Last updated: October 9, 2026. This is a developing story and we will update this page as Ledger publishes more.

On Friday, October 9, Ledger said it was investigating reports of stolen funds from customers in Southeast Asia who bought their devices through a reseller called CryptoBilis. Within hours, on-chain investigators were putting the losses at more than $86 million.

Below is what has been confirmed, what has not, how to check whether you are affected, and the lesson every hardware wallet owner should take from it.

What happened

Here is the sequence as it stands on October 9, 2026:

  1. Users started reporting drained wallets on X and Reddit. Many said they had bought Ledger devices from CryptoBilis, a Malaysian shop founded in 2020 that sells Ledger hardware and also operates in Indonesia and the Philippines (BeInCrypto).
  2. A pseudonymous on-chain investigator called Specter traced the theft addresses and found money flowing in from hundreds of victim wallets across Bitcoin, Ethereum and Tron. Specter's estimate was $86.96 million across 98 receiving addresses (Coinpedia). Another researcher, tanuki42, had earlier put it above $72 million and rising.
  3. Arkham data cited by Specter showed roughly $42 million in ETH, $17.6 million in BTC and $16.5 million in USDT sitting at those addresses (Decrypt).
  4. About an hour after Specter's post, Ledger Support responded. It said it was "investigating reports of loss of funds from users in Southeast Asia" and that "we have asked CryptoBilis to pause all sales and shipments of Ledger devices" (Bitcoin.com News).

Changpeng Zhao (CZ) told Ledger users to "remain vigilant," especially anyone who bought a device recently, and said the incident looked localized to a supply chain attack (KuCoin News).

What Ledger has told customers to do

Ledger's guidance is aimed at one group of buyers:

  • Bought from CryptoBilis in the last 90 days and have not set the device up yet? Do not set it up.
  • Bought from CryptoBilis in the last 90 days and already set it up? Move your funds to a new device with a brand new recovery phrase.

Ledger has said it will post updates as the investigation goes on (CoinDesk).

What is confirmed and what is not

A lot of what you will read on social media today is guesswork. Here is where things actually stand.

Confirmed by Ledger

  • It is investigating reported losses from CryptoBilis customers in Southeast Asia.
  • It has asked CryptoBilis to pause all sales and shipments.
  • Recent CryptoBilis buyers should not set up their devices, and those who already have should move their funds.

Not confirmed

  • The $86 million figure. It comes from independent investigators. Ledger has not endorsed it, and it is not yet clear that every theft address is linked to the reseller.
  • How the funds were taken. Ledger has not said whether devices were tampered with. No method has been confirmed.
  • How many people lost money. 98 receiving addresses does not mean 98 victims. Specter traced funds coming in from hundreds of wallets.
  • Any wider problem with Ledger devices. No outlet covering the story has reported evidence that Ledger's secure element, firmware or own sales channel was compromised (CoinDesk).

So was Ledger hacked?

On the evidence published so far, no. That is why "hack" is in quotation marks at the top of this page.

The pattern points at the supply chain: the stretch between the factory and your hands. When a hardware wallet passes through a middleman, that middleman has a window to open the box. A tampered or swapped device, or a "recovery phrase" printed on a card in the box, lets a thief know your keys before you ever send a coin to the wallet. They wait until a balance builds up, then sweep it.

That is the most likely explanation being discussed, and it fits the facts: losses clustered around buyers of one seller, across several chains, with victims saying their phrase was kept offline. But Ledger has not confirmed it, so treat it as a working theory until its investigation reports back.

Fake and tampered hardware wallets are an old trick. Earlier this year a researcher found counterfeit Ledger units on a Chinese marketplace that sent the buyer's PIN and recovery phrase straight to the attackers (BeInCrypto).

How to check if you are affected

Work through these in order.

1. Where did you buy your device? If you bought it from CryptoBilis, or from any shop in Malaysia, Indonesia or the Philippines that might have sourced stock from CryptoBilis, follow Ledger's instructions above today. If you bought directly from ledger.com, nothing reported so far applies to you.

