Ledger halts Malaysian reseller after $86 million in suspected wallet losses
Ledger halted Southeast Asian reseller sales after reports that buyers lost $86 million from hardware wallets, but the company has not confirmed the figure or explained whether devices were tampered with. For institutional custody and portfolio managers, this incident underscores supply chain risks beyond official channels and parallels a 2024 case involving counterfeit units engineered to steal seed phrases at scale.
- Ledger asked CryptoBilis, a Malaysian reseller operating in Southeast Asia, to pause all sales and shipments after loss reports surfaced Friday (October 9).
- Analyst Specter traced suspected losses to hundreds of victim wallets across Ethereum, TRON and Bitcoin, with about 211 BTC in tracked addresses remaining stationary as of 13:44 UTC Friday.
- The incident echoes a 2024 supply chain attack involving fake Ledger devices with replaced security chips that transmitted PINs and seed phrases to attacker servers.
- $86M Estimated losses from CryptoBilis device sales, per analyst Specter
- 211 BTC Combined holdings in three Bitcoin addresses Specter identified
- 90 days Timeframe for affected purchases Ledger warned to move funds
Ledger told buyers who purchased from CryptoBilis within the past 90 days not to initialize their devices, and instructed those who had already done so to transfer funds to a new device with a fresh seed phrase. The pause, announced by Ledger Support on Friday, covered only this single Southeast Asian reseller. Ledger has not disclosed whether the devices themselves were altered, how funds left wallets, or whether the $86 million figure reflects confirmed losses or suspected activity on blockchain ledgers.
Counterfeit devices with swapped security chips preceded this incident
In April, a cybersecurity researcher documented counterfeit Ledger hardware wallets sold through a Chinese marketplace that sent PINs and seed phrases to attackers. The fake devices spoofed Ledger’s firmware to version 2.1, a release that does not exist in Ledger’s official lineup, and transmitted every PIN and seed phrase entered on the device to attacker-controlled servers in plaintext.
Ledger’s Genuine Check passed legitimate devices but CryptoBilis purchases remain unverified
Ledger’s built-in cryptographic Genuine Check successfully identifies counterfeit hardware when run through the legitimate Ledger Live application downloaded from ledger.com. However, the 2024 counterfeit operation used a cloned phishing website and trojanized app that always returned a false positive result, ensuring victims never received a warning signal.
The current CryptoBilis situation leaves open whether devices were altered before shipment, whether buyers received legitimate hardware sold through an unauthorized channel, or whether the drain involved a separate attack vector such as supply chain interception or compromised firmware during distribution.
Ledger said it will share updates as its investigation progresses, but has not specified a timeline for conclusions or whether it will release a forensic analysis of affected units.
The CCS read. Institutional holders should assume that any hardware wallet purchased outside official channels or verified resellers carries elevated risk of tampering or firmware compromise. The CryptoBilis case expands the attack surface beyond direct counterfeit manufacturing to include legitimate resellers whose fulfillment or warehousing may have been breached. Custody providers and portfolio managers relying on self-hosted cold storage should audit procurement policies and confirm device provenance.
Ledger has not announced a public audit of CryptoBilis’s supply chain, a recall mechanism for affected buyers, or an API-level defense to flag devices with suspicious transaction patterns. Institutional users should watch for Ledger’s investigation conclusion, for which no timeline has been specified, and any guidance on whether the losses resulted from hardware tampering, firmware compromise, or operational failure by the reseller itself.
Original reporting: beincrypto.com