Coincidence? 90 million Ledger users stolen; reseller changed hands just two months ago.

There's a rather coincidental timing in the company registration information.

Author: Seed.eth, BitpushNews

Another security incident has occurred, leaving people in the cryptocurrency community in a state of shock.

On Friday evening Beijing time, a group of Ledger users reported on X and Reddit that their wallets had been emptied, and on-chain tracking estimated the suspected losses at between $86 million and nearly $90 million.

However, this time it wasn't "Ledger itself that was hacked." The company stated that it has launched an investigation, but has not yet confirmed that the device was tampered with, nor is there any evidence that its firmware or the entire product line was compromised. The problem lies with a single distribution channel: CryptoBilis, an authorized distributor located in Southeast Asia.

sr4xQveh9w2r0DiMCxPw4w7yqUlD6JB00xfC54Pn.png

Supply chain attack: shady dealings in distribution channels

CryptoBilis is an authorized reseller of Ledger in Indonesia, Malaysia, and the Philippines. Founded in Malaysia in 2020, it also sells hardware wallets from multiple brands, including Trezor, OneKey, Tangem, and SafePal. Its business extends beyond device sales, encompassing crypto payment integration and community event management, making it a leading channel in Southeast Asia.

However, the official figures for the number of Ledger units sold and their market share in these three markets have never been disclosed.

xRnwOLDzBFmgybktCtiFPRbvyvI7McLTJ4Cr5ibk.jpeg

Incidentally, there's a rather coincidental date in the company registration information: CryptoBilisunderwent achange of ownershiponAugust 3, 2026, with a person named "Jiaming," registered inHeilongjiang, China,acquiring100% of the company's shares. This occurred approximately two months after this incident came to light. However, there is currently no evidence to suggest a connection between the two events, but the timing is certainly noteworthy.

MwSzU6LbY2loYD9CUGBiawRZyNexWKKQndebT4bM.jpeg

drIlogmmmMko9ynyHEmH14E0GyE5Q33QK2puJXiJ.jpeg

On-chain analyst Specter, after tracking the relevant receiving addresses, stated that the funds originated from hundreds of wallets spanning Bitcoin, Ethereum, and Tron, totaling over $86 million. MistTrack tracked losses approaching $90 million.

Lookonchain detected that an address purchased 80 BTC at approximately $65,000 each about four months ago, then bought Ledger from CryptoBilis, deposited all the Bitcoin, and shortly after, transferred it out. Another user bought equipment from the same dealer three weeks ago, deposited 7 million USDT, and had it emptied in about ten hours.

1NvRXoVi2x5c1pyAdHNnV6bAIyR08WrXGNAIgUCT.jpeg

Some users reported that their mnemonic phrases were handwritten and locked in a safe, and they didn't sign the device, yet their money was still transferred out. If this is true, it seems more like the seed was leaked during the generation or display stage, rather than a subsequent phishing attempt.

The closest we've come to the truth with a physical teardown of the object, from Mark Karpelès, former CEO of Mt. Gox.

He claims to have disassembled a Ledger that was shipped from Malaysia. The outer packaging was intact and appeared fine at first glance. However, in the place where the screen cushioning pad should have been, something extra had been inserted: a circuit board with an LTE communication module, antenna, and eSIM, connected to the Ledger's SPI bus via a microcontroller. It could read the characters displayed to the user on the screen and transmit the data after the mnemonic phrase was set. In his opinion, this modification was undetectable by the Ledger's own software and passed Genuine Check. The only problem might be that the battery drained a little faster.

TkLPisPDRKcP4OCPcA7tfXArnXcbg3le0cUfAAx1.png

How do hardware wallets "crash and burn"?

