Ledger said on Friday that it is investigating reports of lost funds from users in Southeast Asia who bought devices from CryptoBilis, a reseller the company lists for Indonesia, Malaysia, and the Philippines. In a post on X, Ledger Support said it had asked CryptoBilis to pause all sales and shipments while that review is underway.
“We recommend Ledger users who purchased from this reseller in the last 90 days to not initiate set up if you have not done so yet,” the support account said. “If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed).”
Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices.…
— Ledger Support (@Ledger_Support) October 9, 2026
A later reply from Ledger’s main account went further. “Based on the information available so far, we believe the funds drained are limited to devices sold through a reseller named CryptoBilis in South East Asia,” the company said. “We have no indication that Ledger’s security infrastructure, systems or services have been compromised.”
Ledger has not accused CryptoBilis of tampering with anything, and nothing public has shown that the shop altered devices. A separate party could have interfered with Ledger devices moving through that channel. CryptoBilis had not issued a public statement as of Friday afternoon.
Arkham Intelligence’s unverified custom entity for the case, labeled ledger-drainer, showed about $71.5 million still sitting in flagged addresses on Friday afternoon. The largest balances were about $29.4 million in ether, $17.5 million in bitcoin, $13.6 million in USDD, and $10.8 million in USDT.
This is not the first security issue that has popped up for Ledger users this year. In January, Ledger disclosed that payment processor Global-e had exposed names and contact details for an undisclosed number of Ledger.com buyers. No crypto was taken in that incident, but the leaked records were the sort that makes later phishing and increasingly common physical targeting easier. In April, a musician also lost about $424,000 in bitcoin after downloading a fake Ledger Live app from Apple’s Mac App Store.
A Theory From an Infamous Source
The theory getting the most attention on Friday did not come from Ledger. Former Mt. Gox chief executive Mark Karpelès posted photos of a Ledger he said he bought in Malaysia, with intact shrink wrap and a second board hidden where the screen’s padding is supposed to sit. He described an antenna on a single wire, a shorter battery or a missing screen pad to make room, and an LTE module with a data eSIM. In a later post, he wrote that the microcontroller can recognize the Ledger font on the 128-by-64 display, spot the setup screen, and send the seed phrase as text over LTE. He also wrote that firmware cannot detect the attack, because the implant only listens when the screen refreshes. He has not said the device came from CryptoBilis.
“My spy-implanted ledger came from Malaysia, and had flawless shrink wrap,” Karpelès wrote. “Even opening it, at first you don’t see the implant which is cleverly hidden where the screen’s padding is supposed to be.”
My spy-implanted ledger came from Malaysia, and had flawless shrink wrap. Even opening it, at first you don't see the implant which is cleverly hidden where the screen's padding is supposed to be.
Follow Ledger's guidance to check yours: https://t.co/FlOjWvqkZw pic.twitter.com/D8mixF1o9L— Mark Karpelès (@MagicalTux) October 9, 2026
He quote-posted Ledger’s alert and told affected buyers to open their devices and send pictures. “This looks like this could be exactly what I’m investigating,” he wrote. He also pointed readers to Ledger’s own guide for spotting a device that has been opened or altered.
Karpelès is better known for running Mt. Gox, the Tokyo exchange that handled most early bitcoin trading and collapsed in 2014 after hundreds of thousands of bitcoin went missing. Earlier this year, he suggested a hard fork of Bitcoin to resolve that previous debacle, which was largely met with mockery.
This Is Bad
Hardware wallets are oftentimes sold as the gold standard of secure crypto storage because the keys to funds sit on a separate device that is not connected to the internet. However, a user still has to trust that the hardware is genuine, the firmware does what the manufacturer says, and nobody swapped the unit out for a backdoored device during the shipping process. For now, the theory in this incident with Ledger devices is that a malicious actor entered the supply chain at some point.
Ledger’s own guide warns that pre-seeded devices, counterfeits, and opened packaging show up on Amazon and other retailers, and that a real device never arrives with a recovery phrase already written down. That same guide tells buyers to stick to Ledger or an authorized reseller to avoid those devices.
A separate hardware wallet manufacturer, Coinkite, had a firmware bug in their devices exploited for more than $100 million earlier this year. While the incidents are different, both the Coinkite and Ledger situations potentially allowed attackers to access crypto users’ keys remotely, despite users following the best practice of holding crypto in self-custody via an offline device.
Notably, CryptoBilis is not a random listing on a marketplace. Ledger’s reseller page still lists the shop for Indonesia, Malaysia, and the Philippines at cryptobilis.id, cryptobilis.com, and cryptobilis.com.ph. The company markets itself as an authorized seller, with a walk-in location in Petaling Jaya, and it also offers Trezor, Tangem, SafePal, and other brands.
Plenty of Questions Remain
Ledger has not said whether the devices in these reports were genuine units that had been opened, pre-seeded fakes, or something else, and the specifics of what exactly happened here are unknown at this time. Karpelès’s photos show one researcher’s device from Malaysia, tied to CryptoBilis only by timing and his own suspicion. A physical implant would also explain why a genuine-device check could still pass, as the secure element can be left alone while a second board watches the display.
🚨SUPPLY CHAIN ATTACK SUSPECTED 🚨
The blast radius could be larger than ledger, It you bought a device through this reseller move your assets immediately. https://t.co/UYrzln9jD6
— Rob Hamilton 🟥 (@Rob1Ham) October 9, 2026
There’s also an open question regarding non-Ledger hardware wallets sold by the same shop. Bitcoin Malaya noted that CryptoBilis is also an authorized reseller of Trezor, CoolWallet, Tangem, OneKey, Ellipal, and SafePal devices, and asked whether those devices are safe to use. AnchorWatch chief executive Rob Hamilton told anyone who bought through the reseller to move funds now, and wrote that the blast radius could be larger than Ledger.
Ledger has said it will keep customers posted as the investigation continues.