BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Ledger Hack? $86 Million Drained: What Is Behind the Tampered Wallets From Southeast Asia

First Coldcard, now Ledger. Two months after more than $116 million drained out of Coldcard Bitcoin wallets, the world's best-known hardware wallet is in the spotlight. Since Friday morning,

AnonymousCryptoCompass newsroom
October 9, 2026
14 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

First Coldcard, now Ledger. Two months after more than $116 million drained out of Coldcard Bitcoin wallets, the world's best-known hardware wallet is in the spotlight. Since Friday morning, 9 October 2026, users in Southeast Asia have been reporting empty wallets on X and Reddit. On-chain analysts now count more than $86 million that has flowed to a handful of collection addresses. Ledger has confirmed an investigation and halted one of its official distributors: CryptoBilis, a reseller that sells Ledger devices in Indonesia, Malaysia and the Philippines.

The most important point first: based on everything known as of Friday evening, Ledger itself was not hacked. The supply chain was. The trail leads to devices sold through a single middleman. If you bought your Ledger directly from the manufacturer, there is no indication so far that you are affected. For everyone else, there are clear steps, summarised further down.

Ledger Hack: What Happened on 9 October

The first major alert came from the pseudonymous blockchain investigator Specter at 12:24 UTC. He had followed up on reports from Ledger users about drained wallets and published ten collection addresses on Bitcoin, Ethereum and Tron that, in his view, received funds from hundreds of victim wallets. His total: more than $86 million. A quarter of an hour later he added that he had not yet been able to determine the exact number of affected wallets. A second analyst, tanuki42, puts the losses at more than $72 million and is asking victims to contact the volunteer emergency group SEAL 911. The analytics firm MistTrack spoke of almost $90 million in the afternoon.

The analytics platform Arkham, which now labels the collection addresses "Ledger Theft", shows what the pattern looks like. On Friday morning, the Tron address tagged TBkcU received ten USDT transfers in quick succession, each between $500,000 and $2.4 million. Around midday two more deposits of $740,000 and $508,000 arrived at two other addresses. These are not small investors losing a few hundred dollars. These are wallets in which people kept their savings.

Warehouse with stacked small product boxes, one box lies open on the packing table The trail leads to devices sold through a reseller in Southeast Asia.

At 13:32 UTC, Ledger responded through its support account. The company said it is investigating reports of losses among users in Southeast Asia who bought products from CryptoBilis. As a precaution it has asked the reseller to pause all sales and shipments of Ledger devices. Anyone who bought there in the past 90 days and has not set up the device yet should not do so. Anyone who already has should move their assets to a new Ledger device with a new seed phrase.

What the statement leaves out is telling: a number, a cause and the word hack. Ledger neither confirms the $86 million nor explains how the seeds ended up in someone else's hands. Neither the total nor the cause has been independently confirmed so far. The only established facts are the halt at the reseller and the advice to its customers.

Time (UTC) What happened from approx. 06:00 Ten USDT transfers of $0.5M to $2.4M arrive at the Tron collection address TBkcU 12:24 Specter publishes ten collection addresses and cites more than $86M 13:32 Ledger confirms its investigation and halts the reseller CryptoBilis 14:01 Binance founder Changpeng Zhao calls it a supply chain attack at one vendor afternoon MistTrack cites almost $90M, Tether freezes linked USDT addresses from 15:37 Mark Karpelès describes a spy implant inside the device that passes the genuine check

Part of the loot may still be frozen. According to MistTrack, stablecoin issuer Tether has already frozen USDT on addresses linked to the thefts. How much is affected is unclear. There is no such lever for Bitcoin and Ether: once funds have left, only an exchange can still stop them when the thief tries to cash out.

Update 16:30 UTC: The attacker has started laundering. According to Onchain Lens, 430.2 ETH, roughly $1.07 million, went into the Tornado Cash mixer across four wallets. Following Tether's freezes, the attacker is also swapping USDT into USDD, a Tron stablecoin that Tether cannot freeze. The longer this goes on, the smaller the share of the loot that can still be recovered.

How the Wallets Were Emptied: The Implant Inside the Device

The most concrete explanation so far comes from a man the crypto world knows from a very different context: Mark Karpelès, former head of the Mt. Gox exchange that collapsed in 2014. Karpelès has been examining tampered Ledger devices for weeks and had already shown photos of a modified Nano X in September. On Friday afternoon he put the new cases into context in a series of posts. His description: an extra chip sits inside the casing, reads what appears on the screen, records the seed phrase at the moment the device displays it for you to write down, and transmits it.

