Ledger has halted hardware wallet sales through Southeast Asian distributor CryptoBilis and advised anyone who purchased a device from CryptoBilis in the past 90 days not to begin setup. All active users should immediately sweep their balances to newly generated seed phrases. The world’s largest hardware wallet manufacturer is investigating a reported wallet drain that could lead to crypto losses above $86 million.Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices. We recommend Ledger users who purchased from this reseller in the last 90 days to not initiate set up if you have not done so yet. If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed). We will continue to inform customers of updates as the investigation progresses.Reach out to Ledger customer support through official channels with any questions: https://t.co/4p918UH8yb— Ledger Support (@Ledger_Support) October 9, 2026This hardware wallet stores private keys once it has been securely initialised, but a device or recovery phrase compromised anywhere in the supply chain could give another party access, no matter how carefully the buyer later stores the wallet.Where the $86 Million Estimate Came From Ledger has not disclosed how many customers are affected or confirmed the value of the reported losses. The widely cited figure of more than $86 million comes from pseudonymous on-chain investigator Specter, who published addresses associated with reported wallet drains across Bitcoin, Ethereum and Tron. However, the researcher later admitted that the actual victim count had not yet been established. The available information also does not prove that every transaction included in the estimate involved a CryptoBilis customer.There have been a reports on X and Reddit of wallet-draining by Ledger users.I traced the theft addresses and identified inflows from more hundreds of victim wallets across several major blockchains, including Ethereum, TRON, and Bitcoin. Total losses $86M+bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dlTK6DWNpNe1w2iJRNFpU8aHdrPTATxvXT6CTBkcUMYC7CkTK99tkTnaStQVBastfrs9d9TCGE3xp6YGRKXxDZiLfysgJW3f22KfMNsW0x69c8f401cfc6cd40ac94691d6d7c48e3b7a478410x033636e45d519bebb7b5c2520ca6ce56fbdb4f7a0x83aeac166f6832ae3500000a24510a95a052a599bc1qqnkwurxs99xkx5t4yffqhq3u6qwy0qpjyujtm9bc1qgqheemzla77pesl227hdtgf5ykz62d0zvld26nTSDWtuZ2pARUVz4v3PkL2hi3iXPjowAr5a— Specter (@SpecterAnalyst) October 9, 2026The Attack Vector Remains Unknown Ledger has confirmed only that it is investigating reports from Southeast Asian users who purchased products through CryptoBilis. It has not identified the countries involved, named individual victims or linked the incident to a vulnerability affecting Ledger devices generally. It is not known whether customers received altered or counterfeit hardware, used recovery phrases that had already been exposed, or lost their assets through another route such as phishing or malicious transaction approval. Until the mechanism is established, the incident cannot be described as a confirmed hardware-wallet exploit or supply-chain attack.However, Ledger’s instruction to replace both the signer and seed phrase places the distribution channel at the centre of the investigation, and shows why the seller and chain of custody matter as much as the device’s security after setup.The reports emerged less than three weeks after Bitget confirmed a $387.5 million breach affecting part of its hot- and warm-wallet infrastructure. The two incidents involve different custody models: Bitget controlled the compromised wallets, while Ledger users hold their own keys. In the Ledger case, the unresolved question is whether that control was compromised before buyers received or initialized their devices.This article was written by Tanya Chepkova at www.financemagnates.com.