Newsroom
9 October, 2026 / News / AI / Tags: cryptobilis, ledger, reseller, specter, shipments

Ledger is probing reports of fund losses after users in Southeast Asia who bought hardware wallets from CryptoBilis had their assets drained
Paris-based Ledger has launched an investigation into potential thefts affecting customers who purchased its Nano X and Nano S Plus devices through reseller CryptoBilis. The company has instructed the reseller to immediately pause all sales and shipments of Ledger products.
Ledger reached out to its support channels to advise affected buyers. The firm stated that it is investigating reports of losses among Southeast Asian customers. It has asked CryptoBilis to halt shipments pending the probe’s outcome.
Anyone who bought devices from the reseller in the last 90 days received a direct warning. Ledger told users who have not yet initialized their hardware wallet to avoid setting it up. Those who have already set up their device should move their funds to a new Ledger signer using a freshly generated seed phrase, which serves as the master backup capable of regenerating the private keys.
Pseudonymous blockchain analyst Specter analyzed user reports on X and Reddit and traced funds moving from hundreds of victim wallets. The investigation covers activity on Ethereum, Tron and Bitcoin blockchains.
Specter estimated more than $86 million in total losses at flagged addresses. The breakdown includes roughly $42 million in Ether, $17.6 million in Bitcoin and $16.5 million in USDT. Ledger has not confirmed the scale of the figure or ruled out that every traced wallet belongs to a CryptoBilis purchaser.
One user whose device was purchased about three weeks earlier lost $7 million in USDT in a single theft that occurred roughly 10 hours before the public reports surfaced. The address associated with the incident was labeled TY24Ya.
CryptoBilis maintains presence in Malaysia, Indonesia and the Philippines. Ledger has not yet identified the exact mechanism behind the losses. Hardware wallets are built to keep private keys offline, but a device compromised during the supply chain before reaching the end user could expose funds if the recovery phrase is known to attackers.
Ledger has not disclosed any tampering or confirmed the number of affected customers. The company’s support account posted the latest statement on X early Friday.
The episode comes as the crypto industry continues to navigate security challenges. Ledger has not commented on whether similar incidents affected other resellers or device models. Customers are now being urged to remain vigilant and follow the company’s guidance on resetting their wallets.
| Asset | Amount Traced (USD) |
|---|---|
| Ether (ETH) | ~$42 million |
| Bitcoin (BTC) | ~$17.6 million |
| Tether (USDT) | ~$16.5 million |
Specter’s on-chain data shows inflows into the tracked addresses from multiple victim wallets across the three chains. The largest single loss reported so far stands at $7 million in USDT.
Ledger’s investigation remains active. The company has not yet shared further details on the timeline or any preliminary findings. Users continue to monitor official channels for updates.









