Hardware wallet manufacturer Ledger has launched an investigation after users in South East Asia reported drained wallets linked to devices purchased from the reseller CryptoBilis. The Paris-based company advised customers who bought from this vendor within the last 90 days not to set up their devices and instructed those already configured to move assets to new signers with fresh seeds. While Ledger did not disclose specific loss amounts, blockchain investigator Specter traced theft addresses and reported that over $86 million had been lost. Ledger stated that the incident appears isolated to this specific reseller and market, confirming that its own infrastructure, systems, and services were not compromised and that no issues were reported for products bought directly from the company.

CryptoBilis, identified as a Kuala Lumpur, Malaysia-based hardware wallet vendor, was asked by Ledger to pause all sales and shipments of its devices. This event follows significant security breaches in the crypto sector earlier this year, including a July hack of Coldcard devices that resulted in nearly $120 million in bitcoin losses due to a firmware bug affecting seed generation. Additionally, Trezor recently disclosed that approximately 81,000 customer details were leaked via a third-party fulfillment partner, while scammers have previously exploited data from Ledger’s payment processor Global-e to conduct phishing attacks.