LIVE CRYPTONEWSINSIGHTS
CryptoNewsInsightsYour source for daily crypto insights
Altcoin News

Ledger Probes $92.9M Drain Tied to CryptoBilis Reseller

Black hardware crypto wallet on a dark desk beside a coiled cable under cool light
In this article4 sections
  1. 01Key facts
  2. 02What the on-chain trail shows
  3. 03Why it matters
  4. 04What to watch

Ledger is investigating reports of cryptocurrency losses among customers in Southeast Asia who bought hardware wallets through the reseller CryptoBilis, an official distributor in Indonesia, Malaysia and the Philippines, according to U.today. Blockchain researchers flagged the fund movements on Friday, Oct. 9, tracing assets out of suspected victims’ wallets.

Bitquery’s analysis put the reported total at $92.9 million across 311 wallets on five networks: Bitcoin, Ethereum, TRON, BNB Chain and Polygon. Earlier estimates had placed losses above $72 million. Separate reporting by Cryptobriefing noted that the on-chain analyst Specter estimated losses above $86 million, based on suspicious addresses that received funds from hundreds of victim wallets across Ethereum, TRON and Bitcoin.

Financial documents and a tablet showing crypto charts under scrutiny, representing the investigation into World Liberty Financial's $100M investment.Also readWorld Liberty Faces New Questions Over $100M Token Purchase Tied to UK Money Probe

Key facts

  • Bitquery reported losses of $92.9 million across 311 wallets on Bitcoin, Ethereum, TRON, BNB Chain and Polygon, up from an initial estimate above $72 million.
  • Ledger said it asked CryptoBilis to pause all sales and shipments while its investigation proceeds and told customers who bought from the reseller in the previous 90 days not to initialize unopened devices.
  • Specter, whose estimate of more than $86 million was carried by Cryptobriefing, flagged one Bitcoin address (bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl) that reportedly received over 211 BTC and had not moved.
  • Tether reportedly froze approximately $10 million in USDT across 20 wallets tied to the suspected theft.
  • Wallet accounts and the cause of the incident have not been confirmed by Ledger.

Cryptobriefing reported that as of its story Ledger had not commented publicly, while U.today carried the company’s Oct. 9 statement issued from its support account. The two outlets also differ on scale: Specter’s $86 million figure covers three networks, whereas Bitquery’s $92.9 million spans five.

What the on-chain trail shows

Bitquery’s review identified small test transactions running for roughly two weeks ahead of the main outflows, then coordinated transfers across multiple networks. Researchers also saw clusters of wallets signing similar requests within seconds of each other, a pattern consistent with preparation and a possible common point of control. Blockchain records alone cannot show how the attacker gained access to the wallets.

Security researcher at a monitor showing code and network diagram in a dark officeAlso readAvalanche founder warns AI could expose XRP Ledger bugs

At the analysis cutoff, about 14,810 ETH sat in a group of suspected attacker-controlled wallets, and roughly 203.8 BTC was identified in associated Bitcoin addresses, reportedly unmoved. Bitquery also traced about 1,254 ETH through Tornado Cash and Zcash, with funds later appearing in three new wallets, one holding about 2.1 million USDC. A USDC freeze would depend on the issuer’s assessment and the addresses involved and should not be assumed.

Former Mt. Gox chief executive Mark Karpelès posted photos of a Ledger Nano X he said he received from Malaysia. He described the shrink-wrap as intact but said a concealed electronic module sat where the screen padding should have been, and asked affected users for photographs to help identify similar tampering. Ledger has not been shown to have confirmed the module was functional or connected to CryptoBilis.

Binance founder Changpeng Zhao said the information available pointed to a localized supply-chain incident involving one vendor, with a small number of buyers possibly receiving fake or tampered devices. He called on industry participants to help trace and recover the assets. That remains an assessment rather than a finding from Ledger’s investigation.

Why it matters

Hardware wallets are bought precisely because the private keys stay offline, so a compromise traced to a reseller rather than to firmware or seed handling shifts attention to the distribution chain that sits between the factory and the buyer. Until the access method is established, no owner of an affected device can tell whether the risk lives in their setup routine or somewhere upstream.

This incident lands in a year of hardware wallet setbacks. Cryptobriefing noted that a fake Ledger Live app on the Apple App Store drained roughly $9.5 million from more than 50 users earlier in 2026, and that a reported seed-generation flaw in Coldcard devices in August 2026 produced losses exceeding $88 million in Bitcoin. The reported Ledger losses sit in the same range.

What to watch

Three things will move the story: whether Ledger names a cause, whether the roughly 211 BTC in the flagged Bitcoin address starts moving, and whether the loss estimate settles near $86 million or climbs toward $100 million as more victims are identified. Further conclusions depend on forensic findings and continued on-chain tracing.

Sources: U.Today, Cryptobriefing

Written by Moris Nakamura

Moris Nakamura is the editor-in-chief at CryptoNewsInsights, overseeing coverage of Bitcoin, altcoin markets, and the broader cryptocurrency industry.

How we report
More from Altcoin News

This article is for information only and does not constitute financial advice. Cryptocurrency markets are volatile; do your own research before making investment decisions.