Ledger, the Paris-based hardware wallet manufacturer, is investigating reports of stolen funds from customers in Southeast Asia who purchased devices through a reseller called CryptoBilis. The company has asked the reseller to halt all sales and shipments as a precaution while the investigation unfolds. Ledger advises customers who bought devices from CryptoBilis in the past 90 days to avoid setting up their wallets and recommends those who have already done so to transfer their assets to a new Ledger signer using a new seed phrase.
The potential losses could be substantial, with estimates suggesting over $87 million in stolen funds. Crypto investigator Specter traced theft addresses linked to reports from Ledger users and found inflows from hundreds of victim wallets across Ethereum, Tron, and Bitcoin. The stolen assets include approximately $42 million in ETH, $17.6 million in BTC, and $16.5 million in USDT. Ledger has not confirmed the figure, and it remains unclear whether all thefts are connected to the reseller.
The incident highlights ongoing security challenges in the crypto space. Rival wallet manufacturer Trezor has also faced security breaches, including a shipping partner data leak and a recent email breach. Other notable security incidents include a $387 million hack at Bitget, linked to North Korean hackers, and a $285 million exploit at Solana exchange Drift, also attributed to North Korean actors.