Ledger is investigating reports of cryptocurrency theft involving hardware wallets purchased by Southeast Asian customers from resellers CryptoBilis. On-chain investigator Specter estimates that over $86 million in crypto assets were transferred to 98 wallet addresses, but the total loss and the cause of the incident have not yet been independently confirmed.
These reports have raised concerns among Ledger users, as affected customers claim that their encrypted assets have been transferred away. However, a security vulnerability across the entire company of Ledger has not yet been confirmed, and the investigation has not determined whether it involves a vulnerability in any devices of Ledger.
Ledger Suspends CryptoBilis sales during the investigation period
Ledger indicates that, as a precautionary measure, the company has requested CryptoBilis to suspend all sales and deliveries of its devices in order to adopt a cautious approach when investigating the reported losses.
The company recommends that customers who purchased Ledger devices from this reseller within the past 90 days and have not yet begun setting up the devices should not proceed with the initialization process.
For customers who have completed their device settings, Ledger it is recommended to consider using a new recovery seed to transfer your assets to the new Ledger signer.
Ledger indicates that as the investigation progresses, the company will continue to update customers on the developments. The company has not yet confirmed the root cause of these reported incidents.
It is estimated that the amount of coin theft exceeds 86 million US dollars.
After reviewing reports from users who claimed to possess Ledger devices, the on-chain investigator Specter provided an estimate of $86.96 million involving 98 addresses.
Security researcher tanuki42 previously estimated the losses to exceed $72 million and stated that the amount is still increasing.
The stolen assets reportedly include Bitcoin, Ethereum, and the Tron network. However, these 98 addresses identified as Specter do not necessarily represent 98 confirmed victims, and these estimates also fail to determine the full extent of the incident.
It is still unclear at this time whether the affected wallets were compromised through stolen recovery credentials, issues related to resellers, or some other method of attack.
Possible reasons why assets may be stolen without any contact with the Ledger device
Hardware wallets protect private keys by storing them within the device itself. However, the wallet's recovery phrase can be used to regain access to the funds on another compatible wallet.
If attackers obtain the complete 24-word recovery phrase, they may be able to reconstruct the wallet keys and transfer the assets within without actually having physical access to the original Ledger device.
If an additional password phrase is set, an extra layer of protection is added. Anyone who attempts to access a wallet protected in this way will also need to enter the correct password phrase.
This is just one possible explanation for why assets may still be transferred without the approval of a transaction in a hardware wallet. However, this does not prove how the thefts described in these reports actually occurred.
Ledger Reminds users not to share recovery phrases
Users must never enter their recovery phrases on websites, mobile applications, or in customer service chats that claim to be able to protect wallets. Ledger repeatedly reminds users that the company will never ask them to disclose their recovery phrases.
Customers who purchased devices from CryptoBilis within the past 90 days should follow the specific guidelines outlined in Ledger. Do not set up unused devices until further information is available.
Users who suspect that their wallets have been compromised should avoid sharing recovery credentials and use a trusted and secure device to set up their new wallets when transferring the remaining assets to them.
The investigation is still ongoing. Until the cause is confirmed at Ledger, the losses mentioned in these reports should not be considered evidence of a hardware wallet vulnerability across the company.












