A crypto hardware wallet is supposed to be the one device nobody can touch remotely. On October 9, 2026, that assumption broke for hundreds of people in Southeast Asia. Ledger, the French hardware wallet maker, confirmed it is investigating asset losses tied to devices sold through CryptoBilis, an authorized reseller in Indonesia, Malaysia, and the Philippines. By the next morning, on-chain investigators at Bitquery had traced $92.9 million drained from 311 wallets across five blockchains, a figure that kept climbing as researchers found addresses the first public lists missed.

The attack matters beyond the dollar figure. Hardware wallets exist to keep a 24-word recovery phrase away from the internet entirely, the one piece of information that lets anyone rebuild a wallet and spend its coins. This incident suggests someone captured that phrase before the owner ever touched a keyboard, through the supply chain itself rather than a phishing email or a malicious browser extension. That is a harder problem to defend against, and it is why this case is already drawing comparisons to the Coldcard wallet theft traced earlier this year.

The headline numbers behind the Ledger CryptoBilis hack

Two independent on-chain researchers posted the first warnings. The analyst known as tanuki42 listed eight drain addresses, while another researcher, Specter, posted ten addresses with losses above $86 million. Bitquery, a blockchain data firm, ran its own trace across every chain involved and came back with a larger number: $92.9 million pulled from 311 wallets on TRON, Bitcoin, Ethereum, BNB Chain, and Polygon. The gap exists because the thief also emptied wallets on BNB Chain and Polygon that the earlier lists did not cover, plus five additional TRON addresses.

TRON carried the heaviest losses by far. Victims there lost roughly 70.2 million USDT plus some TRX, worth about $70.5 million from 131 wallets. Bitcoin holders lost 203.8 BTC, around $16.8 million, from 122 wallets. Ethereum victims lost 1,230 ETH along with $577,000 in stablecoins and a large batch of PEPE tokens, totaling about $3.7 million across 33 wallets. BNB Chain and Polygon accounted for the smallest shares, $1.45 million and $580,000 respectively. Some wallets were drained on more than one EVM chain, which is why the wallet count and the chain-by-chain victim counts don’t add up to a clean sum.

ChainVictim walletsAssets takenValue (Oct 9 prices)
TRON13170.2M USDT + TRX$70.5M
Bitcoin122203.8 BTC$16.8M
Ethereum331,230 ETH + stablecoins + PEPE$3.7M
BNB Chain2759.8 BNB + stablecoins$1.45M
Polygon13579,773 USDC$0.58M
Total311Five chains$92.9M

Ledger itself has not confirmed a final total. The company’s statement, posted the same day, acknowledged losses among users who bought from CryptoBilis and asked the reseller to halt all sales and shipments. That gap between Ledger’s cautious language and the independent trace published by Bitquery’s investigation is itself part of the story: a company whose entire pitch rests on security now has researchers outside the company publishing numbers it has yet to verify.

Forty-seven minutes across five blockchains

The drain did not happen all at once in one place. The first transfers moved on TRON, the network many users across Asia rely on to hold and move USDT. Within 47 minutes, the same actor had emptied wallets on Ethereum, BNB Chain, Polygon, and Bitcoin, hitting five separate blockchains back to back. Pulling that off cleanly, without fumbling a key or triggering a chain’s native fraud alerts, points to a single operator working from a prepared list rather than several opportunistic actors stumbling onto exposed wallets independently.

The clearest evidence for a single thief came from TRON. Twenty-five separate wallets signed the exact same approval transaction within a three-second window. That kind of synchronized signing only happens if one party already holds every one of those wallets’ private keys, something that would be virtually impossible to coordinate through phishing or malware spread across hundreds of separate victims in the same three seconds. It strongly suggests the keys were captured well before the drain, most likely during setup, and simply held in reserve until the operator was ready to move.

Two weeks of rehearsal before the drain

Bitquery’s trace found something that usually doesn’t survive in public reporting on crypto theft: a rehearsal period. Starting September 25, two addresses, one on TRON and one on Ethereum, ran a repeating test. Each would send a wallet a few dollars plus gas money, have that wallet approve a transaction, then pull the small amount back. The TRON address ran the loop 21 times. The Ethereum address ran it 20 times. The final two test runs, on October 7, landed just 23 seconds apart.

One of those practice runs, on October 2, pulled three dollars into an address that went on to receive $36 million on the day of the actual drain. In other words, the attacker had already mapped out which wallet would hold the bulk of the stolen funds a full week before touching any real money. That level of preparation reads less like a smash-and-grab and more like a planned operation against a known list of targets, which fits with a supply-chain theory: the thief likely built that list from devices sold through one specific channel, not from a broad phishing sweep.