The dangerous part: according to Karpelès, such a device passes Ledger's genuine check. The actual secure element is real, it generates the seed correctly and signs properly. It is simply being watched. In his words, the only way to detect the implant is to open the device. Earlier versions gave themselves away with sloppy shrink wrap, the new one is far better made and hidden under the display. The most obvious tell is an antenna cable that looks clearly out of place inside. Ledger has a support page with photos of what the inside of a genuine device should look like, and Karpelès is asking CryptoBilis buyers to open their device and share pictures.

One detail from his posts should alarm anyone who orders hardware wallets online. His own test device had struck him as suspicious because it was listed on Amazon at half price and shipped from Malaysia instead of Japan, where he had ordered it. The origin was the warning sign before he ever opened the case.

Whether every case goes back to an implant is still open. The developer 0xQuit considers it just as possible that some victims fell for phishing, and calls it irresponsible to speak of a Ledger hack. At the same time, security researcher CyberScrilla is warning about a fake Ledger site that ranked at the top of Google Search and, by his account, had more than a million visits in 30 days. It asks for the seed phrase. There is no confirmed link to the $86 million, but the rule applies regardless: a seed phrase never belongs in a website or an app.

It is just as important to understand what this attack is not. It is not a firmware bug like at Coldcard, where a predictable random number generator gave away the seeds. It is not an attack on Ledger's servers and not remote access to every device worldwide. It is an attack on the path a device takes from the factory to you. That is also where the reseller comes in. Whether CryptoBilis itself introduced tampered devices, whether there was an offender in its warehouse, or whether the reseller was itself supplied with counterfeit goods is not known. So far Ledger has only halted sales and has made no accusation.

Blank seed sheet next to a steel backup plate and a hardware wallet in its original packaging The only protection is a device straight from the manufacturer and a seed you create on it yourself.

Ledger in Second Place: Hardware Wallet Incidents of 2026 Compared

How big is this case by comparison? In the afternoon, the on-chain service Chain INK compiled all hardware wallet incidents of the year in one list. Only two of them have demonstrably cost customers money so far: Coldcard and now CryptoBilis. Coldcard is still ahead in total losses at $111 million, and other counts put it as high as $130 million. Less than a day in, the Ledger case already ranks second at $87 million, and the count is still running.

Bar chart: Coldcard $111M across 5,200 wallets, about $21,000 per wallet; CryptoBilis $87M across 98 wallets, about $888,000 per wallet Coldcard cost more money in total, the Ledger case hit fewer but much larger wallets.

The real difference lies in the second number. At Coldcard, the damage was spread across more than 5,200 wallets, around $21,000 per wallet on average. At CryptoBilis, Chain INK counts 98 wallets, which would mean almost $890,000 on average. Even if Specter's estimate of several hundred victim wallets is confirmed, the average remains many times higher than in the Coldcard case. That fits the pattern of an implant: the attacker knows every seed created on the tampered devices and strikes selectively where it pays off.

Table of hardware wallet incidents in 2026: CryptoBilis $87M across 98 wallets, Coldcard $111M across 5,200 wallets, data leaks at SafePal, Trezor and Ledger without funds lost Six customer-facing incidents this year, two of them with losses in the millions.

Three more entries on the list are left out of the table because they did not hit any customers: two lab attacks using a laser on the chip, at Tangem and on the Trezor Safe 7, and a BitBox02 flaw the manufacturer found and fixed in its own audit. The common thread of the table is a different one. Five of the six incidents did not come through the device but through third parties: a reseller, a fulfilment provider, a shop plug-in, an email provider, a sales partner. On top of that come fake letters with QR codes that have been sent to wallet owners for months. Chain INK sums it up: nobody had to crack a seed phrase this year.

Ledger and the Supply Chain: Not a New Problem

The attack route is not new. In December 2020, unknown actors published the names, postal addresses and phone numbers of around 270,000 Ledger customers from a data breach in the summer of 2020. In spring 2021, customers then received supposed replacement devices by post with a letter from "Ledger". Anyone who opened one found an extra memory chip soldered on. In December 2023 it was the software's turn: a tampered update of the Ledger Connect Kit library redirected wallet connections on numerous DeFi sites for several hours. Tether froze part of the loot back then as well. And in May 2023, the Ledger Recover service, which lets users store encrypted parts of their seed with third parties, cost the company a great deal of trust within its own community.

