Ledger is investigating a major cryptocurrency theft linked to devices purchased from CryptoBilis, a reseller operating in Southeast Asia.
CryptoBilis is listed by Ledger as an official reseller in several Southeast Asian markets, which is why the incident cannot simply be dismissed as a case of users buying hardware from an unknown third-party seller.
Early on-chain estimates put the losses above $86 million. A newer analysis by Bitquery estimates that $92.9 million was drained from 311 wallets across five blockchains, although Ledger has not confirmed either the total loss or the number of affected users.
The critical distinction is that there is currently no evidence of a Ledger-wide hack affecting all devices, firmware or infrastructure. The company has linked the reports to users who bought devices from CryptoBilis and is still investigating how their keys may have been compromised.
For Ledger owners, that means the response depends heavily on where the device came from and whether it has already been initialized.
What Happened to Ledger Users?
On October 9, Ledger said it was investigating reports of lost funds from customers in Southeast Asia who had purchased devices through CryptoBilis.
As a precaution, Ledger asked the reseller to pause all sales and shipments while the investigation continues.
Reports initially focused on theft addresses identified by independent on-chain researchers. Early estimates ranged from more than $72 million to more than $86 million across Bitcoin, Ethereum and TRON.
The figure remains an independent on-chain estimate, not an official loss figure from Ledger, and may change as investigators identify additional addresses.
What the On-Chain Data Shows
Bitquery found that the largest portion of the suspected theft involved TRON, where about $70.5 million was drained. Its analysis also attributes approximately:
$16.8 million to Bitcoin;
$3.7 million to Ethereum;
$1.45 million to BNB Chain;
$580,000 to Polygon.
The firm says 111 Bitcoin wallets were emptied in a single block, while multiple TRON wallets authorized similar transactions within seconds of each other.
Based on those patterns, Bitquery argues that the attacker appears to have had access to the victims' keys.
That is significant, but it still does not explain how those keys were obtained.
The analysis also found activity that appeared to precede the mass drain. Addresses associated with the attacker reportedly conducted small test transactions over roughly two weeks before the main theft.
MistTrack also reported that Tether had begun blacklisting some addresses linked to the incident, indicating that at least part of the suspected stolen funds had already entered the asset-freezing stage:
Those numbers describe the movement of suspected stolen funds. They do not amount to confirmation of the attack vector.
Was Ledger Actually Hacked?
So far, nothing publicly released establishes that Ledger itself was breached or that there is a vulnerability capable of remotely compromising Ledger devices in general.
Ledger has not reported a compromise of its firmware, Secure Element, servers or broader device infrastructure.
Instead, the known reports are linked to CryptoBilis customers.
One theory circulating among researchers and industry figures is a supply-chain compromise, in which devices or their recovery process may have been tampered with before reaching customers. But Ledger has not confirmed that explanation either.
That theory gained more attention after Mark Karpelès, former CEO of Mt. Gox, said he was examining a Ledger device from Malaysia that appears to contain an additional hardware implant hidden inside the device:
Until Ledger completes its investigation, however, claims that the CryptoBilis devices were deliberately tampered with should be treated as a working theory, not an established fact.
A compromised recovery phrase would allow an attacker to recreate the wallet elsewhere and move the assets without physically possessing the owner's Ledger.
Albert Quehenberger, CEO of AQ Forensics and ChangeNOW Ambassador, has previously pointed to the same broader weakness in crypto custody: the cryptography itself is often not where real-world compromises happen. Phishing, exposed recovery seeds, fake wallet software, compromised devices and social engineering can all bypass otherwise strong technical protections.
Who Should Take Action Right Now?
The clearest high-risk group is users who purchased a Ledger from CryptoBilis.
Here is the practical breakdown.
Situation
What to do now
Bought from CryptoBilis in the past 90 days and have not initialized the device
Do not set it up. Follow Ledger's official updates.
Bought from CryptoBilis and already initialized it
Move the assets to a new trusted signer using a completely new seed. Do not reuse the old recovery phrase.
Bought from CryptoBilis earlier than 90 days ago
Consider treating the device cautiously while the investigation develops. Bitquery found that some affected wallets appear to predate Ledger's 90-day window.
Bought directly from Ledger or through an unrelated seller
There is currently no evidence of a general Ledger compromise affecting those devices.
Your recovery phrase has ever been entered into a website, computer, unknown app or shared with anyone
Treat that recovery phrase as compromised regardless of the CryptoBilis incident.
Your wallet has already been drained
Preserve transaction data and other evidence immediately and report the theft.