Inside the suspected implant: how a tampered wallet leaks a seed phrase

Ledger has not confirmed the exact mechanism publicly, but two separate claims have emerged that point the same direction. Mark Karpelès, the former CEO of the collapsed Mt. Gox exchange, says he bought a Ledger device through a Malaysian channel and found a hidden module containing a SIM-style chip concealed inside the screen padding, with the outer packaging showing no sign of tampering. Separately, 23pds, the chief information security officer at blockchain security firm SlowMist, described a more detailed technical path: a small microcontroller wired into the device’s screen data lines, recording the recovery phrase character by character as it displays during setup, then transmitting the captured words out over a built-in LTE or eSIM connection.

What makes that approach effective is that it skips the part of a hardware wallet that is actually hard to break. The Secure Element chip inside a Ledger is built to stop anyone from directly reading out the private key material it stores. It does nothing to control what gets drawn on the screen during the brief moment the 24 recovery words are shown to a new owner. An implant tapped into that display path never has to touch the cryptography at all. It just has to watch.

Suspected attack path (per SlowMist's 23pds, unverified by Ledger):

1. Device manufactured, Secure Element intact and uncompromised
2. Microcontroller tapped onto screen's SPI data lines (post-factory)
3. User powers on device, generates new wallet, 24-word phrase renders on screen
4. Implant reads each word as it is drawn, buffers the full phrase
5. Built-in LTE/eSIM chip transmits captured phrase to attacker
6. Attacker rebuilds wallet offline on separate hardware, waits
7. Weeks later: synchronized drain across all captured wallets

Two other, less exotic explanations remain possible and have not been ruled out. One is simple pre-setup fraud: power on the device before shipping, generate a wallet, write down the words, then reseal the box so the buyer believes they are initializing a blank device. The other is a database breach at the reseller followed by targeted phishing against its actual customer list. Binance founder Changpeng Zhao weighed in publicly, describing the pattern as a supply-chain attack limited to a single vendor and affecting a small number of buyers of counterfeit or tampered devices, while still backing Ledger’s broader track record as one of the longer-established names in hardware wallets.

CryptoBilis: an “official” reseller with a murky ownership change

CryptoBilis was not a fly-by-night storefront. It appeared on Ledger’s own distributor listing as an authorized seller covering Malaysia, Indonesia, and the Philippines, founded in Kuala Lumpur in 2020 and selling other hardware wallet brands including Trezor, OneKey, Tangem, and SafePal alongside Ledger’s lineup. For a buyer checking Ledger’s own site before purchasing, that listing functioned as a safety signal, even though “authorized to resell” and “supply chain integrity verified” are two very different guarantees.

Corporate filings reviewed by reporters show CryptoBilis changed hands in 2026. A shareholder registered at an address in Heilongjiang Province, China, took 100% equity in the company effective August 3. The original founding team has since said it lost operational control after the handover and is no longer part of daily operations. The buyer also had former executives sign a non-disclosure agreement covering the transaction’s details, one that runs until October 19, which meant that when the hack went public on October 9, the people who could speak most directly to what changed inside the company were contractually barred from doing so. No evidence yet ties the ownership change directly to the theft. The timing alone is enough to keep investigators asking.

Who got hit: a victim profile built from wallet age

Ledger’s public guidance focused on buyers from the last 90 days, but Bitquery’s wallet-age analysis suggests the exposure window runs longer. Checking when each victim wallet first received funds, researchers found 6 in 10 fell inside that 90-day window, while more than 8 in 10 had been funded since June 2026, several weeks earlier than Ledger’s cutoff. June alone accounted for 42 of the 131 affected TRON wallets receiving their first deposit, a spike sitting just outside the advised window. A wallet’s first deposit isn’t proof of purchase date, but it is a reasonable proxy, and it points to a device-tampering problem that may stretch back roughly four months rather than three.

The victims weren’t all individual savers either. At least one drained TRON wallet had received 33.5 million USDT since October 1 and had been paying most of it back out to 29 separate addresses, a pattern consistent with a business treasury rather than a personal holding. One Bitcoin wallet received 80 BTC on September 29 and lost the entire balance in a single block three days later. The targets ranged from newly onboarded retail buyers to what looks like at least one operating business, all funneled through the same compromised retail channel.

Where the stolen money went

Almost all of the TRON losses were in USDT, a stablecoin that Tether, its issuer, can freeze at will. Knowing that, the thief moved fast to scatter the funds somewhere Tether couldn’t reach. Of the 70.2 million USDT taken on TRON, about $20 million crossed to Ethereum through the USDT0 bridge in 40 equal pieces, where fresh wallets swapped it on UniswapX for roughly 7,994 ETH. Another $14.9 million was converted into USDD, a separate stablecoin Tether has no authority over. The remainder moved through swap services including Relay.link, HiFiSwap, and NEAR Intents, a laundering pattern similar to other 2026 incidents that relied on cross-chain bridges to break the trail.

