In Brief: Ledger is investigating reported cryptocurrency thefts exceeding $86 million and has instructed Southeast Asian reseller CryptoBilis to suspend device sales. Blockchain researchers
In Brief:
- Ledger is investigating reported cryptocurrency thefts exceeding $86 million and has instructed Southeast Asian reseller CryptoBilis to suspend device sales.
- Blockchain researchers traced suspicious transactions across three networks, while former Mt. Gox CEO Mark Karpelès investigates possible malicious hardware implants.
- Binance founder Changpeng Zhao warned about potential supply chain attacks, while Ledger advised affected customers to consider transferring their assets.
More than $86 million in cryptocurrency has reportedly been stolen from Ledger wallet users, raising concerns about a possible supply chain attack involving compromised hardware devices. According to Ledger Support, the company is investigating reports of stolen funds involving customers who purchased hardware wallets from CryptoBilis, a reseller operating in Southeast Asia.
Ledger Orders CryptoBilis to Suspend Device Sales
Ledger has issued precautionary instructions to customers who purchased devices through CryptoBilis as it investigates the reported cryptocurrency thefts. According to the company’s announcement, customers who purchased devices from the reseller within the previous 90 days should avoid activating unconfigured wallets.
Also Read: Visa and ADI Foundation Explore Blockchain Links for Global Payment Networks
Customers who already initialized their devices were advised to consider transferring their cryptocurrency holdings to new Ledger signers with different recovery phrases. The company also directed affected customers to its official support channels for assistance and further information regarding the investigation.
Researchers Trace Over $86 Million Across Multiple Blockchains
Blockchain researchers have identified suspicious cryptocurrency transactions involving hundreds of wallets, providing additional details about the scale of the reported thefts. According to blockchain investigator Specter’s October 9 analysis, ten suspicious addresses received more than $86 million across Bitcoin, Ethereum, and TRON networks.
The researcher found that the identified addresses held approximately $25 million during the latest assessment, indicating substantial funds had already moved elsewhere. Another investigator, tanuki42, previously identified eight suspicious addresses and estimated losses exceeding $72 million from the reported incidents.
Specter’s subsequent findings included those eight addresses alongside two additional Bitcoin addresses, expanding the number of addresses associated with the suspected thefts. Security Alliance also urged affected cryptocurrency holders to contact its SEAL 911 service for assistance with tracing stolen assets and reporting suspicious transactions.
The investigation has also drawn attention to potential hardware tampering, with former Mt. Gox CEO Mark Karpelès examining whether malicious components were installed inside Ledger devices. According to Karpelès, he is investigating whether attackers physically modified Ledger hardware wallets before distributing them to customers.
He requested photographs of affected devices’ internal circuit boards to determine whether unauthorized components had been installed alongside legitimate hardware. His investigation also highlighted limitations in Ledger’s Genuine Check feature, which verifies device authenticity through its security architecture.
Ledger’s documentation acknowledges that its verification process cannot identify certain unauthorized physical modifications when the original Secure Element remains intact. Karpelès has not confirmed the presence of malicious implants in affected devices, leaving the suspected supply chain attack unverified.
Binance Founder CZ Raises Supply Chain Security Concerns
Binance founder Changpeng Zhao also addressed the reported thefts, suggesting that compromised devices distributed through a single reseller could explain the incidents. According to Zhao, preliminary information points toward a possible supply chain attack involving counterfeit or tampered hardware wallets.
He emphasized Ledger’s established security record while acknowledging that hardware devices remain vulnerable to interference during distribution. Zhao recommended that cryptocurrency holders exercise caution when purchasing wallets and avoid transferring substantial funds immediately upon receiving new devices.
Changpeng Zhao expressed confidence that blockchain industry participants would assist investigators in tracing stolen cryptocurrency and supporting potential recovery efforts.
What This Means for Ledger Users
The unresolved attack method has left Ledger customers facing uncertainty over whether the reported thefts involved compromised hardware, malicious applications, or phishing attacks. Users should verify wallet software sources, avoid entering recovery phrases into computers or mobile devices, and carefully examine transactions before authorization.
If investigators identify compromised third-party applications or phishing schemes, stronger software verification and recovery phrase protection could help prevent similar incidents. A confirmed hardware or firmware vulnerability could require security updates or migration to newly configured devices with different recovery phrases.
Researchers are also monitoring suspicious cryptocurrency addresses, including one reportedly holding 211 BTC, for further movements linked to the suspected thefts. The estimated $86 million loss remains independently reported rather than officially confirmed by Ledger, while additional victim reports could change the figure.
Ledger’s investigation remains ongoing, with the attack method, number of affected customers, and total confirmed financial losses still undetermined.
Also Read: Nasdaq CEO Says Tokenization Could Unlock Billions in Global Collateral
The post What We Know About the $86 Million Ledger Drain So Far appeared first on 36Crypto.