MultiversX Tracker is Live!

Ledger Probes Reseller Supply Chain as Analysts Track $86 Million in Suspected Drains

Finance Magnates

Cryptocoins News / Finance Magnates 28 Views

Ledger has halted hardware wallet sales through Southeast Asian distributor CryptoBilis and advised anyone who purchased a device from CryptoBilis in the past 90 days not to begin setup.

All active users should immediately sweep their balances to newly generated seed phrases.

The world’s largest hardware wallet manufacturer is investigating a reported wallet drain that could lead to crypto losses above $86 million.

This hardware wallet stores private keys once it has been securely initialised, but a device or recovery phrase compromised anywhere in the supply chain could give another party access, no matter how carefully the buyer later stores the wallet.

Where the $86 Million Estimate Came From

Ledger has not disclosed how many customers are affected or confirmed the value of the reported losses. The widely cited figure of more than $86 million comes from pseudonymous on-chain investigator Specter, who published addresses associated with reported wallet drains across Bitcoin, Ethereum and Tron.

However, the researcher later admitted that the actual victim count had not yet been established. The available information also does not prove that every transaction included in the estimate involved a CryptoBilis customer.

The Attack Vector Remains Unknown

Ledger has confirmed only that it is investigating reports from Southeast Asian users who purchased products through CryptoBilis. It has not identified the countries involved, named individual victims or linked the incident to a vulnerability affecting Ledger devices generally.

It is not known whether customers received altered or counterfeit hardware, used recovery phrases that had already been exposed, or lost their assets through another route such as phishing or malicious transaction approval.

Until the mechanism is established, the incident cannot be described as a confirmed hardware-wallet exploit or supply-chain attack.

However, Ledger’s instruction to replace both the signer and seed phrase places the distribution channel at the centre of the investigation, and shows why the seller and chain of custody matter as much as the device’s security after setup.

The reports emerged less than three weeks after Bitget confirmed a $387.5 million breach affecting part of its hot- and warm-wallet infrastructure.

The two incidents involve different custody models: Bitget controlled the compromised wallets, while Ledger users hold their own keys. In the Ledger case, the unresolved question is whether that control was compromised before buyers received or initialized their devices.

This article was written by Tanya Chepkova at www.financemagnates.com.
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.



Comments