Ledger users in Southeast Asia who purchased their wallets from a reseller named CryptoBilis have reportedly been drained for over $80 million so far in an ongoing hack.
Crypto analysts Specter and Tanuki42 first noted reports of Ledger users losing funds. They traced the addresses and came up with loss estimates between $72 million and over $86 million.
Ledger subsequently confirmed it was investigating a specific issue concerning CryptoBilis, which has been told “to pause all sales and shipments of Ledger devices.”
Users who bought devices from CryptoBilis in the past 90 days were also advised not to initiate setup and, if they’ve already done this, move assets to a new Ledger signer.
There have been a reports on X and Reddit of wallet-draining by Ledger users. I traced the theft addresses and identified inflows from more hundreds of victim wallets across several major blockchains, including Ethereum, TRON, and Bitcoin. Total losses $86M+… pic.twitter.com/c5dhQeAZ0l — Specter (@SpecterAnalyst) October 9, 2026
Read more: Ledger sued for $500M over its many data breaches
It said, “We will continue to inform customers of updates as the investigation progresses.”
CryptoBilis is a crypto wallet hardware seller that claims to be a “trusted Web3 brand in Southeast Asia” that sells Ledger, Trezor, OneKey, Tangem, and SafePal wallets, among other brands.
It claims to be “the authorized reseller of Ledger products in Malaysia.”
Former Mt Gox CEO Mark Karpelès highlighted yesterday that Ledger wallets sold by resellers have been found to have been tampered with and implanted with spyware designed to steal passkeys.
When approached for comment, Ledger redirected Protos to its recent X statement and said, “We have nothing further to add at this time.”
Ledger reports are causing a panic
Security researcher Taylor Monahan has warned several accounts sharing reports of Ledger wallets being drained that they’re causing a panic and making people think there’s a zero-day vulnerability when there doesn’t seem to be one.
She highlighted the risks of phishing attempts, fake Google ads, and phony applications that could drain a user looking to migrate their funds in a panic.
Ethereum researcher Justin Drake recently warned crypto holders to go “bunker mode” and move their assets somewhere safe to avoid the risk of AI breaking elliptic curve cryptography within “months.”
Monahan also expressed that Drake’s post may do “more harm than what it’s warning against” before highlighting the risk of phishing links in Google results.
Protos has reached out to CryptoBilis for comment and will update this piece should we hear anything back.
Got a tip? Send us an email securely via Protos Leaks. For more informed news and investigations, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.
The post Ledger says Southeast Asia reseller linked to $86M draining appeared first on Protos.
