CryptoSafeKit

$86 Million in Suspected Losses. An Authorized Ledger Reseller. What Actually Went Wrong?

$86 Million in Suspected Losses. An Authorized Ledger Reseller. What Actually Went Wrong?

Ledger is investigating wallet-drain reports involving CryptoBilis customers in Southeast Asia. The hardware wallets may have been genuine—but the questions surrounding their supply chain are now impossible to ignore.

Imagine buying a hardware wallet because you want to stop trusting third parties with your Bitcoin.

You avoid suspicious marketplaces.

You check the seller.

You find a store listed as an authorized Ledger reseller.

You place the order.

The box arrives.

The Ledger logo looks correct.

Everything seems normal.

You set up the wallet, transfer your crypto, and finally feel that your assets are under your control.

Months later, you open your wallet.

The balance is gone.

You never shared your recovery phrase.

You never approved a suspicious transaction.

And you bought the device from an authorized seller.

What went wrong?

That is the uncomfortable question surrounding one of the biggest hardware-wallet security stories of October 2026.


Ledger Is Investigating Reports Linked to CryptoBilis

On October 9, Ledger confirmed that it was investigating reports of cryptocurrency losses among customers in Southeast Asia who purchased devices from a reseller called CryptoBilis.

CryptoBilis has been listed as an authorized Ledger reseller serving Malaysia, Indonesia and the Philippines.

As a precaution, Ledger asked the company to suspend sales and shipments of Ledger devices while the investigation continues.

The warning went further.

Customers who purchased devices from CryptoBilis during the previous 90 days were advised not to initialize unused devices.

Those who had already set up their devices were advised to consider moving their assets to a new Ledger signer with a newly generated recovery phrase.

That is a serious precaution for a hardware-wallet manufacturer to recommend.

But there is an important distinction:

Ledger has not confirmed that $86 million was stolen through a hardware vulnerability or a specific supply-chain compromise.

The investigation is ongoing.


Where Did the $86 Million Figure Come From?

Blockchain investigators began tracing suspicious cryptocurrency movements across multiple networks.

One researcher, tanuki42, reported suspected losses exceeding $72 million.

Another investigator, Specter, estimated that more than $86 million had moved through addresses associated with the suspected thefts.

The investigation involved assets on:

  • Bitcoin

  • Ethereum

  • Tron

However, the estimates have not been independently confirmed.

The exact number of victims is also uncertain, and the reported blockchain totals should not be treated as Ledger's official loss figure.

Still, even the possibility of losses at this scale raises an extremely important question.

What happens when a product designed to remove trust from the financial system still depends on trust in its physical distribution?


The Supply-Chain Theory

One of the leading theories being discussed publicly is a possible supply-chain compromise.

That could involve a device being modified or otherwise compromised before reaching its final owner.

But a theory is not proof.

At the time of writing, investigators have not publicly established the exact mechanism responsible for these reported losses.

That means we should not claim that CryptoBilis deliberately altered devices, that every affected wallet contained malicious hardware, or that Ledger's Secure Element was defeated.

Those would be conclusions ahead of the available evidence.

Nevertheless, the incident has brought renewed attention to a security risk that hardware-wallet users often overlook.

A hardware wallet doesn't begin its life when you switch it on.

It has already passed through manufacturing, packaging, storage, distribution and delivery.

Every stage matters.


Could a Genuine Ledger Still Be Tampered With?

Here is where things get interesting.

Ledger offers a cryptographic authentication feature called Genuine Check.

The check verifies that a connected device contains a genuine Ledger Secure Element capable of responding to an authentication challenge.

That is an important defense against counterfeit hardware.

But Ledger's own purchasing-security documentation acknowledges a limitation:

A successful Genuine Check cannot necessarily detect unauthorized physical modifications if the original Secure Element remains intact.

Think about the distinction.

A device may contain genuine Ledger security hardware.

But that fact alone does not reconstruct its entire physical history.

A cryptographic identity check and a complete hardware-forensics inspection are not the same thing.

This does not establish that modified devices caused the CryptoBilis incident.

It explains why investigators are examining the supply-chain possibility so seriously.


The Scariest Scenario Doesn't Require Breaking Encryption

Hypothetical Example

Imagine someone gains physical access to a wallet before delivery.

They install an unauthorized component capable of observing sensitive information displayed during setup.

The legitimate owner receives the device.

The owner generates a recovery phrase.

The phrase appears on the hardware-wallet screen.

But the malicious addition might also capture information needed to reconstruct that wallet.

The owner subsequently funds the wallet.

The attacker waits.

And later, the funds disappear.

This is an illustrative threat model—not a confirmed reconstruction of the CryptoBilis incident.

Its purpose is to show that attacking the environment around secure hardware can be very different from cracking the cryptography inside it.


So Is Buying From an Authorized Reseller Still Safe?

This is probably the most controversial part of the story.

Hardware-wallet manufacturers generally recommend purchasing directly or through approved distribution partners.

That advice still has merit.

Established sourcing and traceable distribution can reduce exposure to counterfeit devices and unknown sellers.

But authorized does not mean invulnerable.

Being listed as a reseller does not create a mathematical guarantee about every device passing through a distribution chain.

