Ledger is investigating reports of crypto losses involving customers in Southeast Asia who purchased hardware wallets through reseller CryptoBilis. On-chain investigators have estimated the suspected losses at more than $86 million, while former Mt. Gox chief Mark Karpelès has separately reported finding a hidden chip in a Ledger device he examined.
The cause of the reported wallet drains remains unconfirmed. The implant report has raised concerns about possible hardware tampering, but the available evidence does not establish that the chip caused the CryptoBilis-related losses. Binance co-founder Changpeng Zhao, known as CZ, has also urged Ledger users to exercise caution.
What Ledger has said
In a statement published by its official support account on X, Ledger said it was investigating reports of fund losses involving users in Southeast Asia who had purchased products from CryptoBilis.
As a precaution, the company asked the reseller to pause all sales and shipments of Ledger devices while the investigation continues.
CryptoBilis is listed on Ledger’s official reseller directory, with listings covering Indonesia, Malaysia, and the Philippines. Its presence in the company’s reseller network is relevant because customers purchasing through an authorized channel may reasonably expect to receive genuine products.
The scale of the reported losses remains uncertain. Blockchain analytics firm Bitquery estimated that approximately $92.9 million had been drained from 311 wallets across Bitcoin, Ethereum, TRON, BNB Chain, and Polygon. On-chain investigator Specter separately estimated losses exceeding $86 million. Ledger has not confirmed either figure, and the estimates should not be treated as a final accounting of losses. The Crypto Times had reported the incident when Ledger began investigating the reseller after reports of more than $86 million in crypto losses.
The reported losses have been linked to customers who purchased devices through CryptoBilis. However, the precise mechanism by which the affected wallets were compromised has not been publicly established. There is also no confirmed finding in the cited reports that Ledger’s core systems were breached.
Mark Karpelès reports finding a hidden chip
Mark Karpelès, the former chief executive of collapsed crypto exchange Mt. Gox, has described finding a small component inside a Ledger device he examined.
In a post on X, Karpelès said his device had arrived from Malaysia with apparently intact shrink-wrap. He said the component was concealed near the area where padding around the screen would normally sit. In a later post, Karpelès described the component as a small “spy SIM card” measuring approximately 2 by 2 millimeters and shared a microscope image.
The report has raised the possibility that a device could be physically altered before reaching its buyer, even if its external packaging appears intact. However, the component’s precise function, how it was installed and whether it was connected to the CryptoBilis-related losses have not been independently established in the available reporting.
The distinction matters: finding a suspicious component in one device is not, by itself, proof that the component was responsible for the reported wallet drains. Ledger has not publicly confirmed the implant as the cause of the incident.
The reports therefore leave two questions open: whether the affected CryptoBilis customers received tampered devices and how the attackers obtained access to the wallets that were drained.
CZ urges caution over potentially tampered devices
Binance co-founder Changpeng Zhao has also commented on the incident, warning users who recently purchased Ledger hardware wallets to exercise caution.
In a post on X, Zhao said the information available to him suggested a possible supply-chain attack involving a single vendor. He added that some users may have purchased counterfeit or tampered devices.
Zhao also called for industry participants to help trace and recover the funds, while emphasizing that self-custody carries additional responsibilities.
In a separate post about hardware-wallet security, Zhao discussed the risks associated with tampered hardware and compromised software distribution channels.
Waiting before funding a new wallet is not a substitute for verifying a device’s authenticity or protecting its recovery phrase. Users should follow the manufacturer’s specific guidance when a device or reseller is implicated in a security investigation.
Zhao has also disclosed a relevant commercial interest. In an October 10 post on X, he said his investment arm, YZiLabs, had backed wallet businesses including OneKey, SafePal, and Trust Wallet. That disclosure provides context for his comments, although it does not in itself establish that his assessment of the incident is incorrect.
Previous hardware-wallet security concerns
The CryptoBilis investigation comes amid other security incidents and disputes involving hardware wallets. In April, The Crypto Times reported on a counterfeit Ledger wallet scam linked to a Chinese marketplace. In that case, counterfeit devices were reportedly used to obtain users’ recovery phrases.
Ledger is also facing a reported $500 million class-action lawsuit linked to an earlier data breach. The allegations in that case are separate from the current investigation and should not be treated as evidence of a connection between the incidents.
The broader debate over hardware-wallet security has also drawn criticism from blockchain investigator ZachXBT, who argued that hardware wallets are not worth trusting.
The CryptoBilis incident raises a specific issue within that debate: a hardware wallet’s security depends not only on its design but also on the integrity of the device and the protection of the recovery phrase. It does not establish that hardware wallets as a category are compromised, or that Ledger’s underlying security model has failed.
What affected Ledger users should do
Ledger has issued specific guidance for customers who purchased devices from CryptoBilis in the 90 days preceding its warning.
According to the company’s statement, customers who have not yet set up their devices should not initiate setup. Those who have already set up a device should consider moving their assets to a new Ledger signer with a new recovery seed, following Ledger’s instructions.
Users should consult the official Ledger Support account for updates and avoid relying on unsolicited messages, social-media accounts or links claiming to offer recovery assistance. Anyone asking for a wallet’s 24-word recovery phrase should be treated as untrusted; that phrase must never be shared with support agents or other third parties.
Customers who suspect their funds have been stolen should preserve transaction records and report the incident through appropriate security-response channels.
For users who did not purchase through CryptoBilis, the reports do not establish that all Ledger devices are affected. They should avoid panic-driven transfers and follow the manufacturer’s normal security guidance unless they have a specific reason to suspect their device or recovery phrase has been compromised.
The investigation is ongoing. The cause of the reported wallet drains, the final amount lost and the role, if any, of physically tampered devices remain to be established.
Also Read: NEAR Says Accounts Support ML-DSA Post-Quantum Signatures
