Gold 24K AED 494.96/gUSD/AED 3.6725USDT/AED 3.6697AED/INR 26.38All live rates →

Ledger Fund Losses Probe Targets Southeast Asian Reseller CryptoBilis

Ledger fund losses reported by customers in Southeast Asia have pushed the hardware wallet maker into an active investigation of devices bought from CryptoBilis, an authorized reseller spanning Indonesia, Malaysia and the Philippines — and the company’s advice for anyone who bought a device in the past 90 days is blunt: don’t set it up.

In a statement posted on X, Ledger said it had asked CryptoBilis to suspend sales and shipments of its devices as a precaution. Customers who purchased within the past 90 days were told not to configure their devices at all; those who already had were advised to transfer their assets to a new Ledger signer with a freshly generated recovery phrase. Ledger has not disclosed how many customers may be affected, the value of the reported losses, the cause of the incidents, or whether the devices themselves were compromised — all of which remain open questions as the probe continues.

The Ledger fund losses estimates floating around — none confirmed

While the company stays quiet on numbers, onchain researchers have not. Investigator tanuki42 identified eight wallet addresses allegedly linked to more than $72 million in losses, while fellow researcher Specter estimated suspected thefts exceeding $86 million across Bitcoin, Ethereum and Tron. Neither figure has been confirmed by Ledger, and the extent of any connection to the CryptoBilis investigation remains unclear.

Crypto security organization Security Alliance, better known as SEAL, amplified tanuki42’s findings on X and urged anyone whose funds were transferred to the identified addresses to contact its incident-response team. SEAL did not offer an independent loss estimate or name a cause for the suspected thefts. For context on how fast stolen-fund flows move, today also brought news of a $1 billion Bitcoin transfer out of the Bitfinex hack wallet — large onchain movements attract scrutiny quickly, and these addresses already have.

Ledger says its own infrastructure is untouched

In a statement to Cointelegraph, Ledger said the incident appeared isolated to the reseller and the affected market, adding that it had received no reports involving devices purchased directly from the company. “Ledger’s infrastructure, systems and services were not compromised,” the company said, describing its investigation as ongoing.

That distinction — reseller supply chain versus manufacturer security — is the whole story in one line. If the devices left Ledger’s control intact and were tampered with downstream, the failure sits in distribution, not in the chip design that cold-storage guides routinely tell readers to trust. The practical checklist for holders: buy direct or from verified channels, never set up a device whose packaging shows signs of interference, and treat any reseller-bought unit from the affected markets in the last 90 days as suspect until Ledger says otherwise.

Sourced from Cointelegraph’s report on the Ledger-CryptoBilis investigation.

📧 The Gulf reads Cryptonite first
Get MENA regulation moves, RWA deals and AI-money trends in one weekly brief — plus instant alerts when the MENA Regulation Tracker changes. Free, no spam.
Was this briefing useful?Thanks for the feedback!
Vaibhavv Ali
Vaibhavv Ali

Vaibhavv Ali is the founder and editor of Cryptonite (cryptonite.ae), an independent digital-asset news and analysis publication with a UAE focus. He covers virtual-asset regulation — VARA, ADGM and the UAE Central Bank — alongside real-world-asset tokenization, stablecoins and agentic AI in finance. Every Cryptonite article is human-edited and its sources are linked. He is also a celebrated speaker and host.

More articles by Vaibhavv Ali →

Leave a Comment

About  ·  Contact  ·  Privacy Policy  ·  Editorial Policy  ·  Advertise  ·  Newsletter
Follow: X  ·  LinkedIn  ·  Instagram  ·  Binance Square  ·  CoinMarketCap  ·  Gate