Ledger fund losses reported by customers in Southeast Asia have pushed the hardware wallet maker into an active investigation of devices bought from CryptoBilis, an authorized reseller spanning Indonesia, Malaysia and the Philippines — and the company’s advice for anyone who bought a device in the past 90 days is blunt: don’t set it up.
In a statement posted on X, Ledger said it had asked CryptoBilis to suspend sales and shipments of its devices as a precaution. Customers who purchased within the past 90 days were told not to configure their devices at all; those who already had were advised to transfer their assets to a new Ledger signer with a freshly generated recovery phrase. Ledger has not disclosed how many customers may be affected, the value of the reported losses, the cause of the incidents, or whether the devices themselves were compromised — all of which remain open questions as the probe continues.
The Ledger fund losses estimates floating around — none confirmed
While the company stays quiet on numbers, onchain researchers have not. Investigator tanuki42 identified eight wallet addresses allegedly linked to more than $72 million in losses, while fellow researcher Specter estimated suspected thefts exceeding $86 million across Bitcoin, Ethereum and Tron. Neither figure has been confirmed by Ledger, and the extent of any connection to the CryptoBilis investigation remains unclear.
Crypto security organization Security Alliance, better known as SEAL, amplified tanuki42’s findings on X and urged anyone whose funds were transferred to the identified addresses to contact its incident-response team. SEAL did not offer an independent loss estimate or name a cause for the suspected thefts. For context on how fast stolen-fund flows move, today also brought news of a $1 billion Bitcoin transfer out of the Bitfinex hack wallet — large onchain movements attract scrutiny quickly, and these addresses already have.
Ledger says its own infrastructure is untouched
In a statement to Cointelegraph, Ledger said the incident appeared isolated to the reseller and the affected market, adding that it had received no reports involving devices purchased directly from the company. “Ledger’s infrastructure, systems and services were not compromised,” the company said, describing its investigation as ongoing.
That distinction — reseller supply chain versus manufacturer security — is the whole story in one line. If the devices left Ledger’s control intact and were tampered with downstream, the failure sits in distribution, not in the chip design that cold-storage guides routinely tell readers to trust. The practical checklist for holders: buy direct or from verified channels, never set up a device whose packaging shows signs of interference, and treat any reseller-bought unit from the affected markets in the last 90 days as suspect until Ledger says otherwise.
Sourced from Cointelegraph’s report on the Ledger-CryptoBilis investigation.
