Ledger probes alleged $90 million wallet-draining incident tied to CryptoBilis distribution channel
AI Market Summary
Ledger reported an estimated ~$90m wallet-draining incident tied to devices sold via its authorized Southeast Asia distributor CryptoBilis, suggesting potential supply-chain tampering. Sales through the channel are suspended and recent buyers are urged to migrate funds, raising near-term operational and counterparty risk perceptions for self-custody users. The headline reinforces security and phishing concerns around hardware-wallet distribution, which can temporarily pressure broader crypto risk appetite.
Impact level
● Medium
Affected assets
BTC/USDT+2.23%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ChainCatcher reports that hardware wallet maker Ledger is dealing with a fresh security incident, with third-party security firms estimating total losses at close to $90 million.
Ledger said it is investigating reports of financial losses connected to devices sold via its authorized Southeast Asia distributor, CryptoBilis. The company has asked the distributor to halt all sales and shipments. Users who purchased Ledger devices through this channel within the last 90 days are urged to take precautions, including moving assets to a safe wallet.
The root cause has not been confirmed. Initial indications point to a possible supply-chain compromise or device tampering affecting this specific distribution route.
Ledger's past major security incidents and related losses include:
- 2018: Early hardware and supply-chain security weaknesses surfaced. Researchers showed Nano S devices could potentially be altered before shipment and demonstrated techniques such as MCU bootloader bypasses, isolation flaws, and Bitcoin change-address injection. Ledger released advisories and fixes; most issues were research-grade and typically required physical access.
- 2020: A large-scale customer data breach exposed more than 1 million email addresses and roughly 272,000 to 292,000 detailed customer records (including names, addresses, and phone numbers). Hardware wallets and private keys were not compromised, but the leak fueled prolonged phishing, social engineering, and impersonation campaigns.
- December 2023: A supply-chain attack targeted Ledger Connect Kit. After a former employee was phished, the attacker gained control of an NPMJS account and published a malicious library version that injected code into DApps, prompting users to sign fraudulent transactions. The exposure lasted about two hours, with estimated losses of $480,000 to $600,000. Ledger hardware and Ledger Live were not directly compromised.
- January 2026: Order data tied to third-party partner Globale was leaked after unauthorized access to the payment and logistics provider's systems, exposing certain Ledger.com order details such as names, addresses, and contact information. Ledger's systems and private keys were not affected, but phishing risk increased.
- April 2026: Counterfeit Ledger Live apps appeared on the App Store for about a week, tricking users into entering recovery phrases. More than 50 victims reportedly lost around $9.5 million across multiple blockchains. Apple removed the apps, and Ledger reiterated it never asks for users' 24-word recovery phrases.
- August 2026: Ledger disclosed Ethereum app signing vulnerabilities, including command interleaving that could cause display/signing mismatches and clear-signing bypasses. Exploitation required a malicious host. Ledger said it had seen no evidence of real-world exploitation at the time and has since patched the issues in newer versions.
- October 9, 2026: A large-scale wallet-draining incident linked to the CryptoBilis distribution channel was reported, with losses estimated near $90 million. Ledger said it believes the attack may involve targeted supply-chain compromise or device tampering limited to a single distribution channel, and it has suspended sales through that channel while advising potentially affected users to migrate assets.