BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

CZ Warns of an Invisible Threat Following the $86 Million Ledger Hack

Ledger users lost more than $86 million on October 9, 2026, on Bitcoin, Ethereum, and Tron. Binance founder Changpeng Zhao (CZ) believes these thefts come from a supply chain attack linked to

AnonymousCryptoCompass newsroom
October 10, 2026
4 min read
NEWS
CZ Warns of an Invisible Threat Following the $86 Million Ledger Hack
CryptoCompass editorial visual for altcoins coverage.

Ledger users lost more than $86 million on October 9, 2026, on Bitcoin, Ethereum, and Tron. Binance founder Changpeng Zhao (CZ) believes these thefts come from a supply chain attack linked to a single seller. Ledger is investigating and the cause is not confirmed.

In Brief

  • $86 million stolen from Ledger users.
  • Ledger is investigating reported losses among buyers of CryptoBilis in Southeast Asia and has requested a halt to its sales.
  • Changpeng Zhao (CZ) mentions a supply chain attack.
  • Tether froze $1.45 million in USDT, lifted after three hours.

Ledger Hack: What Happened and How Much Was Stolen?

On October 9, 2026, Ledger announced it was investigating fund losses among Southeast Asian users who purchased their hardware wallet from reseller CryptoBilis. Analyst Specter estimates these losses at over $86 million, across Bitcoin, Ethereum, and Tron. Ledger has neither confirmed the cause nor the number of devices involved. Where did the funds go? Arkham grouped 152 addresses under the label “ledger-drainer”, their wallet valued at $71.6 million. Arkham’s tracing also shows outflows to other addresses, ranging from $500,000 to $4 million each.

Three counts, three results. Specter speaks of more than $86 million. MistTrack places losses near $90 million. Arkham shows $71.6 million. The gap partly comes from scope since the capture attached to Specter’s post shows another Arkham entity valued at about $87 million. It’s like three watches not showing the same second: they describe the same event, not at the same minute.

Asset Quantity Held Value (USD) Ether (ETH) 11,822 ETH $29.4 M Bitcoin (BTC) 213,371 BTC $17.68 M USDD 13.646 M USDD $13.65 M Tether (USDT) 10.849 M USDT $10.85 M “ledger-drainer” entity, 152 addresses, capture of October 9, 2026. Source: Arkham.

Tether also reacted. According to MistTrack, the issuer froze USDT on addresses linked to the thefts. Do not confuse this freeze with that of THORChain, on the same day when about $1.45 million USDT were blocked in its vaults on Tron, then released about three hours later. Tether has not explained this second freeze, and no link to the thefts is confirmed.

What Does CZ Say About the Ledger Wallet Hack?

On October 9, 2026, CZ (Changpeng Zhao) considered on X that the thefts seem linked to a supply chain attack, limited to a single seller. This type of attack involves tampering with a product before it reaches the customer. Here is his message:

Based on the available information, this appears localized to a supply chain attack involving a single seller. A small number of people probably bought fake Ledger devices (or tampered Ledger devices).

Three scenarios remain open:

  • Counterfeit: a fake device that mimics Ledger;
  • Physical modification: a real device with an added or altered component;
  • Recovery phrase known by a third party, whatever the cause.

In a second message, CZ advises waiting a few weeks before putting a large sum on a new wallet. Except the threat is hard to see. The Genuine Check, Ledger’s authenticity control, does not detect physical modification as long as the original chip remains intact, according to Ledger’s documentation on Genuine Check. It remains useful against counterfeits.

Mark Karpelès, former CEO of Mt. Gox, showed on X a Ledger he claims is modified, with a hidden implant. According to him, such a device could read the screen and retrieve the recovery phrase during setup. He also asked CryptoBilis to open devices in stock for inspection. Nothing establishes at this stage that this device comes from CryptoBilis, nor that this implant explains the thefts. No source consulted also indicates how long after purchase the funds disappeared.

What Does Ledger Recommend to CryptoBilis Buyers?

On October 9, 2026, Ledger Support asked CryptoBilis to suspend all sales and shipments of Ledger devices. Ledger recommends customers of this reseller from the past 90 days not to initialize their devices. Those who have already done so may consider moving their funds to a new device, with a new recovery phrase.

Victims of this Ledger Hack should stay cautious because no one, not even a fake technical support, needs this phrase. Ledger directs its customers to its official support channels, where they can open a ticket. The alert targets Southeast Asian buyers and a single reseller. Ledger does not cite any other reseller at this stage.

As of October 10, 2026, no end date for the investigation is announced despite Changpeng Zhao’s (CZ) statement. Upcoming communications from Ledger and MistTrack will likely indicate whether these thefts come from hardware implants or another mechanism. Do you think this Ledger hack could extend to European customers?