Ledger's official warning covers CryptoBilis purchases made during the previous 90 days. Bitquery, however, reports that while around 60% of the wallets it tracked were first funded inside that period, more than 80% had been funded since June.
A wallet's first funding date does not prove when its owner bought the hardware device, so this does not establish that older CryptoBilis devices were compromised.
Do All Ledger Owners Need to Move Their Crypto?
Based on the information available now, no.
There is currently no evidence that every Ledger owner, or even Ledger owners generally, need to migrate their assets.
Moving funds unnecessarily during a breaking security incident creates risks of its own: fake support accounts, phishing sites, malicious wallet software and fraudulent “security checks” tend to appear quickly when users are scared and looking for instructions.
If your Ledger was not purchased from CryptoBilis and there are no other signs that your recovery phrase or device has been compromised, the current evidence does not indicate a Ledger-wide emergency.
For a broader guide to cold-wallet risks and safe storage practices, see ChangeNOW's guide on whether cold wallets are safe.
Watch for the Second Attack: Phishing
Messages claiming that users must “verify” a Ledger, migrate immediately, connect to a security portal or enter a recovery phrase should be treated with extreme suspicion.
Quehenberger puts the most important rule simply:
“Any request for a seed phrase, private key or wallet backup should be an immediate stop signal.”
Ledger likewise repeatedly warns that it will never ask users to provide their 24-word Secret Recovery Phrase.
Do not enter a recovery phrase into a website sent through an email, direct message, advertisement or supposed support conversation.
One user reported receiving a scam letter sent by mail from France and impersonating Ledger, adding that others had reported similar letters alongside scam calls and phishing emails.
If action is required, navigate to Ledger's official channels independently rather than following unsolicited links.
What If Your Ledger Wallet Was Already Drained?
If funds are already missing, speed matters.
Preserve:
affected wallet addresses;
transaction hashes;
transaction history;
timestamps;
screenshots;
purchase and device information;
communications or suspicious messages connected to the incident.
Report the incident to law enforcement and contact relevant platforms or qualified blockchain investigators where appropriate.
This matters because blockchain transactions remain traceable after a theft, but the opportunity to intervene may shrink once assets reach mixers, cross-chain services or other destinations.
As Quehenberger explained:
“The transaction history may stay, but the opportunity to act can disappear very fast.”
What We Still Don't Know about Ledger Drain
Several major questions remain open:
How were the private keys or recovery phrases compromised?
Were any devices physically modified before reaching buyers?
How many individual customers are actually affected?
What is the final amount stolen?
Does the affected purchase period extend beyond Ledger's current 90-day warning?
How much of the stolen crypto can ultimately be frozen or recovered?
Until those questions are answered, calling this a confirmed breach of Ledger's hardware or infrastructure goes beyond the available evidence.
Fake Ledger Sites Are Appearing in Search
The current Ledger investigation is unfolding alongside a separate phishing risk.
Security researcher CyberScrilla reported a fake Ledger website and app appearing at the top of Google Search, apparently designed to steal users' seed phrases. The researcher explicitly noted that there is no confirmed link between the phishing site and the reported CryptoBilis-related thefts.
Ledger responded publicly to the report, saying it had forwarded the malicious domain to its team and warning that impersonation scams remain common.
The company reiterated a basic rule:
“Ledger will never call, DM, or ask for your 24-word recovery phrase.”
Fake search results and lookalike domains can be difficult to spot, especially when branding, HTTPS and page design appear legitimate. For more on how these attacks work, see our guide to Punycode phishing and lookalike domains.
Users searching for urgent instructions may encounter fake support pages, malicious ads or impersonation accounts precisely when they are most likely to act quickly.
So even if the phishing campaign turns out to be completely unrelated to the CryptoBilis case, the practical takeaway is the same: do not enter a recovery phrase into a website, form or support chat, and do not assume that a top Google result is legitimate.
ChangeNOW continues to support its industry partners, including Ledger, in efforts to identify and respond to illicit crypto activity. If funds linked to the CryptoBilis theft are detected moving through our services, we will cooperate with relevant parties in line with our compliance procedures and applicable requirements.
How to Recover Stolen Crypto: Step-by-Step Guide | ChangeNOW X Space
Learn what to do after a crypto theft, how investigators trace stolen funds, when exchanges can freeze assets, and how to avoid fake recovery services.
Bitget has confirmed a major security breach affecting approximately $387.5 million in assets across its hot and warm wallet infrastructure. Private-key compromise has been ruled out.