Ledger Investigates CryptoBilis Over $86M in Wallet Losses

iconNS3
Share
AI summary iconSummary
Ledger is investigating CryptoBilis, a reseller linked to over $86 million in wallet losses. Analysts Specter and Tanuki42 traced the damage to wallets bought through the firm. Ledger told recent buyers to stop setup and move funds to a new signer. CryptoBilis, an authorized reseller in Malaysia, has paused sales. Mark Karpelès said devices were tampered with and infected. Taylor Monahan warned of phishing and fake ads, noting no zero-day flaw. Fear and greed index remains volatile as altcoins to watch face renewed scrutiny. Justin Drake urged users to secure assets against AI risks, though Monahan said panic is unwarranted.

Ledger confirmed that Ledger is investigating a specific issue concerning Southeast Asia reseller CryptoBilis. Ledger users who purchased wallets from CryptoBilis have reportedly lost over $80 million so far in an ongoing hack. Crypto analysts Specter and Tanuki42 first noted reports of Ledger users losing funds. Specter and Tanuki42 traced wallet addresses and estimated losses between $72 million and over $86 million.

CryptoBilis has been told to pause all sales and shipments of Ledger devices. Customers who bought devices from CryptoBilis in the past 90 days were advised not to initiate setup. Customers who had already completed setup were advised to move assets to a new Ledger signer. Ledger said Ledger will continue to inform customers as the investigation progresses. Asked for comment, Ledger directed inquiries to Ledger's recent statement on X and said Ledger had nothing further to add at this time.

CryptoBilis sells hardware wallets and claims to be a trusted Web3 brand in Southeast Asia. CryptoBilis says CryptoBilis sells Ledger, Trezor, OneKey, Tangem and SafePal wallets, among other brands. CryptoBilis claims to be the authorized reseller of Ledger products in Malaysia. CryptoBilis was asked for comment.

Former Mt Gox CEO Mark Karpelès said yesterday that Ledger wallets sold by resellers had been found tampered with and implanted with spyware designed to steal passkeys.

Security researcher Taylor Monahan warned several accounts sharing reports of drained Ledger wallets that the accounts were creating panic about a zero-day vulnerability. Monahan said there did not seem to be such a vulnerability. Monahan highlighted risks from phishing attempts, fake Google advertisements and phony applications that could drain users seeking to move funds in a panic.

Ethereum researcher Justin Drake recently urged crypto holders to move assets somewhere safe against the risk that AI could break elliptic curve cryptography within months. Monahan said Drake's post might cause more harm than the danger Drake was warning against. Monahan also highlighted the risk of phishing links in Google results.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.