Ledger is investigating reports of financial losses for customers in Southeast Asia who purchased hardware wallets through CryptoBilis. CryptoBilis is listed as an official distributor in Indonesia, Malaysia, and the Philippines.
This incident came to light on Friday, October 9th, when blockchain researchers began tracking the funds in what appeared to be the victims' wallets. Initially, the loss was estimated to exceed 72 million US dollars, but subsequent analysis by Bitquery raised the total amount to 92.9 million US dollars, involving 311 wallets across five networks: Bitcoin, Ethereum, TRON, BNB Chain, and Polygon.
It is important to distinguish between the event of 'wallet being emptied' and the situation where 'the Ledger system itself is compromised.' The original design intention of the Ledger device was to keep the private key offline, but if the hardware is maliciously tampered with or the supply chain is disrupted, this protection may become ineffective.
At present, the specific method of attack has not been confirmed, and the existing evidence also does not prove that the core infrastructure of Ledger has been compromised.
Ledger indicates that during the investigation, CryptoBilis was requested to suspend all sales and deliveries. The company also issued preventive guidelines to customers who purchased equipment from that distributor within the past 90 days.
Ledger stated in the declaration: ' Ledger is investigating reports of financial losses by users from Southeast Asia who purchased products from a dealer named CryptoBillis.'
Ledger It is recommended that customers who have purchased equipment from this dealer but have not yet initialized it should not proceed with further settings. Customers who have completed the configuration are advised to consider transferring their assets to the new Ledger signer and using a new mnemonic phrase.
Blockchain investigator Specter reported separately that he traced suspicious addresses receiving funds from hundreds of victim wallets on Ethereum, TRON, and Bitcoin, with an estimated loss of over 86 million US dollars.
Analysis of Bitquery revealed that about two weeks before the major capital outflow, there were small-scale test transactions, followed by coordinated transfers across multiple networks.
Researchers also observed that a group of wallets signed similar requests within a few seconds. These patterns indicate prior preparation and there may be a common control point, but it is not possible to prove how the attackers obtained access to these wallets solely based on blockchain transactions.
When investigators traced the funds, $10 million USDT were frozen.
Several advancements have been made in tracking the stolen assets in this investigation. Tether It is reported that approximately $10 million has been frozen USDT, involving 20 wallets suspected to be related to the theft. This move can prevent the relevant USDT from transferring funds through these addresses, but it will not automatically return the money to the victims.
As of the time of analysis, there were still approximately 14,810 ETH in a wallet controlled by the suspected attackers. Researchers also identified about 203.8 BTC in related Bitcoin addresses, and it is reported that these funds had not been moved at that time.
Analysis of Bitquery also revealed that approximately 1,254 ETH were transferred through Tornado Cash and Zcash. Subsequently, it was reported that the related funds appeared in three new wallets, one of which held about $2.1 million in USDC.
The existence of USDC may provide another possible path for further intervention, depending on the assessment of the issuer and the relevant addresses. However, it should not be assumed that it has been frozen until confirmation is obtained.
Chao Changpeng ( CZ ), the founder of Binance, stated that the information available at that time pointed to a local supply chain incident involving a certain supplier.
He believes that a small number of customers may have received counterfeit or tampered devices, and he also calls on industry participants to assist in tracking down and recovering the assets. However, this is still just his judgment and not a confirmed conclusion derived from the Ledger investigation.
The Mark Karpel CEO also shared a photo of what he claimed to be a Ledger Nano X device from Malaysia. According to the Karpel, the plastic casing of this device appears to be in good condition, but he discovered a hidden electronic module in the area where the screen buffer material is supposed to be placed.
He stated that hardware implants have become more complex, which may make it harder to distinguish the modified components from the original parts.
Karpel has requested affected users to provide photos to help identify similar modifications. However, Ledger has not yet been confirmed to have verified whether the module mentioned in the report is functional, or whether it is related to the CryptoBilis incident.
The latest independent estimate reports a loss of $92.9 million, but this figure has not yet been confirmed by Ledger. The cause of the incident remains unresolved. The existing evidence points to possible supply chain issues, but it has not been conclusively proven that the issue was due to counterfeit or tampered devices.
As of now, the confirmed measures include an investigation into Ledger, a suspension of sales to distributors, preventive guidance for customers, and reportedly a freeze of $10 million in USDT. Further conclusions will depend on the results of evidence collection and ongoing on-chain tracking.












