Ledger Warns Buyers Not to Set Up Wallets From Reseller After Users Report Losses
Bitcoin Magazine Ledger Warns Buyers Not to Set Up Wallets From Reseller After Users Report Losses Hardware wallet manufacturer Ledger is investigating after users reported having wallets drained. T...
Hardware wallet manufacturer Ledger is investigating after users reported having wallets drained.
Hardware wallet manufacturer Ledger has said that it is investigating loss of user funds after customers in South East Asia reported issues with devices bought from a reseller.
The Paris-based company on Friday advised customers who’d bought from vendor CryptoBilis within the last 90 days to not set up their devices.
Ledger did not reveal how much money users had lost but one blockchain investigator, Specter, wrote on X that he’d traced theft addresses following social media posts and that over $86 million had been lost.
BREAKING: Ledger reports loss of funds from users in South East Asia who purchased products from the reseller "CryptoBillis". The situation is ongoing and users are urged to review Ledger's official updates. pic.twitter.com/0GT3cthQtD
The issue comes following a number of data breaches this year in the crypto world and a huge hack of popular Coldcard hardware wallet devices in July.
“Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBilis,” Ledger said via its support X account.
Ledger added that it had asked CryptoBilis to pause all sales and shipments of Ledger devices.
“If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed). We will continue to inform customers of updates as the investigation progresses,” the company said.
In a statement to Bitcoin Magazine, Ledger said that based on the information to date, the incident is isolated specifically to this reseller in this specific market.
“No reports were made of products purchased directly from Ledger, and Ledger’s infrastructure, systems and services were not compromised,” the company added.
CryptoBilis is a Kuala Lumpur, Malaysia-based hardware wallet vendor, according to its website. The company did not immediately respond to questions from Bitcoin Magazine.
The crypto industry is still reeling after hackers in July were able to steal close to $120 million in bitcoin from Coldcard users.
The products, made by Canadian company Coinkite, had a firmware bug which led to faulty seed generation, allowing hackers to essentially guess investor seedphrases.
Galaxy Research said in the months following the attack various attackers were able to exploit the bug independently.
In a separate incident, hardware wallet manufacturer Trezor last month reported that close to 81,000 customers had their details leaked after its third-party fulfillment partner had data stolen.
Criminals have been targeting data this year, with scammers getting hold of customer information via crypto wallet Ledger’s payment processor Global-e to send phishing emails.
Asanat Analysis — Why it matters
Ledger's warning about reseller-sourced devices signals a critical supply-chain vulnerability in hardware wallet distribution. When users report fund losses after purchasing through unofficial channels, it suggests either counterfeit devices, compromised firmware during resale logistics, or the reseller itself acting maliciously. This hits at the core trust assumption underlying hardware wallets: that the device's integrity is guaranteed from manufacture to user hands.
The incident underscores why hardware wallet adoption, despite strong theoretical security, remains constrained by practical distribution risks. Unlike software wallets where users verify code themselves, hardware wallet security depends entirely on a supply chain spanning manufacturers, distributors, retailers, and shipping. Ledger's own platform (Ledger Live) has faced prior scrutiny over data practices, so third-party reseller incidents compound user skepticism. This likely accelerates institutional adoption of air-gapped signing solutions and direct-from-manufacturer procurement, while highlighting ongoing friction in retail crypto onboarding.
The story also demonstrates why self-custody remains operationally difficult at scale. Users buying from convenience channels (non-official resellers) face hidden risks that centralized exchanges don't; the trade-off for custody is bearing supply-chain and operational security burden. Regulatory pressure on exchanges may push retail toward self-custody, but incidents like this reveal the infrastructure gaps that regulators haven't yet addressed.