Photo: Connor Scott McManus / Pexels
PeckShield traces $3.89 million from Ledger wallet drain to Binance deposits
Stolen USDT and TRX tied to tampered CryptoBilis devices landed in exchange deposit addresses on Tron, giving investigators a possible lead
Blockchain security firm PeckShield says roughly $3.89 million drained from compromised Ledger hardware wallets has been routed into Binance deposit addresses on the Tron network.
Following the money to Binance
PeckShield flagged the transfers on October 11, 2026. The movements happened over a two-day window.
The haul included approximately 3.685 million USDT and 615,000 TRX. Both moved on Tron before landing in deposit addresses linked to Binance.
There is a catch. Some of the stolen funds reportedly passed through intermediary wallets that also handle money belonging to other clients.
This also isn’t the first Binance-bound flow tied to the incident. Earlier on October 11, approximately $10 million in USDT had already been sent to Binance deposit addresses, according to the research findings.
A much bigger theft behind the headline number
The $3.89 million is a slice of a far larger draining campaign. Total losses are estimated between $86 million and $94.5 million.
More than 300 wallets were hit across several blockchains, including Bitcoin and Ethereum. Most of the damage, though, came in USDT on Tron.
The drains started on October 9, 2026, and moved quickly. The common thread among the biggest losses: devices purchased from CryptoBilis, a Southeast Asian reseller of Ledger hardware.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Ledger has paused sales through CryptoBilis. The company also confirmed unauthorized hardware modifications in at least one of the compromised devices.
Ledger has also advised affected users to adopt new security measures.
Tether freezes, and the attacker adapts
Tether moved to freeze addresses tied to the attack. The frozen funds total approximately $10 million in USDT.
The attacker appears to have anticipated that move. Some funds were swapped into USDD, a different stablecoin, in an apparent effort to dodge Tether’s freeze powers.
Mixers also entered the picture. These services blend funds from many users so outside observers struggle to tell which coins came from where.
What this means
For victims, the Binance deposits are the most hopeful development so far. A centralized exchange can, in principle, connect deposit addresses to account holders, which gives law enforcement and investigators a concrete next step.
The intermediary wallets are the obvious complication. If those addresses serve other customers too, any freeze or account action risks catching uninvolved users, and any claim that a specific account belongs to the attacker needs careful proof.
Tether’s roughly $10 million freeze shows how centralized controls can claw back part of a theft quickly. The attacker’s pivot to USDD shows the limit: a freeze only works on the token an issuer controls.
The key things to watch now: whether Binance or authorities act on the flagged deposit addresses, how much of the estimated $86 million to $94.5 million in losses can realistically be traced or frozen, and whether Ledger shares more about how many CryptoBilis devices were tampered with.