Chain Ink compiled a list of 10 hardware wallet security incidents in 2026, of which only two resulted in actual losses: the Coldcard firmware vulnerability and the Ledger reseller CryptoBilis incident. Specifically:

j4QocgDlqFbCzIqkr2CpzW3Y0JblCE5hD1QgsJCu.jpeg

Firmware bugs.During a code migration in 2021, Coldcard made a mistake in its code handling, causing the hardware random number chip to be omitted during seed generation, reverting to a software pseudo-randomization scheme. The most severely affected Mk3 was affected, with its effective randomness collapsing from 128 bits to approximately 40 bits, allowing attackers to brute-force it remotely without physical contact with the device. Coinkite released emergency firmware, but explicitly stated that the new firmware could not repair old seeds; assets had to be regenerated and migrated. This was the largest loss this year, exceeding $110 million.

The supply chain is being manipulated.Devices are being tampered with or implanted before they even reach you. Ledger itself fell victim to this in 2023: a former employee was phished, and a malicious version of Connect Kit was sent to NPMJS, injecting stealing code into DApps that relied on the library. This malicious code was active for about two hours, resulting in losses of approximately $480,000 to $600,000. If the CryptoBilis incident is ultimately confirmed to be due to hardware modification, it falls into the same category—the attacker doesn't touch your keys, only peeks at the mnemonic phrase on the screen, and then transmits it over the cellular network.

Phishing for mnemonic phrases.In September 2026, attackers compromised Brevo, Trezor's third-party email service provider, and sent "STM32 vulnerability alerts" to 347,000 subscribers using Trezor's legitimate domain. Approximately 2,500 people clicked on the malicious links. The emails originated from the real domain and passed SPF/DKIM/DMARC checks, making them technically almost impossible to detect. The attackers were not exploiting a hardware vulnerability, but rather the users' trust in official notifications.

Third party dragged into itIn 2020,Ledger suffered a breach due to a third-party API vulnerability, resulting in the leakage of over 1 million email addresses and approximately 270,000 customer details. In January 2026, its payment and logistics partner, Global-e, was again compromised. Trezor's logistics provider, ShipMonk, was also hacked in August 2026, with approximately 81,000 customer records stolen. While the hardware and private keys remain intact, this data becomes a precise target pool for targeted phishing and offline threats. You are safe, but your shipping label is not.

Laser chip skidding.Both Tangem and Trezor Safe 7 have attempted laser fault injection, but neither suffered financial losses. The process is highly complex and costly, currently mostly confined to laboratory settings, but it demonstrates that physical defenses are not absolute.

These things are more important than changing brands.

As of press time, Ledger has requested CryptoBilis to suspend all sales and shipments, and advises users who purchased devices from that reseller within the past 90 days to: not power on uninitialized devices, and if already configured, to replace them with new devices and new torrents as soon as possible, and to treat old torrents as already leaked. CZ also forwarded the message, reminding recent buyers to be vigilant, believing this is more like a localized supply chain attack, and that Ledger remains a brand that has stood the test of time.

53NIdcn71fXShm6bodYD4ipgRrplpnquWc3NPdS7.png

For individuals holding crypto assets, the following suggestions are essential to keep in mind:

  • Only buy from the official website. Authorized dealers, intact heat shrink film, and seemingly authentic packaging don't prove the product hasn't been opened and resealed. Don't gamble your assets to save a little money.
  • The seed only recognizes the screen. It is only generated, handwritten, and stored offline on the device screen. Never use the words pre-printed in the packaging, and never enter them into any website or customer service. Anyone who proactively asks for your mnemonic phrase is a scammer.
  • If you purchased from CryptoBilis within the last 90 days, follow Ledger's instructions. Don't turn on the device if it's not initialized; if it's already set up, get a new device and a new torrent as soon as possible, and treat the old torrent as already leaked. Don't hesitate, don't take chances.
  • Those who purchased from official channels and have been using them normally need not panic. There is currently no indication of these reports. However, before the investigation is concluded, avoid large transactions on third-party, second-hand, or unclear-origin devices. The security boundary of a cold wallet begins before you even receive it.
  • For those with ample funds, consider multiple signatures, distributing signature generators across different batches or even different brands.

This incident has not yet reached a final conclusion, but it serves as a reminder that cold wallets are never automatically synonymous with security. What truly determines the risk is the entire chain from the factory to your hands.

Source:Global Cybersecurity Alliance (GCSA)
Website:www.gcsa.org