Ledger confirmed that Ledger is investigating a specific issue concerning Southeast Asia reseller CryptoBilis. Ledger users who purchased wallets from CryptoBilis have reportedly lost over $80 million so far in an ongoing hack. Crypto analysts Specter and Tanuki42 first noted reports of Ledger users losing funds. Specter and Tanuki42 traced wallet addresses and estimated losses between $72 million and over $86 million.
CryptoBilis has been told to pause all sales and shipments of Ledger devices. Customers who bought devices from CryptoBilis in the past 90 days were advised not to initiate setup. Customers who had already completed setup were advised to move assets to a new Ledger signer. Ledger said Ledger will continue to inform customers as the investigation progresses. Asked for comment, Ledger directed inquiries to Ledger's recent statement on X and said Ledger had nothing further to add at this time.
CryptoBilis sells hardware wallets and claims to be a trusted Web3 brand in Southeast Asia. CryptoBilis says CryptoBilis sells Ledger, Trezor, OneKey, Tangem and SafePal wallets, among other brands. CryptoBilis claims to be the authorized reseller of Ledger products in Malaysia. CryptoBilis was asked for comment.
Former Mt Gox CEO Mark Karpelès said yesterday that Ledger wallets sold by resellers had been found tampered with and implanted with spyware designed to steal passkeys.
Security researcher Taylor Monahan warned several accounts sharing reports of drained Ledger wallets that the accounts were creating panic about a zero-day vulnerability. Monahan said there did not seem to be such a vulnerability. Monahan highlighted risks from phishing attempts, fake Google advertisements and phony applications that could drain users seeking to move funds in a panic.
Ethereum researcher Justin Drake recently urged crypto holders to move assets somewhere safe against the risk that AI could break elliptic curve cryptography within months. Monahan said Drake's post might cause more harm than the danger Drake was warning against. Monahan also highlighted the risk of phishing links in Google results.

