Ledger Investigates $86M Crypto Losses Linked to Suspected Fake Wallets

Wait 5 sec.

TLDR:More than $86 million in reported crypto losses are linked to suspected fake or tampered Ledger wallets.Ledger told reseller CryptoBilis to pause sales and shipments while the investigation continues.On-chain analyst Specter traced funds across Bitcoin, Ethereum, and TRON from hundreds of victim wallets.CZ described the incident as a suspected localized supply chain attack, not a confirmed Ledger-wide exploit.Ledger is investigating more than $86 million in reported cryptocurrency losses involving users in Southeast Asia who purchased hardware wallets from reseller CryptoBilis. The affected devices are suspected of being counterfeit or tampered with before reaching customers.Ledger has instructed CryptoBilis to suspend sales and shipments while the investigation continues.On-chain analyst Specter traced stolen funds across Ethereum, TRON, and Bitcoin, identifying inflows from hundreds of victim wallets. The findings point to a possible supply chain attack involving one reseller, rather than a vulnerability affecting Ledger hardware wallets across the board. Binance founder Changpeng Zhao, known as CZ, also warned users who recently purchased Ledger devices.How the Ledger Hardware Wallet Attack May Have HappenedThe reported incident raises concerns about how compromised hardware wallets can expose crypto holdings. Hardware wallets typically keep private keys offline, reducing their exposure to internet-based attacks. However, that protection depends on users receiving genuine devices that have not been manipulated.If counterfeit or tampered devices were distributed through a reseller, attackers could potentially compromise wallet security before customers began using them. The provided information does not establish exactly how the suspected devices enabled the reported thefts. Ledger’s investigation will need to determine the compromise method and identify the affected products.Specter’s on-chain analysis identified multiple theft addresses receiving funds from victims across three major blockchain networks. There have been a reports on X and Reddit of wallet-draining by Ledger users.I traced the theft addresses and identified inflows from more hundreds of victim wallets across several major blockchains, including Ethereum, TRON, and Bitcoin. Total losses $86M+… pic.twitter.com/c5dhQeAZ0l— Specter (@SpecterAnalyst) October 9, 2026The identified addresses include Bitcoin addresses beginning with bc1q, TRON addresses beginning with T, and Ethereum addresses beginning with 0x. This cross-chain activity suggests the reported losses extend beyond a single cryptocurrency.The scale of the incident remains significant, with reported losses exceeding $86 million. However, the available information does not provide a final breakdown by blockchain, the number of confirmed victims, or the total amount recovered.What Ledger Users Should Know About the $86M Crypto TheftLedger’s instruction to CryptoBilis to pause sales and shipments represents a precautionary response while the investigation proceeds. It does not establish that Ledger’s entire hardware wallet product line has been compromised. CZ similarly described the available evidence as pointing toward a localized supply chain attack involving one vendor. Beware if you use a Ledger hardware wallet, especially if you bought one recently.Based on information so far, it seems to be localized to a supply chain attack with one vendor. A small number of people probably bought fake (or tampered) Ledgers.Ledger is one of the most… https://t.co/zW8wkvdZNf— CZ BNB (@cz_binance) October 9, 2026For cryptocurrency holders, the incident highlights a security risk that extends beyond software vulnerabilities and exchange breaches. Purchasing hardware wallets through trusted channels can help reduce exposure to counterfeit products. Users should also follow official manufacturer guidance when verifying devices and setting up wallets.Anyone concerned about a recently purchased device should avoid entering existing recovery phrases into unverified software or websites. A recovery phrase can provide direct access to the funds controlled by a wallet. Users who suspect compromise should follow official security guidance and consider moving assets to a verified, secure wallet.The investigation also highlights the role of blockchain analysis in tracing stolen cryptocurrency across networks. Specter identified multiple addresses associated with the reported thefts, giving investigators potential leads for tracking fund movements. CZ said he expects industry participants to help trace and recover the assets.For now, the key distinction is between a suspected reseller-level compromise and a confirmed vulnerability in Ledger’s broader hardware wallet systems. The investigation must establish how the devices were compromised, how many users were affected, and whether any funds can be recovered.The post Ledger Investigates $86M Crypto Losses Linked to Suspected Fake Wallets appeared first on Blockonomi.