As of 16:45 UTC on October 9, roughly $79 million of the total remained traceable on-chain rather than fully laundered. The Bitcoin, 203.8 BTC worth about $16.8 million, had not moved at all since the theft. Around 14,810 ETH, worth close to $36.9 million, sat in a handful of attacker-controlled wallets, most of it purchased with the stolen USDT. Another 15.1 million USDD sat across seven TRON wallets. That leaves roughly $11 million spent through other services or not yet fully traced.

Tether’s freeze and the race into Tornado Cash

Tether moved quickly once the drain addresses went public. Roughly ten minutes after the first researcher posted drain addresses, Tether began blacklisting linked wallets, ultimately freezing 37 addresses within two hours. Twenty of those still held about half a million USDT each at the time of the freeze, locking up roughly $10 million. A freeze stops the coins from moving, but it does not automatically return them to victims, though Tether has the technical ability to later destroy and reissue frozen tokens if it chooses to.

The thief didn’t wait around. Less than two hours after Ledger’s public statement, the attacker began feeding ETH into Tornado Cash, the mixing service that breaks the on-chain link between deposit and withdrawal. Three batches of roughly 400 ETH each, about 1,254 ETH total, went into the mixer within a 40-minute window on the afternoon of October 9. At that pace, researchers estimated the attacker’s remaining ETH holdings could clear the mixer within a day, putting a meaningful share of the stolen funds permanently out of reach of any future freeze or clawback effort.

How this compares with 2026’s other hardware and exchange hacks

The CryptoBilis hack lands in a year that has already produced several large crypto security failures, though the attack vectors differ sharply from one incident to the next. The Bitget exchange breach in September, covered in our reporting on the $387.5 million hot-wallet compromise, involved attackers spoofing withdrawals from inside Bitget’s own backend systems, a very different failure point than a tampered consumer device sold through a third party. The 79thVault incident on BNB Chain, roughly a week before the Ledger disclosure, lost about $12.5 million when a wallet holding a privileged operator role on the protocol’s token contract drained its own liquidity pool, a case of credential compromise rather than hardware tampering.

IncidentDate (2026)Attack vectorEstimated lossFunds status
Ledger / CryptoBilisOct 9Suspected hardware supply-chain implant$92.9M~$10M frozen by Tether, rest largely moved
Bitget exchange hackSept 24Hot-wallet backend compromise$387.5MPartially traced, no confirmed recovery
79thVault (BNB Chain)Oct 7Privileged operator key compromise$12.5MNo recovery reported
NEAR IntentsOct 1Omni-deposit bridge exploit$3.8MReturned within 24 hours

Ledger has its own history with security incidents that predates CryptoBilis. A 2020 data breach exposed customer emails and home addresses, a serious privacy failure but not one that touched user funds directly. In December 2023, attackers compromised Ledger’s Connect Kit code library, a piece of software some crypto websites relied on, and used it to trick users into approving malicious transactions for a few hours before the issue was caught. Both of those were software or data problems that Ledger could patch from its end. The CryptoBilis case, if the implant theory holds up, is different in kind: it is a hardware-level compromise that happened after the device left Ledger’s factory and before it reached a paying customer, a weak point no software patch can close retroactively.

Market impact: what this means for the hardware wallet business

Hardware wallets exist because software wallets connected to the internet carry obvious risk, and millions of crypto holders have paid a premium specifically for a device marketed as immune to remote attacks. A supply-chain compromise undercuts that pitch at its foundation, not because the device itself failed, but because the retail channel around it did. That distinction matters for how the industry responds. Ledger can’t simply ship a firmware update to fix a reseller’s distribution chain.

Expect buying behavior to shift toward direct-from-manufacturer purchases over the next several months, a pattern our hardware wallet security checklist already flags as the safest default. Competing wallet makers, including Trezor, OneKey, Tangem, and SafePal, all of which CryptoBilis also sold, will likely face pressure to publicly audit their own regional distribution partners rather than wait for their own version of this story to break. Regulators in Malaysia, Indonesia, and the Philippines, where financial authorities have been tightening digital asset oversight, now have a concrete domestic incident to point to when pushing for distributor licensing requirements specific to hardware security products, not just exchanges.