2. Did you create your own recovery phrase? When you first set up a genuine hardware wallet, the device itself shows you a brand new list of words and asks you to write them down. If your phrase came printed on a card, a scratch-off sheet or a leaflet in the box, assume the wallet is compromised no matter where you bought it. Move the funds to a new wallet with a phrase you generated yourself.

3. Was the packaging right? Signs of a resold or opened box include broken or re-glued seals, a device that was already set up or asked for no PIN, extra paperwork telling you to "use this phrase", or a cable and accessories that look wrong. Any one of these is reason enough to stop.

4. Has anything moved that you did not move? Look up your addresses on a block explorer. If you see outgoing transactions you did not make, move what is left immediately to a wallet with a fresh phrase on a device bought from the manufacturer.

5. Watch for follow-up scams. Every wallet headline brings a wave of fake "Ledger Support" emails, texts and DMs. Ledger will never ask for your 24 words. Nobody legitimate will. If someone asks, it is a scam.

If you bought from Ledger directly, created your own phrase and nothing has moved, the most useful thing you can do is nothing. Moving funds in a panic, or typing your phrase into a "check your wallet" website, is how people lose money in weeks like this.

Why you should never buy a hardware wallet from a third party

CryptoBilis was a reseller that Ledger did business with (Crypto Briefing describes it as an authorized one). That is the uncomfortable part. Even a seller with the manufacturer's blessing is one more set of hands between the factory and you, and every extra set of hands is a chance for someone to open the box.

A hardware wallet has one job: to make sure the only person who ever knows your keys is you. Buying through a reseller, an Amazon marketplace listing, eBay, a Telegram seller or a "discounted" bundle adds risk for the sake of saving a few dollars or a week of shipping. On a device that will guard your savings, that trade never makes sense.

The rules are simple:

  • Buy only from the manufacturer's own website.
  • Never accept a device with a recovery phrase already in the box.
  • Generate your phrase on the device and write it down by hand, offline.
  • Run the manufacturer's authenticity check during setup.
  • Consider an extra passphrase, so that someone holding your 24 words still cannot open the wallet.

Our recommendation: Trezor, bought direct

At Learning Crypto we recommend Trezor hardware wallets. A few reasons:

  • Open source. Trezor's firmware is public, so anyone can inspect what the device does. You do not have to take a company's word for it.
  • Checks built into setup. Trezor's current models run an authenticity check during setup, and the packaging is sealed so you can see if it has been opened.
  • Long track record. Trezor made the first consumer Bitcoin hardware wallet in 2014.
  • Passphrase support for an extra layer that a stolen recovery phrase alone cannot get past.

The point of today's story still applies to Trezor, though. Any hardware wallet bought through a middleman carries the same supply chain risk. Buy it from Trezor itself.

Get a Trezor directly from the manufacturer here (this is our referral link, which supports Learning Crypto at no extra cost to you).

FAQ

Was Ledger hacked? Nothing published as of October 9, 2026 shows Ledger's own systems, firmware or devices were breached. The reported thefts are linked to devices sold by one Southeast Asian reseller, CryptoBilis. Ledger is investigating.

How much was stolen? Independent investigators estimate more than $86 million across Bitcoin, Ethereum and Tron. Ledger has not confirmed the figure.

I bought my Ledger from ledger.com. Am I affected? Nothing reported so far links direct Ledger purchases to these thefts. Check that you created your own recovery phrase and that no transactions you did not make have left your wallet.

I bought from CryptoBilis. What should I do? If you have not set the device up, do not. If you have, move your funds to a new wallet with a newly generated recovery phrase, on a device bought direct from the manufacturer.

How do I know if my hardware wallet was tampered with? Red flags include a recovery phrase supplied in the box, broken or re-glued seals, a device that was already initialized, or a failed authenticity check. Any of these means stop and move funds to a clean wallet.

Is it safe to buy a hardware wallet on Amazon or eBay? We would not. Buy only from the manufacturer's own website.

Sources: CoinDesk · Decrypt · BeInCrypto · Crypto Briefing · Bitcoin.com News · Coinpedia · KuCoin News

Keep learning