Ledger is investigating reports that over $86 million in cryptocurrency has been stolen from users who purchased hardware wallets through Southeast Asian reseller CryptoBilis. Onchain investigator Specter traced the theft across Bitcoin, Ethereum, and Tron. Concurrently, former Mt. Gox CEO Mark Karpelès released photos of a Malaysian Ledger device allegedly containing a hidden physical LTE implant. Ledger has halted CryptoBilis sales and warned recent buyers not to initialize their devices.
Ledger's response to CryptoBilis reports
- ▪Ledger advised customers who purchased devices from CryptoBilis within the past 90 days not to begin setting up or initializing their hardware wallets
- ▪Ledger advised customers who already activated Ledger wallets purchased from CryptoBilis to consider transferring their assets to a new device with a newly generated recovery phrase
- ▪Ledger requested that Southeast Asian reseller CryptoBilis pause all sales and shipments of Ledger devices while its investigation into fund losses reported by CryptoBilis buyers is ongoing
- ▪Ledger announced on October 9, 2026, that it is investigating reports of cryptocurrency losses from users in Southeast Asia who purchased hardware wallets from reseller CryptoBilis
Onchain analysis of stolen funds
- ▪Onchain researcher tanuki42 estimated that more than $72 million had moved to a group of suspected theft addresses linked to CryptoBilis and requested that users affected by the CryptoBilis-linked theft contact crypto security response group SEAL 911
- ▪Arkham data shared by blockchain investigator Specter showed nearly $87 million (estimated at over $86 million) stolen from hundreds of Bitcoin, Ethereum, and Tron wallets, including approximately $42 million ETH, $17.6 million BTC, and $16.5 million USDT
Mark Karpelès' hardware tampering investigation
- ▪Former Mt. Gox CEO Mark Karpelès posted photos on October 9, 2026, of a Ledger device purchased in Malaysia that allegedly contained a hidden physical implant behind the screen padding
- ▪The physical implant Mark Karpelès described in a Malaysian Ledger device allegedly contained LTE components, an antenna, an eSIM, and a microcontroller wired to the Ledger device's SPI bus to transmit display data over cellular networks
Changpeng Zhao's statements on the attack
- ▪Binance co-founder Changpeng Zhao stated that available information suggested a supply chain attack involving one vendor, and called on BNB ecosystem players to help trace and recover funds reported stolen from CryptoBilis buyers
- ▪Binance co-founder Changpeng Zhao stated that a small number of users may have purchased fake or tampered Ledger devices
Debatable claims
- ▪Ledger's hardware design is inadequate because it fails to detect physical screen-reading implants
- ▪The risk of supply chain attacks makes hardware self-custody too dangerous for average investors
- ▪Hardware wallet manufacturers should eliminate third-party retail networks to prevent supply chain tampering
- ▪Ledger bears responsibility for losses caused by tampered devices sold through its authorized resellers
Story comments
Loading comments…