modified hardware, exposed recovery phrases, phishing or an unrelated attack would each carry very different implications for other Ledger owners.Ledger’s current warning is deliberately narrow. Customers who purchased from CryptoBilis during the previous 90 days and have not initialized their devices are being told not to do so. Those already using one are being advised to consider migrating funds to a different signer initialized with a newly generated recovery phrase.Until Ledger identifies the cause, neither the reported $86 million loss estimate nor claims of a broader hardware vulnerability can be treated as established. The investigation now needs to determine whether the common link is the reseller, the devices themselves, the setup process or another attack vector entirely.