A supply-chain attack linked to Southeast Asian reseller CryptoBilis drained roughly $92.9 million from Ledger hardware wallet users across Bitcoin, Ethereum, TRON, and three additional block
A supply-chain attack linked to Southeast Asian reseller CryptoBilis drained roughly $92.9 million from Ledger hardware wallet users across Bitcoin, Ethereum, TRON, and three additional blockchains, in one of the most geographically targeted hardware-wallet incidents on record. Ledger paused sales and shipments through the reseller while its investigation remains open, and on-chain analysis from Bitquery has since traced the full scope of the damage.
Ledger Support announced on October 9, 2026, that it was investigating reports of fund losses from users in South East Asia who had purchased devices through a reseller named CryptoBillis. As a precaution, Ledger asked the reseller to pause all sales and shipments and advised recent buyers not to initialize new devices or, if already initialized, to migrate assets to a wallet secured by a freshly generated seed phrase. For related coverage, see Bulgaria Investment Bank to Offer Bitcoin and Crypto Assets to 1M+ Customers.
On-chain analytics firm Bitquery counted $93.2M taken from 315 wallets across TRON, Bitcoin, Ethereum, Solana, BNB Chain, and Polygon — a slightly higher figure than the $92.9M cited in initial reporting, which covered only five of the six chains.
Total traced loss
$93.2M
Across 315 wallets on six networks, according to Bitquery.
Timeline of the wallet drain
Bitquery's analysis identified roughly two weeks of low-value test transactions preceding the main drain event, a pattern consistent with an attacker probing wallet responsiveness before executing the full sweep. The operational precision extended to TRON: 25 TRON wallets signed identical approvals within a three-second window, indicating automated, coordinated execution rather than manual access.
How the reported losses are distributed by chain
TRON bore by far the largest share of losses. Bitquery attributed roughly $70.5M of the total to TRON, followed by $16.8M (203.8 BTC) on Bitcoin, $3.68M on Ethereum, $1.45M on BNB Chain, $0.58M on Polygon, and $0.25M on Solana.
TRON victim loss
$70.5M
The largest chain-level amount in Bitquery's six-network table.
The TRON dominance is notable: TRON hosts a large share of USDT in Southeast Asia, which aligns with the reported geographic concentration of victims. At press time, Bitcoin traded at $83,043, up roughly 0.49% on the day, suggesting the incident has not yet triggered measurable market-wide panic — consistent with the Fear & Greed Index reading of 64 (Greed) at the time of writing.
Why the Ledger connection matters for crypto users
This incident is not evidence that every Ledger device is compromised. The available evidence points to a localized supply-chain attack through a single reseller rather than a flaw in Ledger's core firmware or secure element. Changpeng Zhao characterized it on X as what appeared to be "a supply chain attack with one vendor," explicitly framing it as a preliminary assessment rather than a confirmed finding by Ledger.
Whether the attack vector was pre-seeded devices (where seed phrases were known to the attacker before shipping), tampered firmware, or a compromised initialization flow has not been confirmed by Ledger. Until the forensic investigation concludes, all three remain plausible, and no single causal claim should be treated as established fact.
What Ledger users should check now
Users who purchased a Ledger through CryptoBilis or any unverified Southeast Asian reseller should treat their current seed phrase as potentially compromised. The safest course is to move assets to a wallet generated on a separate, verified device with a brand-new seed phrase — not to restore the existing seed on a new device. Ledger's official guidance issued via its support account reflects this approach.
Users who purchased directly from Ledger's official store or established authorized resellers and have no connection to CryptoBilis have no specific action required at this stage, though routine hygiene — verifying device authenticity and the integrity of the recovery phrase booklet — is always appropriate. Supply-chain risk is a broader concern in hardware security; readers tracking institutional crypto custody developments may also find relevant context in how DBS and Citi approached ledger-level trust in a recent Swift digital payment test.
Red flags for phishing, malicious approvals, and address substitution
The three-second coordinated approval signature across 25 TRON wallets indicates the attacker held pre-existing signing capability — not that victims were tricked in real time. This rules out a standard phishing flow and points instead to a scenario where seed phrases or private keys were extracted before or during device setup. Separately, Bitquery traced 1,254 ETH routed through Tornado Cash and Zcash, with proceeds ending in wallets including one holding $2.1M USDC, a fund-obfuscation path typical of sophisticated actors seeking to break the on-chain trail.
What happens next in the investigation
Tether's response has already created one partial recovery lever: the stablecoin issuer froze $10.0M USDT across 20 wallets identified in the flow. That represents roughly 10.7% of the total traced amount — meaningful, but leaving the vast majority of funds still in motion or obscured through privacy tools.
The cross-chain nature of the drain makes full attribution difficult. TRON-based USDT moves quickly and often ends at offshore exchanges with limited KYC enforcement. The Bitcoin portion (203.8 BTC) is traceable on-chain but has not been publicly linked to identified exchange deposit addresses. The Ethereum funds that passed through Tornado Cash complicate recovery further, as mixing breaks the direct transaction graph. Readers following the DOJ's ongoing review of Binance's compliance with its 2023 settlement will recognize the broader regulatory pressure on exchanges to flag and freeze wallets tied to known hacks — that infrastructure may matter here as tracing efforts mature.
Verified updates will flow through Ledger's official support channels and on-chain analysis platforms tracking the identified attacker wallets. Anyone approached by a third party claiming to offer asset recovery should treat the contact as a scam; unsolicited recovery services targeting hack victims are a well-documented secondary fraud vector. The investigation's forensic findings, once published, will be the authoritative record — no earlier speculation, including CZ's preliminary assessment, should be treated as a conclusion.
The incident arrives as the broader crypto market registers a macro environment that CoinShares has flagged as increasingly bond-driven rather than rate-driven for Bitcoin, meaning sentiment around hardware security could have outsized behavioral effects on self-custody adoption at a moment when institutional interest is rising. Hardware wallet security incidents of this scale are rare; how Ledger's investigation resolves will shape industry standards for reseller verification and device authentication for years ahead.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Read original article on tokentopnews.com