Home › Crypto News

Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen

CoinDesk
Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen

The hardware wallet maker said it is investigating devices sold by a Southeast Asian reseller as social posts swirl about crypto assets drained from Bitcoin, Ethereum and Tron addresses.

Crypto hardware wallet maker Ledger said Friday it is investigating reports of stolen funds linked to devices sold through a reseller in Southeast Asia as a suspected $86 million heist threatens to add to the industry's mounting losses from exploits this year.

Pseudonymous blockchain investigator Specter said on X that more than $86 million in crypto may have been stolen from hundreds of wallets. There hasn’t been any independent confirmation of the amount of user assets affected.

Specter said they traced suspected theft addresses across Bitcoin, Ethereum and Tron after seeing reports from Ledger users on X and Reddit. It remains unclear whether the incidents are connected or what caused the losses.

Ledger acknowledged in the post the reports of missing funds from customers who purchased devices through CryptoBilis, a reseller in Southeast Asia, but did not confirm the reported loss amount or identify the cause.

As a precaution, the company said it asked CryptoBilis to pause all sales and shipments while its investigation continues. Ledger advised customers who purchased devices from the reseller within the past 90 days not to begin setting them up. Those who have already activated their wallets should consider moving their assets to a new Ledger device with a newly generated recovery phrase, the company said.

The potential theft may add to an already rough year for crypto security. Last month, crypto exchange Bitget suffered an exploit that resulted in over $350 million in stolen assets. Other major incidents included Liquid Network at about $320 million, Drift at $295 million and Kelp at $293 million, according to DefiLlama data.

Founded in 2014 and based in Paris, Ledger is a major maker of hardware wallets, devices that keep the private keys used to access cryptocurrency offline. The company says it has sold more than 7 million devices worldwide and its products are widely used by investors seeking to protect their crypto without relying on exchanges.

That makes any potential security issue involving its products significant for the broader crypto market. In this case, however, the investigation concerns devices sold through a third-party reseller, and there is no confirmed evidence that Ledger's own systems or wallet technology were compromised.

One possible explanation is a supply-chain attack, in which hardware wallets are tampered with before reaching customers. For example, an attacker could supply a device with a recovery phrase they already know, allowing them to access funds deposited into the wallet at a later date.

Such a scenario would differ from a breach of Ledger's own systems. However, there is no confirmation that device tampering or pre-generated recovery phrases caused the reported losses.

The incident remains under investigation, and it is unclear how many users were affected, whether the reported thefts are connected or how much cryptocurrency was lost.

Diversified RWA stablecoins sustain 5-7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off-chain; TAM grows to $4B in 3 years.

Asanat Analysis — Why it matters

Ledger's investigation into potentially compromised devices represents a critical supply-chain vulnerability in hardware wallet distribution. Unlike software wallets, hardware wallets derive their security model from isolated, tamper-resistant hardware—if that foundation is breached at the reseller level, the entire value proposition collapses. The $86M theft suggests either pre-loaded malware on devices or compromised firmware during the resale channel, both scenarios that undermine customer confidence in 'unhackable' cold storage.

This incident signals broader risks in hardware wallet ecosystems where geographic distribution creates enforcement gaps. Southeast Asian resellers operating outside Ledger's direct control create an attack surface; bad actors can intercept, modify, or clone devices before reaching end users. The multi-chain nature of the theft (Bitcoin, Ethereum, Tron) indicates sophisticated attackers targeting high-value addresses, not opportunistic fraud. This will likely accelerate demand for direct-purchase verification and drive competitors (Trezor, Coldcard) to emphasize supply-chain transparency as a differentiator.

Ledger ▼ Bitcoin Ethereum Tron Trezor ▲ Coldcard ▲
Originally reported by CoinDesk. Read the original article →

AI-powered DeFi intelligence, daily

Asanat distills 100+ premium crypto newsletters and live market data into personalized insights.

Try the Asanat Platform