BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Ledger probes $86M theft linked to one of its own listed resellers

Ledger has opened an investigation into the theft of about $86 million. The money was allegedly stolen from crypto wallets sold through CryptoBilis. The company’s standard safety advice is to

AnonymousCryptoCompass newsroom
October 9, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.

Ledger has opened an investigation into the theft of about $86 million. The money was allegedly stolen from crypto wallets sold through CryptoBilis.

The company’s standard safety advice is to buy only from vetted, official channels like CryptoBilis, which was vetted by Ledger itself.

How much was stolen from Ledger’s reseller?

CryptoBilis is a Malaysian online store launched in December 2020 by Arravind Prabu, Vimal Selvamany and Dhivager Rathakrishnan, under their company, Fetch International. The store said in 2021 that it became an authorized reseller for the Paris-based hardware wallet maker.

Ledger investigates suspected $86M theft affecting authorized reseller. Authorized resellers of Ledger hardware wallets in Malaysia. Source: Ledger.

On Friday, Ledger said on its support account that it had asked CryptoBilis to halt all sales and shipments of Ledger products while it investigates reports that more than $86 million in Bitcoin, Ethereum and Tron was stolen from wallets the store sold.

Specter, a pseudonymous blockchain investigator, posted on X that there had been complaints of drained wallets across X and Reddit among Ledger owners.

Specter said their investigation into the suspected theft addresses found deposits arriving from hundreds of victim wallets on Bitcoin, Ethereum and Tron, adding up to more than $86 million.

The total amount lost in the hack and any connection between the individual cases have not been confirmed. The cause is also still unknown. Ledger says there is no evidence that its own systems or wallet software were breached.

Ledger advised anyone who bought from the reseller in the past 90 days not to set up their device yet. Customers who had already activated a wallet were told to move their funds to a different Ledger device with a newly generated recovery phrase.

What are the leading theories?

One popular theory for how the attackers carried out the hack is a supply-chain attack. In this attack, a device is tampered with such that whatever recovery phrase used for it is already known to an attacker before it reaches the buyer. The attacker can then drain the wallet once funds land on it.

This method was documented in 2023 when Kaspersky researchers found a tampered Trezor Model T hardware wallet. The device’s main chip had been replaced, and its software was rigged so that it gave users one of 20 phrases already known to the attackers. The attackers waited about a month before emptying the wallet in this case.

Cryptopolitan reported that Ledger abandoned a planned $4 billion U.S. IPO in May, saying the decision was due to poor market conditions. The company said it was weighing private fundraising instead, but the chances now seem slim with this fresh security scare.

Ledger recorded a separate incident in January, disclosing that its payment processor Global-e experienced a customer-data leak. Investigator ZachXBT commented on the incident, saying that hardware wallet firms cannot be trusted with personal information.

If you're reading this, you’re already ahead. Stay there with our newsletter.