Sealed hardware-wallet package and security key under forensic inspection

Ledger Warns Reseller Customers as It Investigates Reported Wallet Losses

• October 9, 2026 11:13 pm • Comments

Ledger is investigating reports of lost cryptocurrency tied to devices purchased from CryptoBilis, a reseller serving customers in Southeast Asia, while urging affected buyers to take precautions before the cause is known.

The warning is serious, but the facts still have limits. Ledger says its own infrastructure, systems and services were not compromised.

The company has not confirmed how many customers were affected, the value of any losses, or whether the devices themselves were tampered with.

That leaves customers with a practical security decision in the middle of an unfinished investigation.

According to Cointelegraph, Ledger asked CryptoBilis to pause sales and shipments of Ledger devices while the company investigates. CryptoBilis is listed as an authorized reseller in Indonesia, Malaysia and the Philippines.

Ledger advised people who bought a device from the reseller during the previous 90 days not to initialize it. Customers who already set one up were told to consider moving their assets to a new signer using a newly generated recovery phrase.

Ledger has not said how many reports it received or how much cryptocurrency may be missing. It also has not identified a technical cause, confirmed that any device was altered, or established that the manufacturer’s systems played a role.

The company told the publication that the incident appeared limited to the reseller and affected market. It said it had received no reports involving devices purchased directly from Ledger, making the reseller connection the focus of the current precaution rather than proof of a global product failure.

The company posted the precaution publicly:

Separate onchain researchers identified addresses they believe are connected to tens of millions of dollars in suspicious transfers across Bitcoin, Ethereum and Tron. Those estimates range above $70 million, but Ledger has not confirmed them or established that every address is connected to the reseller investigation.

That distinction matters. A cluster of suspicious transfers can help responders trace funds, but it does not by itself prove how a device or recovery phrase was compromised—or that every reported loss came through the same route.

Security Alliance amplified the address information and asked potential victims to contact its incident-response team:

A hardware wallet protects keys only when the device, setup process and recovery phrase remain trustworthy. If a buyer has reason to doubt any part of that chain, moving funds to a freshly generated wallet on a trusted device can separate those assets from the old credentials.

The most important point is that a “new signer” needs a genuinely new recovery phrase. Restoring the old phrase on different hardware would preserve the same underlying secret and would not remove the risk if that phrase had already been exposed.

Customers should rely on Ledger’s official support channels and avoid unsolicited messages offering “recovery” help. No legitimate responder needs a customer’s recovery phrase.

The investigation may eventually identify a specific cause. Until then, Ledger’s targeted precaution is clearer than the online speculation: buyers connected to the named reseller should treat the device and its original setup as potentially unsafe, while everyone else should avoid turning an unresolved regional incident into a claim that Ledger’s entire system was breached.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.