Ledger is investigating a major cluster of wallet drains affecting customers in Southeast Asia who purchased hardware wallets from reseller CryptoBilis, with the latest onchain estimate placi
Ledger is investigating a major cluster of wallet drains affecting customers in Southeast Asia who purchased hardware wallets from reseller CryptoBilis, with the latest onchain estimate placing suspected losses at $92.9 million.
The company asked CryptoBilis to stop all Ledger sales and shipments on October 9 while the investigation continues. Anyone who purchased a device from the reseller during the previous 90 days and has not initialized it should not begin setup. Customers already using one of the devices were advised to consider moving their assets to a new Ledger signer generated with an entirely new recovery seed.
Ledger later said the reports identified so far were limited to devices distributed through CryptoBilis and that it had no indication its security infrastructure, systems or services had been compromised.
The company has not confirmed the amount stolen, the number of victims or the mechanism used to gain access to their wallets.
CryptoBilis Changed Ownership Months Before the Drains
CryptoBilis was acquired earlier in 2026, former co-founder Arravind Prabu confirmed after the wallet-drain investigation began. Prabu said the former owners fully stepped down from operations, system access and management after the acquisition and no longer operate CryptoBilis.
The transaction was completed in March, while Malaysian corporate records published during the investigation show an individual identified as Jiaming, with a registered address in Heilongjiang, China, holding 100% of CryptoBilis shares as of August 3.
Security researcher Quit said the acquisition included a non-disclosure agreement that prevented the previous owners from publicly revealing the sale, with the restriction due to expire on October 19. He raised the possibility that the acquisition could have been carried out by a sophisticated threat actor seeking access to an established authorized reseller rather than the incident originating from a rogue employee.
That remains an investigative theory. No public evidence has established that the new owner acquired CryptoBilis to compromise Ledger devices, participated in the wallet drains or had any connection to the attacker-controlled addresses. The timing nevertheless places the change of ownership months before the affected devices were sold and before the coordinated drains began.
Onchain Estimate Reaches $92.9 Million
Suspected losses have expanded beyond the initial estimates of $72 million to $86 million as investigators identified additional affected addresses and networks.
A detailed Bitquery reconstruction of the drain identified $92.9 million taken from 311 wallets across Tron, Bitcoin, Ethereum, BNB Chain and Polygon.
The largest losses were concentrated on Tron, where approximately $70.5 million was removed. Bitcoin wallets lost about 203.8 BTC worth $16.8 million, while Ethereum, BNB Chain and Polygon accounted for the remaining funds.
The transaction timing points to centralized control over the affected private keys. Twenty-five Tron wallets authorized the same spender within three seconds, and 111 Bitcoin wallets were emptied within a single block. Bitquery also traced 41 small test transactions across Tron and Ethereum during the two weeks preceding the main drain.
That pattern does not establish how the private keys were obtained, but it differs from individual victims independently approving malicious transactions over an extended period.
Tether subsequently froze approximately $10 million in USDT across 20 addresses connected to the activity. Another 15.1 million USDD remained in attacker-controlled wallets, while 1,254 ETH was sent through Tornado Cash later on October 9. Roughly $79 million remained traceable at the latest analysis.
Physical Implant Raises Supply Chain Questions
A possible hardware-based attack route is also under examination.
Former Mt. Gox CEO Mark Karpelès opened a Ledger device obtained from Malaysia and reported finding a concealed electronic implant positioned where screen padding would normally sit.
Karpelès said the modified device retained convincing packaging and that the implant was difficult to spot even after the case was opened. His analysis indicated the additional hardware could monitor information displayed during setup and transmit recovery phrase data externally.
No public evidence has yet established that the device inspected by Karpelès came from CryptoBilis or that the same modification caused the $92.9 million drain. Ledger has also not confirmed a supply-chain attack.
The technique resembles risks exposed earlier this year when a counterfeit Ledger containing hidden hardware was found capable of targeting recovery phrases and PIN information.
The current case is also distinct from the Coldcard wallet drains earlier in 2026, where investigators traced the losses to weak seed generation in affected firmware rather than reseller-level hardware modification.
Ledger’s warning currently applies specifically to customers who purchased devices from CryptoBilis within the last 90 days. Users who already initialized one of those devices need a new signer and newly generated seed, rather than simply moving the existing recovery phrase onto another hardware wallet.
The post Ledger Probes CryptoBilis Wallet Drains as Estimated Losses Reach $92.9 Million appeared first on Crypto Adventure.