

Ledger CryptoBilis wallet drain reports prompt a sales and shipment pause as Ledger investigates fund losses in Southeast Asia.
Author: Kritika Gupta
9th October 2026- Ledger is investigating reports of lost funds from crypto users in Southeast Asia. The company said that the reports involve buyers of an authorized reseller named CryptoBilis. As a precaution, Ledger CryptoBilis has asked the reseller to pause all sales and shipments of its devices.
High Signal Summary For A Quick Glance
Javier Florentino
@iamflorentinus
@Ledger_Support For the sake of the industry, I hope this issue is limited to the reseller and doesn’t point to a broader vulnerability affecting Ledger users. Either way, it’s heartbreaking for those who lost their funds.
Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices.
03:20 PM·Oct 9, 2026
Michael-G
@MichaelGHash
@Ledger_Support The uncomfortable part: this was reportedly an authorized reseller. Self-custody was supposed to remove trust from the equation, but the supply chain puts it right back in. The cryptography was never the weak link — the chain of custody from factory to doorstep is. Verify before
Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices.
02:32 PM·Oct 9, 2026
Rug.Tools | Crypto Rug Checker
@Rug_tools
@Ledger_Support A hardware wallet is only as secure as its supply chain and seed phrase. This is a serious reminder that buying from a trusted source matters just as much as protecting your private keys. Good to see Ledger investigating and advising affected users to take precautions. The
Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices.
02:28 PM·Oct 9, 2026
High attention and emotional sentiment detected.
The company posted the alert through Ledger Support at 13:32 UTC. Notably, it has not confirmed how the funds moved, how many people lost money, or any dollar total. Independent researchers, meanwhile, had flagged the drains more than an hour earlier.
Ledger kept its statement narrow. First, it confirmed the investigation. The reports involve users in “South East Asia” who bought from the reseller, Ledger said. Next, it asked CryptoBilis to pause sales and shipments while the investigation continues.
The company also gave direct guidance. It told recent buyers from this reseller not to start device setup. That guidance covers purchases made in the last 90 days. In addition, it addressed users who already set up a device. They should consider moving assets to a new Ledger signer with a new seed.
Ledger did not name a device model, a victim count, or an attack method. It also did not single out a country beyond the region. The brand itself is CryptoBilis, with one “l,” though Ledger’s post spelled it both “CryptoBillis” and “CryptoBilis.”
CryptoBilis appears on Ledger’s official reseller page for Indonesia, Malaysia, and the Philippines. According to Philippine outlet BitPinas, CryptoBilis is a regional web3 store that also sells Trezor devices. The reseller had not issued a statement by the time of that report.
On-chain analysts raised the alarm before Ledger posted. At 12:00 UTC, analyst tanuki42 shared a set of theft addresses. The SEAL 911 contributor also asked victims to contact the group. He put the total loss at “more than $72 million and increasing.”
Then, at 12:24 UTC, analyst Specter published ten theft addresses across Ethereum, TRON, and Bitcoin. He estimated total losses above $86 million and said inflows came from “hundreds of victim wallets.” Ledger has not confirmed either figure.
Soon after, Specter walked back part of that claim. At 12:41 UTC he said he could not yet confirm an actual wallet count. So the “hundreds of wallets” line remains an estimate, not a verified tally.
Analysis by Unchained found the ten addresses held only a little over $25 million when checked. That gap suggests most of the funds had already moved elsewhere. Later secondary reports cited about $86.96 million across 98 addresses, though 98 addresses do not equal 98 confirmed victims.
The attack method is still unconfirmed. A hardware wallet does not store coins. Instead, it stores the private keys that authorize transfers.
During setup, a genuine device generates a recovery phrase, usually 24 words, inside its secure chip. Anyone who later knows those words can rebuild the keys on another device. As a result, that person can move the funds without ever touching the original hardware.
So a compromised reseller could, in theory, steal funds in several ways. For example, it could ship a device that is already set up. It could also include a pre-filled backup card, or sell a convincing counterfeit. Each path ends the same way, because the attacker already knows the seed.
Ledger’s own help pages list a clear red flag. A recovery phrase written on a card inside the box is never normal. The device should generate that phrase during first setup, and no one else should ever see it.
Ledger CryptoBilis wallet drain timeline
Users in Southeast Asia report fund losses after purchasing Ledger devices from CryptoBilis. Reports reach Ledger.
Ledger publicly confirms its investigation and asks CryptoBilis to pause all Ledger device sales and shipments.
The attack method remains unconfirmed. Any refund measures or law-enforcement action also remain unconfirmed.
Ledger buyers often rely on the Genuine Check during setup. That test confirms the device contains a real Ledger secure element. However, it does not prove that nobody else knows the seed.
Mt. Gox veteran Mark Karpeles made that point on 9 October. He said a device he examined still passed the check. According to him, the only way to detect a hardware implant, if one exists, is to open the unit.
Binance founder Changpeng Zhao also weighed in. He called the episode a localized supply-chain issue with one vendor. In his view, a small number of people probably bought fake or tampered devices. Still, that reading is his own, not a Ledger finding.
The practical advice follows Ledger’s own guidance. Recent CryptoBilis buyers who have not set up a device should not start now. Instead, they should wait for Ledger to update the investigation.
Those who already set up a device should treat the seed as compromised. The safer move is a new device with a brand-new seed, rather than a restore of the old phrase. Buyers should also never type a recovery phrase into any website, or hand it to anyone claiming to be support.
For now, Ledger has promised further updates as its probe into CryptoBilis continues. Buyers should watch the official Ledger Support channel for any confirmed findings on the vector, the scope, or the losses.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
Ledger Probes User Fund Losses Tied to Reseller CryptoBilis
ZachXBT Infiltrated Lazarus Laundering Ring Behind Bybit Hack
Kelsier Ventures As 1,000 Wallets Fell From $300M to $2M in LIBRA
Base Vault Exploit Drains $6M in wstETH Via Whitelist
Ledger Probes User Fund Losses Tied to Reseller CryptoBilis
ZachXBT Infiltrated Lazarus Laundering Ring Behind Bybit Hack
Kelsier Ventures As 1,000 Wallets Fell From $300M to $2M in LIBRA
Base Vault Exploit Drains $6M in wstETH Via Whitelist