• 5 min read
Authorized resale is not a supply-chain security control
Ledger is investigating losses tied to an authorized Southeast Asian reseller, showing that a genuine-device check may not catch a physical implant.

Image: Gizmodo
Ledger has told customers who bought a device from CryptoBilis within the previous 90 days not to begin setup, and advised already-configured users to consider moving assets to a new Ledger signer with a new seed. The warning, issued on October 9, 2026, concerns reports of drained wallets among buyers in Southeast Asia.
The incident is not a confirmed breach of Ledger’s backend or cryptographic hardware. Ledger said the information it has so far points to devices sold through CryptoBilis, which it lists as a reseller for Indonesia, Malaysia, and the Philippines. CryptoBilis was still listed on Ledger’s reseller page when the reports surfaced, and the reseller also sells hardware wallets from other vendors.
“Based on the information available so far, we believe the funds drained are limited to devices sold through a reseller named CryptoBilis in South East Asia. We have no indication that Ledger’s security infrastructure, systems or services have been compromised.”
An authorized storefront is a purchasing channel, not proof that every unit reaching a customer is physically intact. Ledger has not said whether the affected products were genuine devices altered after manufacture, counterfeit units, devices supplied with attacker-controlled recovery phrases, or something else. It has not publicly accused CryptoBilis of tampering.

Recommended reading
CPR’s trusted access is Denmark’s unanswered security problem
Sergey Kuznetsov • • 4 min read
The alleged attack bypasses the secure element
The most detailed public theory came from former Mt. Gox chief executive Mark Karpelès, who posted photos of a Ledger he said he purchased in Malaysia. He described a second board concealed in the space normally occupied by display padding, including a single-wire antenna, an LTE module, and a data eSIM.
Karpelès’s account is unverified, and he has not established that his device came from CryptoBilis. But if the claim proves accurate, the implant would not need to modify the Ledger secure element or its firmware. Instead, it could monitor display refreshes, recognize Ledger’s typeface on the 128-by-64 screen, identify the setup flow, and transmit a seed phrase as text over LTE.
“My spy-implanted ledger came from Malaysia, and had flawless shrink wrap. Even opening it, at first you don’t see the implant which is cleverly hidden where the screen’s padding is supposed to be.”
A display-snooping implant could observe the only moment the secret must be rendered or entered while the secure element still generates and retains a seed correctly and the device passes a genuine-device check. That would be a supply-chain attack on the physical interface rather than an exploit of the wallet’s signing firmware.
Ledger’s customer guidance warns against devices that arrive pre-seeded, counterfeit hardware, and packaging that appears to have been opened. Its rule that a legitimate Ledger never arrives with a recovery phrase already written down remains important, but this reported scenario is more difficult: Karpelès said the shrink wrap on his unit appeared flawless and the added board was not obvious on initial inspection.
Flagged balances are large, but attribution is unsettled
Arkham Intelligence’s custom, unverified entity labeled ledger-drainer showed approximately $71.5 million in flagged addresses on October 9, 2026. That figure is not a confirmed total stolen from Ledger customers, and the reporting does not independently establish that every address in the cluster is connected to the reseller case. It indicates the scale investigators are tracking.
| Asset in flagged addresses | Balance reported on October 9, 2026 |
|---|---|
| Ether | About $29.4 million |
| Bitcoin | About $17.5 million |
| USDD | About $13.6 million |
| USDT | About $10.8 million |
The reported asset mix complicates incident response. A customer who suspects a compromised seed needs to move every asset controlled by that seed to a newly generated one; migrating a single balance does not remove the attacker’s ability to drain remaining holdings. Ledger’s recommendation to use a new signer with a new seed is more specific than simply reinstalling Ledger Live or changing an account password.
The reseller’s wider inventory is an unanswered risk
CryptoBilis markets itself as an authorized seller with a walk-in location in Petaling Jaya and carries products from Trezor, Tangem, SafePal, CoolWallet, OneKey, Ellipal, and other wallet brands. No evidence in the available reporting ties any of those vendors' products to the incident. If the compromise happened in the reseller’s physical fulfillment chain rather than at Ledger, the question is not limited to Ledger’s firmware or secure element.
Customers who purchased Ledger devices through CryptoBilis in the stated 90-day period have a clear vendor instruction: do not set up an unused device, and consider migrating assets if it has already been configured. The reporting does not establish an equivalent instruction for buyers of other brands sold by the retailer.
Ledger’s 2026 security problem is broader than this investigation
This is the second kind of exposure Ledger customers have faced in 2026. In January, Ledger disclosed that payment processor Global-e exposed names and contact details for an undisclosed number of Ledger.com buyers. No cryptocurrency was reported stolen in that event, but customer identity and contact data can enable phishing and physical targeting. In April, a musician reportedly lost about $424,000 in bitcoin after installing a fake Ledger Live application from Apple’s Mac App Store.
Those cases differ from the current reports. A leaked customer list enables social engineering; a fake desktop app targets the host computer; a physical implant, if confirmed, attacks the wallet’s trusted presentation layer. Self-custody depends on the authenticity of the delivered hardware, the software a customer installs, and the recovery process around both.
Ledger has not confirmed the compromise mechanism, the number of affected devices, whether CryptoBilis’s other inventory is implicated, or whether the approximately $71.5 million in Arkham-tagged addresses is attributable to this case. Its authorized reseller status did not prevent Ledger from telling recent customers to stop using their devices.
Frequently asked questions
What should Ledger buyers from CryptoBilis do?+
Ledger said buyers who purchased through CryptoBilis in the last 90 days should not initiate setup. Users who already configured a device should consider moving assets to a new Ledger signer with a new seed.
Did Ledger confirm that its systems were hacked?+
No. Ledger said it has no indication that its security infrastructure, systems, or services were compromised, and believes the reported drains are limited to devices sold through CryptoBilis.
Was CryptoBilis confirmed to have altered Ledger devices?+
No. Ledger has not accused CryptoBilis of tampering, and the reporting does not publicly establish how any device was compromised.
Are other wallet brands sold by CryptoBilis affected?+
The reporting does not establish that non-Ledger products sold by CryptoBilis are affected. The reseller carries several other hardware-wallet brands.
Editor-in-Chief
Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.


