Introduction
Ledger is investigating reports of lost funds from users in Southeast Asia who purchased hardware wallets through a reseller named CryptoBilis. Approximately $71.5 million in cryptocurrency has been flagged as moved from addresses linked to the reseller, prompting urgent warnings for affected buyers.
What Happened
On Friday, Ledger Support announced it had asked CryptoBilis to pause all sales and shipments while reviewing reports of missing funds. Users who bought devices from the reseller in the last 90 days were advised not to complete setup if they haven't already, and to consider moving assets to a new Ledger signer with a fresh seed. Arkham Intelligence's custom entity labeled "ledger-drainer" showed about $71.5 million still sitting in flagged addresses, with the largest balances in ether, bitcoin, USDD, and USDT. The company emphasized it has no indication its own systems were compromised, suggesting a supply chain breach rather than a network hack. The theory gaining attention involves former Mt. Gox CEO Mark Karpelès, who posted photos of a Ledger device he bought in Malaysia, claiming it contained a hidden implant including an antenna, modified battery, and LTE module capable of transmitting seed phrases. Karpelès advised affected buyers to open their devices and share photos, pointing to Ledger's own guide for spotting altered units. This incident follows earlier Ledger-related issues this year, including a payment processor leak in January and a fake Ledger Live app distributed via the Mac App Store in April that cost one musician $424,000 in bitcoin.
Why This Matters
Hardware wallets are widely promoted as the gold standard for self-custody, but this situation highlights the risks when trust is placed in third-party resellers. If a device is compromised before it reaches the user, even an offline hardware wallet can become a vector for remote key extraction. The scope of the alleged breach remains unclear, but the fact that CryptoBilis also sells other major brands—including Trezor, CoolWallet, Tangem, OneKey, Ellipal, and SafePal—raises questions about whether similar supply chain issues could affect those devices. Ledger's own guidance warns against pre-seeded devices, counterfeits, and opened packaging, recommending buyers stick to official channels. For users, this incident serves as a stark reminder that physical device integrity must be verified, and that moving funds promptly is critical when supply chain risks emerge.
Key Takeaways
- Ledger has asked CryptoBilis to pause sales and shipments while investigating $71.5 million in flagged transactions.
- Users who purchased from the reseller in the last 90 days are advised to move assets to a new device with a fresh seed.
- The exact method of compromise is still under investigation, with theories ranging from physical implants to pre-seeded counterfeit units.
- CryptoBilis sells multiple hardware wallet brands, potentially expanding the impact beyond Ledger devices.
- Ledger's guide emphasizes buying only from authorized resellers and verifying device integrity upon arrival.
Conclusion
As the investigation continues, the priority for anyone who bought a Ledger device through CryptoBilis is to assume the device may be compromised and move funds to a new, verified wallet. The situation underscores the broader risk of supply chain attacks in the crypto hardware space and the importance of staying informed about device provenance. Ledger says it will keep customers updated, but for now, vigilance and prompt action remain the best defenses.







Discussion
Join the conversation
Thoughtful reactions, questions, and follow-up ideas help shape the next story.