BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Ledger investigates $86 million crypto theft linked to suspected fake wallets

Ledger has launched an investigation after more than $86 million in cryptocurrency holdings reportedly disappeared from customers who acquired hardware wallets through Southeast Asian reselle

AnonymousCryptoCompass newsroom
October 9, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

Ledger has launched an investigation after more than $86 million in cryptocurrency holdings reportedly disappeared from customers who acquired hardware wallets through Southeast Asian reseller CryptoBilis. The devices at the center of the incident are suspected to be counterfeit or tampered with before delivery to users.

Investigating the source of losses

Ledger instructed CryptoBilis to halt all sales and shipments while it works to determine how the breach occurred. The company emphasized that the investigation remains ongoing.

On-chain analyst Specter traced the movement of stolen funds across three major blockchain networks: Bitcoin, Ethereum, and TRON. Specter uncovered deposits from hundreds of victim wallets, pointing to a coordinated scheme likely targeting these specific devices.

The evidence suggests the incident may stem from a supply chain attack limited to a single reseller, rather than indicating a widespread security flaw in Ledger’s hardware. Binance founder Changpeng Zhao, known as CZ, underscored this perspective and issued a warning to customers who recently acquired Ledger devices.

Reports indicate theft addresses received inflows from hundreds of victim wallets across Ethereum, TRON, and Bitcoin, highlighting a significant breach affecting multiple blockchains.

How fake hardware wallets expose user funds

Hardware wallets are designed to protect users’ assets by keeping private keys offline and away from internet-based threats. This safety is effective only if the devices themselves are genuine and have not been compromised during the supply chain process.

If attackers distribute counterfeit or manipulated devices through a reseller, they may gain access to users’ funds as soon as the devices are initialized, bypassing the standard protections of hardware wallets.

The specifics of how these tampered wallets enabled theft have not yet been disclosed. Ledger is reviewing each affected product to determine the exact fraud techniques used.

Identified theft addresses began with familiar prefixes: Bitcoin addresses starting with “bc1q”, TRON addresses with “T”, and Ethereum addresses with “0x”. This pattern demonstrates the cross-chain nature of the incident and suggests the attackers targeted a broad swath of assets.

While over $86 million in losses have been reported, complete details on the number of affected victims, asset distribution by blockchain, and any recovery efforts remain pending.

Guidance for Ledger users and security measures

Ledger’s move to pause CryptoBilis sales is a precautionary step while it clarifies the scope of the breach. The action does not mean that all Ledger hardware wallets are affected or insecure.

CZ described the available evidence as consistent with a targeted supply chain attack affecting one specific vendor, suggesting that only a restricted group of users is at risk.

CZ warned, “If you use a Ledger hardware wallet, especially if you bought one recently, exercise caution. Based on what we know, the attack seems confined to a specific supplier, with some people likely buying fake or altered devices.”

The incident draws attention to the risks posed not only by software exploits or exchange breaches but also by physical tampering of hardware devices before they ever reach consumers. Purchasing wallets from trusted, official sales channels remains crucial for asset security.

Users should always follow manufacturer instructions for verifying the authenticity of new wallets and setting up their devices. Those who suspect their wallets may have been compromised are advised to avoid entering recovery phrases into unverified software and to transfer funds only after confirming device authenticity.

The response to this event highlights the critical role of blockchain analytics in tracking stolen funds and providing leads for investigations. Specter’s analysis of addresses tied to the thefts demonstrates how tracking remains possible even when funds are moved across multiple chains.

In an environment where shifts like Federal Reserve rate decisions or sudden altcoin listings can have rapid impacts, investors are increasingly opting for privacy-focused, streamlined platforms. With tools like CryptoAppsy, traders can view real-time charts, set custom price alerts, monitor coin-specific headlines, and access crucial macro data—all on a single interface without creating an account. This approach cuts down on time, minimizes the need to juggle multiple apps, and can help users avoid unnecessary portfolio losses.

The ongoing investigation aims to determine how the devices were compromised, the total extent of affected users, the total losses by chain, and the possibility of asset recovery. Industry stakeholders are expected to assist in tracking and potentially freezing stolen funds.

The post Ledger investigates $86 million crypto theft linked to suspected fake wallets appeared first on COINTURK NEWS.