BackLedger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller
Ledger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller
Urgent
Decrypt1 hour agoCrypto2 min read

Ledger Probes Potential Theft of $87M in User Funds Tied to Crypto Wallet Reseller

Company advises customers who purchased from the reseller to pause device setup amid reports of missing assets.

Quick Look

  • Ledger is investigating reports of fund losses among Southeast Asian users who purchased hardware wallets from reseller CryptoBilis.
  • The company has paused the reseller's operations, while investigators estimate potential losses exceeding $86 million.

AI-generated summary

Why It Matters

Hardware wallets are designed to keep private keys offline, but devices compromised before reaching the buyer can leave funds exposed.

Font size

Ledger is telling some customers to hold off on setting up their hardware wallets.

The Paris-based wallet maker said Friday it is investigating reports that users in Southeast Asia who bought devices from a reseller called CryptoBilis have lost funds.

“As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices,” the company’s support account wrote on X.

Ledger urged anyone who bought from the reseller in the past 90 days not to set up their device if they haven’t already. Those who have should consider moving their assets to a new Ledger signer with a new seed phrase, the master backup that can regenerate a wallet’s private keys.

Ledger didn’t say what caused the losses or how many customers were affected. Hardware wallets are designed to keep private keys offline, but a device compromised before it reaches the buyer, such as one shipped with a recovery phrase an attacker already knows, can leave funds exposed. No tampering has been confirmed.

The losses may be large, potentially in the tens of millions of dollars. Pseudonymous crypto investigator Specter said they traced theft addresses flagged in reports from Ledger users on X and Reddit and found inflows from hundreds of victim wallets across Ethereum, Tron, and Bitcoin.

“Total losses $86M+,” Specter wrote. Arkham data shared by the investigator shows nearly $87 million at those addresses, including about $42 million in ETH, $17.6 million in BTC and $16.5 million in USDT. Ledger hasn’t confirmed the figure, and it’s unclear whether every theft is linked to the reseller.

Rival Trezor has faced its own security headaches, including customer data exposed in a shipping partner breach and a breach of its email just last month.

The episode adds to a brutal stretch for crypto security. Last month, Bitget lost roughly $387 million in a hack that investigators have tied to North Korea, and blockchain tracking firms Chainalysis and Elliptic have since traced part of the haul.

What to Watch

AI outlook — possibilities, not facts

  • Ledger will release findings from its investigation into CryptoBilis.

    Likely · Within weeks

Open Questions

  • What is the exact cause of the fund losses?
  • How many customers were affected?
  • Is every theft linked to the reseller?

Related Topics

This article was originally published by Decrypt.

Related Stories

More on this topicledger