Hardware wallet manufacturer Ledger has launched an investigation after users in South East Asia reported drained wallets linked to devices purchased from the reseller CryptoBilis. The Paris-based company advised customers who bought from this vendor within the last 90 days not to set up their devices and instructed those already configured to move assets to new signers with fresh seeds. While Ledger did not disclose specific loss amounts, blockchain investigator Specter traced theft addresses and reported that over $86 million had been lost. Ledger stated that the incident appears isolated to this specific reseller and market, confirming that its own infrastructure, systems, and services were not compromised and that no issues were reported for products bought directly from the company.
CryptoBilis, identified as a Kuala Lumpur, Malaysia-based hardware wallet vendor, was asked by Ledger to pause all sales and shipments of its devices. This event follows significant security breaches in the crypto sector earlier this year, including a July hack of Coldcard devices that resulted in nearly $120 million in bitcoin losses due to a firmware bug affecting seed generation. Additionally, Trezor recently disclosed that approximately 81,000 customer details were leaked via a third-party fulfillment partner, while scammers have previously exploited data from Ledger’s payment processor Global-e to conduct phishing attacks.
The isolation of the breach to a single reseller highlights the persistent supply chain vulnerabilities inherent in hardware wallet distribution. Although Ledger asserts its core infrastructure remains secure, the reliance on third-party vendors for regional market penetration introduces operational risks that are difficult to fully mitigate through internal compliance alone. The discrepancy between Ledger’s silence on total losses and Specter’s $86 million estimate underscores the opacity often present during active investigations, where immediate forensic tracing may capture preliminary figures before full scope assessment.
Institutional adoption of self-custody solutions depends heavily on trust in both the manufacturer and the distribution network. This incident reinforces the necessity for end-users to verify purchase channels strictly against official authorized lists, as social engineering or compromised intermediaries can bypass technical safeguards like secure elements. Market structure implications suggest a potential tightening of vetting protocols for resellers, as manufacturers face reputational pressure to ensure that physical device integrity is maintained from factory to consumer.


