Crypto
Ledger Wallet Theft: $86 Million Drained From Users
Ledger investigates reports of $86 million in wallet thefts linked to a reseller, raising fresh concerns about hardware wallet security.
Ledger investigates reports of $86 million in wallet thefts linked to a reseller, raising fresh concerns about hardware wallet security.

Hundreds of Ledger users reportedly woke up on October 9 to emptied wallets, with an estimated $86 million gone.
Ledger has now linked the reports to a Southeast Asian reseller called CryptoBillis and asked it to halt sales. The cause, and how thieves reached funds stored offline, remains unconfirmed.
User Specter Analyst said on X that its trace shows losses above $86 million from wallet drains tied to Ledger users. Theft addresses collected funds from hundreds of victim wallets on several major blockchains.
Another report put the estimate at $86.96 million across 98 addresses. Security researcher tanuki42 had earlier estimated losses above $72 million and said the figure kept rising. Some reports suggest the final tally could approach $100 million.
Several victims said they never stored their seed phrases digitally. They said funds left their wallets anyway, which points away from the usual explanation of a leaked online backup. The claims, however, remain unverified and subject to further investigation.
Ledger Support confirmed it is investigating reports of stolen funds from users who bought devices from CryptoBillis. The distributor reportedly operates in Southeast Asia, making most of the victims from the same region. Ledger asked the seller to pause all device sales and shipments.
Ledger further advised that buyers who purchased from CryptoBillis in the past 90 days should not set up uninitialized devices. Those who already did should move assets to a new device with a new recovery phrase.
Ledger has not confirmed the $86 million total. It also has not said how thieves took the funds or whether devices were tampered with.
Hardware wallets keep private keys offline, so remote drains of this scale are rare. Users usually lose funds through phishing, malware or exposed recovery phrases. A device-level compromise would be far more serious.
Specter listed 10 theft addresses that held just over $25 million at last check. That suggests thieves already moved most of the funds.
Three Bitcoin addresses received more than 211 BTC between October 8 and 9, according to on-chain tracking.
The reseller angle matters. A third-party channel opens room for supply chain tampering, where someone alters a device before it reaches the buyer. A compromised device could expose keys even when owners guard their phrases. Investigators have not confirmed that theory.
This is not Ledger's first security scare. In 2020, a breach through its e-commerce provider exposed customer data, including about 270,000 physical addresses.
The data stayed in circulation, so phishing and extortion attempts against customers continued for years.
In December 2023, attackers hijacked Ledger's Connect Kit library after phishing a former employee. Malicious code drained roughly $600,000 from users of connected apps. Ledger pushed a fix within hours, and losses stayed limited. Earlier this year, a fake Ledger Live app reportedly drained about $9.5 million from more than 50 users.
Hardware wallets face wider pressure too. A reported seed-generation flaw in Coldcard devices caused losses above $88 million in August.
The distinction matters for the industry. A reseller-specific fault would limit the damage to one sales channel. A flaw in Ledger firmware would put millions of devices at risk.
The earlier Ledger incidents received fixes, yet the current case remains open. That gap matters for confidence in the sector, since buyers cannot easily verify what happens before a device arrives.
No comments yet