Ledger $86M theft: Ledger probes $86M theft from authorized reseller CryptoBilis

Ledger probes $86M theft from authorized reseller CryptoBilis

Hardware wallet manufacturer Ledger has launched an urgent investigation into reports of an $86 million cryptocurrency theft. The funds, comprising Bitcoin, Ethereum, and Tron, were allegedly drained from devices sold through CryptoBilis, a Malaysian company that was an authorized reseller for the Paris-based firm, raising concerns about the Ledger $86M theft.

The incident strikes at the heart of Ledger’s core security advice, which has always been for customers to purchase devices exclusively through its official website or a vetted list of authorized resellers. The inclusion of CryptoBilis on that trusted list has now raised serious questions about the security of the hardware wallet supply chain.

Ledger addresses the $86M theft

In a statement posted to its official support account on X (formerly Twitter) on Friday, Ledger confirmed it was aware of the user reports and had begun a formal investigation. The company immediately instructed CryptoBilis to halt all sales and shipments of Ledger products pending the outcome of the inquiry.

The alarm was raised by a pseudonymous on-chain investigator known as Specter, who posted on X about numerous complaints on social media platforms, including X and Reddit, from Ledger owners who found their wallets unexpectedly emptied.

Specter’s analysis tracked funds from what they claimed were hundreds of victim wallets, culminating in deposits worth over $86 million to the attackers’ addresses across the Bitcoin, Ethereum, and Tron blockchains.

Ledger has emphasized that there is currently no evidence that its own systems or the wallet software itself have been compromised. The focus of the investigation remains squarely on the devices distributed by the third-party reseller. The scale of the reported loss makes this a significant event.

As a precautionary measure, Ledger has advised anyone who purchased a device from CryptoBilis within the last 90 days to refrain from setting it up. For customers who have already activated a wallet from this reseller, the company issued a stark warning: immediately move all crypto assets to a different Ledger device with a newly generated, secure recovery phrase.

Focus turns to supply-chain integrity

The most prominent theory among security experts for how the theft occurred is a sophisticated supply-chain attack. In this scenario, devices are physically tampered with somewhere between the factory and the end-user. The hardware or its firmware could be altered to generate a predictable recovery phrase known only to the attacker.

Once an unsuspecting user receives the compromised device and transfers funds to it, the attacker can use their pre-knowledge of the private key to drain the wallet at will. This type of attack is particularly insidious because it preys on the user’s trust in a sealed, seemingly authentic product from a trusted vendor.

It undermines the very concept of “cold storage,” where assets are meant to be kept completely offline and beyond the reach of hackers.

This attack vector isn’t merely theoretical. In 2023, security researchers at Kaspersky documented a similar case involving a tampered Trezor Model T hardware wallet, a Ledger competitor.

In that instance, the device’s main chip had been replaced, and its software was rigged to offer the user one of only 20 pre-determined recovery phrases, all of which were controlled by the attackers. After the user loaded the wallet with funds, the thieves waited approximately a month before emptying it.

The reseller at the center of the probe

CryptoBilis, the reseller now under scrutiny, is an online store based in Malaysia. It was launched in December 2020 by founders Arravind Prabu, Vimal Selvamany, and Dhivager Rathakrishnan under their parent company, Fetch International. The store announced in 2021 that it had become an official, authorized reseller for Ledger products in the region, a status that is now suspended.

Becoming an authorized reseller typically involves a vetting process by the manufacturer, intended to ensure that partners adhere to specific standards for storage, shipping, and customer service. The apparent breach within this trusted channel is a major blow to the program and forces a re-evaluation of the risks associated with not buying directly from the manufacturer.

Ill-timed crisis as Ledger seeks funding

This security crisis could not have come at a worse time for Ledger. The company, a dominant force in the hardware wallet market, has been navigating a challenging period. In May, Ledger reportedly shelved plans for a $4 billion U.S. initial public offering (IPO), citing unfavorable market conditions.

Having pivoted away from the public markets, the company was said to be exploring private fundraising rounds to fuel its next stage of growth. This $86 million theft, linked directly to its distribution network, will inevitably make conversations with potential investors far more difficult.

It raises questions about operational oversight, third-party risk management, and the potential for reputational damage to impact future sales. Such incidents can highlight broader challenges in corporate governance and the need for robust oversight, drawing attention to areas like business practices.

The incident also adds to a list of recent security-related issues for the company. In January, Ledger disclosed a customer data leak that occurred at its third-party payment processor, Global-e. While not a direct hack of its crypto hardware, the leak exposed personal customer information.

Investigator ZachXBT commented on the incident, saying that hardware wallet firms cannot be trusted with personal information. The repeated involvement of third-party partners in security lapses is becoming a worrying pattern. This is precisely the kind of issue that invites further examination from regulators and powerful figures.

What this means for wallet security

The core promise of a hardware wallet is that it provides a “trustless” environment where users can secure their own keys without relying on a third party. This incident serves as a stark reminder that the physical supply chain itself can be a point of failure, introducing an element of trust where none should be required.

For users, it reinforces critical security hygiene. Best practice dictates that a recovery seed phrase should only ever be generated by the secure device itself, in view of the user, and never come pre-printed or pre-installed. Any device that arrives with a pre-set seed phrase should be considered compromised and never used.

This event will likely force Ledger and other hardware manufacturers to re-evaluate their reseller programs and supply chain logistics. More stringent audits, tamper-evident packaging, and clearer communication about the risks of buying from anyone other than the official factory source may become the new norm.

It highlights a fundamental tension: the need for global distribution versus the security imperative of a tightly controlled, end-to-end supply chain.