Bitcoin holder loses 80 BTC worth $5.2 million after moving funds to reseller-bought Ledger
Ledger is investigating a string of losses tied to Southeast Asian reseller CryptoBilis, with on-chain analysts estimating total damage between $72 million and over $87 million
A Bitcoin holder watched 80 BTC, worth $5.2 million, vanish after moving the coins onto a Ledger hardware wallet. The device was not bought from Ledger directly. It came from CryptoBilis, a reseller operating in Southeast Asia.
The transfer to the new device happened just one week before the funds disappeared.
A pattern, not a one-off
The 80 BTC loss is not an isolated case. Multiple buyers who purchased Ledger devices through the same reseller have reported significant losses.
Ledger confirmed on October 9, 2026, that it is investigating fund losses connected to CryptoBilis. The company is not waiting for the investigation to finish before issuing guidance.
Anyone who bought a Ledger from the reseller in the last 90 days has been told not to initialize their device. Ledger is also advising those buyers to move their assets to new Ledger wallets set up with different seed phrases.
Another victim reported losing 7 million USDT, a dollar-pegged stablecoin. That user had bought a Ledger device three weeks before the incident.
Following the money on-chain
On-chain analysts have tracked assets flowing to theft addresses across several blockchain networks. Trackers have identified $17.7 million in BTC and $29 million worth of ETH equivalents sitting in wallets linked to the thefts.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Analysts’ estimates of the total damage range from $72 million to over $87 million, spread across numerous victim wallets.
The cause has not been confirmed. Speculation centers on two possibilities: supply-chain tampering, where a device is compromised before it reaches the buyer, or phishing attacks that trick users into handing over sensitive information.
Where the problem appears to stop
So far, no reports indicate that Ledger devices bought through official channels have been affected. That points toward a localized issue tied to CryptoBilis.
The reseller’s footprint covers Southeast Asian markets including Indonesia, Malaysia, and the Philippines.
What this means for hardware wallet buyers
If supply-chain tampering turns out to be the cause, the security model breaks down if someone gets to the hardware first. If phishing is behind the losses, the takeaway shifts toward user behavior and how victims were targeted.
For now, the practical steps are straightforward. Anyone who bought a Ledger from CryptoBilis in the past 90 days should follow the company’s guidance: do not initialize the device, and move funds to a new Ledger wallet with a different seed phrase.
Ledger’s investigation will need to determine what actually happened, whether the reseller was complicit or itself a victim, and whether the damage extends beyond the current estimates.