Each of these cases had a different cause. What they have in common is that the core never failed, meaning the secure element, but everything around it did: customer data, software suppliers, distribution channels. For Ledger, that is more uncomfortable than a firmware bug. A bug in the code can be fixed with an update. A reseller network in which an official partner can ship tampered devices cannot be repaired with an update. How Ledger supervises its authorised resellers is a question the company will have to answer in the coming days.

What CZ Advises, and Why the Tip Does Not Help Here

The most prominent comment of the day came from Binance founder Changpeng Zhao, better known as CZ. At 14:01 UTC he wrote that, based on the information so far, it appears to be a supply chain attack at a single vendor, and that a small number of people probably bought fake or tampered Ledgers. In a second post he offered a security tip: leave a new hardware wallet for a couple of weeks before moving any meaningful amount to it, and follow the news during that time.

That sounds sensible but does nothing against this particular attack. An implant that captures the seed phrase during setup knows your wallet from day one. The attacker has no reason to sweep a $50 test transfer and give himself away. He waits until the wallet is worth it. If you test small amounts for two weeks and then move your savings over, you have gained nothing. The only protection is a device that verifiably came straight from the manufacturer.

Then there is the question of who is handing out advice on safe custody. In November 2023, Zhao pleaded guilty in the United States to failing to maintain an effective anti-money-laundering programme at Binance, a violation of the Bank Secrecy Act. He stepped down as CEO of the exchange and paid a $50 million fine, while Binance itself settled with US authorities for $4.3 billion. In 2024 he served four months in prison, and in October 2025 US President Donald Trump pardoned him. Zhao was not charged with fraud. Still, the founder of the largest centralised exchange, a business built on third-party custody, giving self-custody advice is a bold move.

Bought a Ledger? Here Is What You Should Do Now

Whether you need to act depends almost entirely on where your device came from. Go through the following points in order.

Bought from CryptoBilis in the past 90 days, not yet set up: Do not switch it on, do not set it up. Ledger explicitly advises against it. Keep the device, packaging and receipt, and contact Ledger through its official support page.

Bought from CryptoBilis and already set up: Treat your seed phrase as known. Buy a new device directly from the manufacturer, create a new seed on it and move all your coins, and do it now, not after the investigation. Adding a passphrase on the old device is not enough if the implant reads whatever appears on the screen.

Bought on a marketplace, second-hand or at a suspicious discount: The same risk applies, even without CryptoBilis. If you bought through Amazon, eBay, Shopee, Lazada or classified ads, you do not know which route the device took. The same advice applies as above, at least for larger amounts.

Bought directly from Ledger: As things stand, there is no indication that devices from the Ledger shop are affected. Still, check that your device generated a new seed on first start and that no pre-printed recovery card with words was included in the box. A seed you did not create on the device yourself is never yours alone.

Already lost funds: Save the transaction hashes and the address the funds went to, contact SEAL 911 and file a police report. If USDT was lost, also notify Tether through its support, because Tether can freeze balances on attacker addresses as long as they remain there. The faster you act, the better your chances.

If you hold larger sums, consider a multisig setup, meaning a wallet that needs two or three devices from different manufacturers to sign. A single tampered device is then no longer enough for a theft. Which devices are suitable and where to get them directly from the manufacturer is shown in our hardware wallet comparison. After the Coldcard case we also explained in detail which hardware wallet you can still buy with a clear conscience.

Why We Do Not Ship Hardware Wallets

This case shows why the distribution route matters as much as the device. CryptoTicker does not sell or ship hardware wallets. Our comparisons and product pages describe the devices, and the purchase happens with the provider. For Ledger, OneKey and Tangem, the buy button leads directly to the manufacturer's official shop, so the device goes from the manufacturer to you without any stop in between. After today, exactly this route, with no third-party warehouse in between, is the most important property when buying a hardware wallet. A discount of a few dollars at a middleman is no compensation for the risk that someone opened the case before you.

What You Should Take Away From the Ledger Case

Two of the best-known hardware wallets in two months, both times damage in the region of $100 million, and both times the failure was not where the marketing promises security. At Coldcard it was randomness, at Ledger, as things stand, it is the route from the factory to the customer. None of this is an argument against self-custody. On an exchange your funds would face entirely different risks. What follows is that a hardware wallet is only as secure as its origin and the moment the seed is created.

Three rules remain. Only buy directly from the manufacturer. Always create the seed yourself and never accept one that was already in the box. And spread large holdings so that a single device cannot give everything away. Ledger has promised updates on its investigation. We will update this article as soon as the cause and the size of the losses are confirmed.