Ledger probes CryptoBilis wallet reports; $86M estimate unverified
Ledger has asked CryptoBilis to stop shipments as it probes reported wallet drains; an investigator's $86 million estimate remains unverified, and buyers are told to act.
The Finality Desk3 min read#97b451

Ledger is investigating reports of missing crypto linked to devices sold by reseller CryptoBilis, and has asked the company to pause sales and shipments while it checks the reports. The suspected losses could exceed $86 million, but that figure comes from an on-chain investigator and has not been independently confirmed. CoinDesk’s report on Ledger’s investigation says Ledger has not identified a cause or confirmed that its devices were tampered with.
The reports concern funds traced across Bitcoin, Ethereum and Tron. Ledger advised customers who bought from CryptoBilis in the past 90 days not to start setting up an unused device. Customers who already set one up should consider moving assets to a new Ledger signer with a newly generated recovery phrase, according to the company’s support post cited by The Block.
What has Ledger confirmed about CryptoBilis?
Ledger has confirmed that it is investigating reports from customers who bought devices through CryptoBilis and has asked the reseller to pause all sales and shipments. The Block reports that CryptoBilis is listed as an official Ledger reseller in Indonesia, Malaysia and the Philippines. Ledger’s warning covers purchases from that reseller within the past 90 days.
The warning is a precaution, not a finding that the devices were compromised. Ledger has not confirmed that the reported wallet drains are connected, how many customers were affected, or whether the reseller’s devices caused any losses. It has also not confirmed a breach of its own systems or wallet technology.
Where does the $86 million estimate come from?
The figure is an estimate by pseudonymous on-chain investigator Specter, who said they traced suspected theft addresses across Bitcoin, Ethereum and Tron. Another researcher, tanuki42, separately reported more than $72 million moving to suspected theft addresses. The figures have not been independently verified, and it is unclear whether they cover overlapping transactions.
Specter initially described hundreds of victim wallets, but later said the number of affected wallets was not known. The amount traced to suspicious addresses therefore should not be treated as a confirmed total loss, nor as proof that all the reported incidents share one cause.
How could a tampered device put funds at risk?
A hardware wallet signs transactions using private keys held on the device. One possible supply-chain scenario is that a device reaches a buyer with a recovery phrase already known to someone else. If that phrase controls the wallet, another party could use it to access assets even while the buyer uses a hardware device to sign transactions. CoinDesk describes this as one possible explanation; there is no confirmation that it happened here.
That distinction matters: the current evidence describes reports of drained wallets associated with a reseller, not a confirmed flaw in a Ledger contract, signing process or device firmware. Ledger’s immediate advice is directed at recent CryptoBilis buyers: leave an unused device unset up, and consider transferring assets from an activated device to a new signer using a new recovery phrase. The investigation has yet to establish whether device tampering, another cause, or a link between the reported losses explains the activity.
Sources and documents
- CoinDesk’s report on Ledger’s investigation — coindesk.com
- The Block — theblock.co