And buying from an unknown seller is not suddenly safer because an incident involves an authorized one.

The useful lesson is not to abandon all trust.

It is to understand what that trust covers—and what it doesn't.


What Should CryptoBilis Customers Do?

Ledger's specific warning should be taken seriously by customers who purchased devices from CryptoBilis within the period covered by its announcement.

If the device has not been initialized, do not set it up while awaiting official guidance.

If it has already been initialized, review Ledger's recommendation to consider migrating assets to a new, trusted signer with a newly generated recovery phrase.

Reusing the same potentially exposed phrase on a different device would not resolve a compromise of that phrase.

If you purchased your Ledger through another retailer, this investigation alone does not prove your device is affected.

Avoid panic-driven transfers, unsolicited recovery services, or messages claiming that every Ledger device must immediately be reset.

And whatever you do:

Never type your recovery phrase into a website that claims it can check whether your Ledger was affected.

A real security incident can quickly create opportunities for new scams.


What I Would Check Before Trusting Any New Hardware Wallet

After reading these reports, I would pay more attention to the purchase and initialization process.

Not only which model to buy.

But how the device reached me.

My checklist would include:

1. Verify the seller and purchasing channel.

Independently confirm the retailer's status rather than relying on a logo or claim on its own website.

2. Inspect the package and device.

Look for unusual components, signs of modification, unexpected accessories or suspicious setup instructions.

Packaging that appears normal is reassuring, but not conclusive.

3. Generate the recovery phrase yourself.

Never accept a recovery phrase or PIN that arrived prewritten or preconfigured.

4. Use authentic manufacturer software.

Run the manufacturer's supported authentication process using software obtained independently from official channels.

5. Understand what the authenticity check proves.

A genuine Secure Element does not automatically prove the complete physical supply chain was uncompromised.

And if a specific device or distributor is under an active manufacturer warning, do not treat routine setup checks as permission to ignore that warning.


This Changes How I Think About Self-Custody

At CryptoSafeKit, we work with hardware wallets and offline recovery products, including Ledger, Trezor, Tangem and VAULTIGO metal seed backups.

That makes one principle especially important to us:

No retailer's claims—including ours—should replace independent device verification.

A hardware wallet can protect private-key operations.

A metal recovery backup can improve the physical durability of recovery information.

Neither can guarantee the integrity of every component in a device's supply chain.

And a metal backup cannot make a previously exposed recovery phrase secret again.

The security system has to work from the moment the device is sourced through the day its owner eventually needs to recover the wallet.

Security is a process.

Not a sticker on a box.


The Biggest Lesson Isn't About Ledger Alone

This incident is receiving attention because of the reported dollar amount.

But the larger question applies to almost every hardware-wallet manufacturer.

Ledger.

Trezor.

Coldcard.

SafePal.

OneKey.

Any device shipped through a physical supply chain can raise questions about product handling, seller verification, counterfeit units or unauthorized modification.

Different manufacturers implement different hardware defenses.

Those differences matter.

But no product should be evaluated solely by its marketing slogan.

What matters is what its security controls can actually verify.


The Question Everyone Is Avoiding

For years, crypto users have repeated:

"Not your keys, not your coins."

That principle remains central to self-custody.

But perhaps there is another question worth asking:

Who had access to the device before those keys were created?

It is uncomfortable because most buyers cannot independently audit an entire supply chain.

They have to rely on some combination of manufacturer controls, retailer accountability, authentication tools and careful setup procedures.

And that is precisely why the CryptoBilis investigation matters.

Not because every Ledger is suddenly unsafe.

Not because an authorized reseller has been conclusively proven responsible.

But because it forces the industry to examine a form of trust that self-custody enthusiasts rarely discuss.


One Question for the Comments

I'm genuinely curious how other hardware-wallet users feel about this.

After the CryptoBilis reports, would you still buy a hardware wallet from an authorized reseller, or would you only buy directly from the manufacturer?

And another question:

If a Ledger passes Genuine Check, how confident are you that the physical device has not been modified?

Does that change your opinion of hardware-wallet security?

Or do you think supply-chain incidents are rare enough that the existing model still makes sense?

I'm interested in actual user experiences—not brand wars.

Please don't share recovery phrases, private keys, wallet balances or identifying purchase information in the comments.


Security note — October 10, 2026: Ledger has acknowledged reports of losses associated with CryptoBilis customers and requested a pause in sales and shipments. The widely circulated $86 million figure is an unconfirmed on-chain estimate. The cause, extent of any physical tampering, exact number of affected users and responsibility for the losses remain under investigation. This article is educational and does not provide financial or legal advice.

How do you rate this article?

4



CryptoSafeKit
CryptoSafeKit

CryptoSafeKit shares practical, independent guides on crypto security, self-custody, hardware wallets, recovery phrase protection, phishing prevention, and safer Web3 habits. Our goal is to help everyday users understand risks, avoid common mistakes, and take greater control of their digital assets.

Publish0x Publish0x

Reward the author with $0.01 in crypto, and earn yourself as you read!

20% to author / 80% to me.
Rewards are FREE. Publish0x pays them, not you.

Page not displaying correctly?