What happens next: five predictions

  • Ledger and its competitors will accelerate tamper-evident packaging and serial-based verification tools that let buyers confirm a device hasn’t been opened since leaving the factory, rather than relying on shrink-wrap alone.
  • CryptoBilis’s August ownership change will draw scrutiny from Malaysian and Indonesian regulators, and other regional hardware wallet resellers may face similar ownership-disclosure questions in the coming months.
  • A meaningful share of the roughly $79 million still traceable on October 9 will be gone within weeks as more of it clears Tornado Cash or gets swapped into USDD, leaving Tether’s $10 million freeze as close to the ceiling of what gets clawed back.
  • Researchers will apply Bitquery’s rehearsal-pattern detection, the two weeks of small test loops before the drain, to comb through dormant wallets elsewhere, likely surfacing other prepared-but-not-yet-executed thefts tied to compromised devices.
  • Hardware wallet makers will push toward secure-boot attestation and anomaly detection on the display pathway itself, the specific weak point the suspected implant exploited, since the Secure Element chip was never the part that failed here.

What CryptoBilis buyers and other hardware wallet owners should do now

Ledger’s own advice for confirmed CryptoBilis buyers is direct: don’t power on a device that has never been activated, and if coins are already stored on one, treat the recovery phrase as compromised and move funds to a brand-new device with a freshly generated phrase immediately. Given Bitquery’s finding that risk extends back to wallets first funded in June, buyers from that reseller going back roughly four months, not just the last 90 days, should take the same precaution rather than assume they fall outside the affected window.

For everyone else, the incident is a reminder that “authorized reseller” and “verified supply chain” aren’t the same claim, even when a manufacturer’s own website lists the seller. Buying directly from the manufacturer remains the lowest-risk option, and anyone generating a new wallet on any hardware device should do it somewhere the screen can’t be observed by a hidden camera or implant, ideally offline and away from a shared or public setting. Readers who want a step-by-step walkthrough of safer setup practices, including offline generation, can find that in our guide to air-gapped Bitcoin cold storage.

The broader lesson sits uncomfortably close to the core promise of self-custody. A hardware wallet is supposed to remove the need to trust any third party with your keys. This incident shows that promise only holds if every link in the chain between factory and buyer holds too, and in this case, at least one of those links apparently didn’t. Readers tracking the broader pattern of 2026’s crypto thefts can follow ongoing coverage in our cryptocurrency section.

Frequently asked questions

Was Ledger itself hacked?

Nothing public so far points to a breach inside Ledger’s own systems. The losses are tied to devices bought from CryptoBilis, a third-party reseller, and Ledger says it is investigating how the affected wallets’ recovery keys were obtained.

What is CryptoBilis?

CryptoBilis is a hardware wallet retailer founded in Kuala Lumpur in 2020, listed on Ledger’s own distributor page as an authorized seller for Malaysia, Indonesia, and the Philippines. It also sold Trezor, OneKey, Tangem, and SafePal devices. Ledger ordered it to halt all sales and shipments on October 9, 2026.

How much was stolen in the Ledger CryptoBilis hack?

Bitquery’s trace puts the total at $92.9 million taken from 311 wallets across TRON, Bitcoin, Ethereum, BNB Chain, and Polygon. Earlier public estimates from individual researchers ranged from about $72 million to $87 million, based on smaller sets of known drain addresses. Ledger has not confirmed a final figure.

How did the thief get the recovery phrases?

The exact method hasn’t been confirmed by Ledger. Independent claims point to a hidden hardware implant that reads the recovery phrase off the device’s screen during setup and transmits it over a built-in cellular connection, though pre-set devices and a reseller database breach followed by phishing remain unruled-out alternatives.

Can a Ledger hardware wallet be hacked?

The device is designed so the recovery phrase never leaves its Secure Element chip under normal use. If someone else obtains that phrase through a tampered device, a pre-set mnemonic, or a phishing site, they control the wallet without ever touching the physical device. In this case, the evidence points to the keys being captured before the owner ever used the device.

Is my Ledger safe if I didn’t buy from CryptoBilis?

Devices bought directly from Ledger or from other authorized resellers are not implicated in this specific incident. The safest general practice remains buying directly from the manufacturer whenever possible, since this case shows that “authorized reseller” status doesn’t guarantee supply-chain integrity.

Can the stolen crypto be recovered?

About $10 million in USDT is currently frozen by Tether, which could later be destroyed and reissued to victims. The stolen Bitcoin hasn’t moved since the theft, and a large share of the Ethereum still sits in identifiable attacker wallets. Funds that have already passed through Tornado Cash or been converted into USDD are far harder to trace or recover.

How does this compare to past Ledger security incidents?

Ledger’s 2020 breach exposed customer contact data but not funds. Its December 2023 Connect Kit incident involved a compromised software library that tricked users into signing malicious transactions for a few hours. The CryptoBilis case is different because it points to a hardware-level compromise introduced somewhere in the physical supply chain, after devices left Ledger’s factory and before they reached buyers.