KEY POINTS
- On October 9, 2026, Ledger users in Southeast Asia had their assets drained. Security firms estimate losses at nearly $90M.
- Every known victim bought their device from CryptoBilis, a reseller in Malaysia. Ledger has opened an investigation and asked the reseller to pause sales.
- recoin's verification: three attacker BTC addresses hold about 213.37 BTC that has never been moved. Three ETH addresses hold about 3,337 ETH.
- Ledger's products were not broken. The problem was the purchase channel. Buying through official channels and refusing any device that ships with a pre-written seed phrase avoids this risk.
1. What happened
The victims did not click a phishing link or share their seed phrase. They bought a Ledger, set it up the normal way and deposited their assets. Days or weeks later, everything was drained.
| Time | Event |
|---|---|
| ~05:54 | 80 BTC leaves a victim address (confirmed on-chain by recoin, see section 2) |
| 12:00 | Security researcher @tanuki42_ warns losses exceed $72M and publishes attacker addresses |
| 13:32 | Ledger confirms an investigation and asks CryptoBilis to pause sales and shipments |
| 14:01 | Binance founder CZ shares a warning, describing a supply chain attack at a single reseller |
| 15:15 | MistTrack (SlowMist) reports losses near $90M and says Tether has frozen some related USDT |
| 15:33 | @lookonchain publishes victim cases, including one loss of 7M USDT |
The first theft visible on-chain happened about six hours before the first public warning.
2. recoin's on-chain verification
Most reported figures come from third parties. recoin independently checked the published attacker and victim addresses. Data is as of October 10, 2026.
1. Verified case: the 80 BTC victim
| Time (UTC) | On-chain activity |
|---|---|
| 2026-09-29 ~10:59 | Victim address bc1q9r0j…n53fs receives 80 BTC |
| 2026-10-09 ~05:54 | All 80 BTC is sent out; 79.9997711 BTC after fees lands at bc1qqnkw…jtm9 |
The receiving address bc1qqnkw…jtm9 appears on MistTrack's published list of attacker addresses. The two independent sources agree: this victim's funds went to the attacker behind this incident.
About ten days passed between deposit and theft. The attacker did not move as soon as they had the keys. They waited for assets to arrive. That delay is a hallmark of a supply chain attack.
2. Attacker BTC addresses: the funds have not moved
| Address | Total received | Sent | Balance | Transactions |
|---|---|---|---|---|
| bc1qjqgw…x49dl | 92.51 BTC | 0 | 92.51 BTC | 76 |
| bc1qqnkw…jtm9 | 111.28 BTC | 0 | 111.28 BTC | 46 |
| bc1qgqhe…ld26n | 9.58 BTC | 0 | 9.58 BTC | 154 |
| Total | 213.37 BTC | 0 | 213.37 BTC | 276 |
- All three addresses have only received funds and never sent any. The attacker may be waiting for attention to fade before moving the BTC through mixers or bridges. Any movement gives exchanges and security teams a chance to intervene.
- With 276 incoming transactions across the three addresses, the funds likely came from many victims rather than a single large holder.
3. Attacker ETH and TRON addresses
| Chain | Addresses | Result |
|---|---|---|
| Ethereum | 3 | Currently hold about 3,337 ETH in total (1,168.91 + 1,026.91 + 1,141.53) |
| TRON | 4 | TRX balance near zero; no USDT balance visible on-chain |
The USDT is no longer sitting at the TRON addresses. That does not contradict reports of Tether freezes; some funds may also have been moved on. We are tracing where they went and will add findings in an update.
About this data: all figures come from the public Bitcoin, Ethereum and TRON blockchains and can be checked by anyone in a block explorer. Addresses are shortened so readers do not send funds to the attacker by mistake.
3. Why a genuine hardware wallet can still be drained
A hardware wallet's security rests on one assumption: the seed phrase is generated by the device when you first set it up, and nobody else has ever seen it.
A supply chain attack breaks exactly that assumption. If the device is tampered with before it reaches you, the attacker holds the keys alongside you. They only need to watch the addresses and drain them once assets arrive. The roughly ten-day gap seen on-chain fits this pattern.
Ledger has not yet said which method was used: a modified device, a pre-generated seed phrase, or a counterfeit swapped in for a genuine unit. Whatever the method, the defense is the same: make sure the device comes from a trusted source, and make sure you generate the seed phrase yourself.
4. Hardware wallet protection guide
Buying: most of the risk is avoided here
- Buy only from Ledger's official store or an authorized reseller listed on its website. Be especially careful if the price is below the official one or the seller pressures you to buy quickly.
- Do not use second-hand devices or hardware wallets given to you by others. You cannot know what happened to them before they reached you.
- Inspect the packaging on arrival, but remember that intact packaging does not prove the device is safe. Skilled tampering leaves no visible trace.
Setting up: spotting a tampered device
- If the box includes a pre-written seed phrase, treat the device as tampered. A genuine device never ships with 24 words already filled in.
- Only use a seed phrase that the device generates itself and shows on its own screen. If a website, app or leaflet asks you to enter or use a particular seed phrase, stop immediately.
- Connect to Ledger Wallet (formerly Ledger Live) and complete the genuine check. Do not use a device that fails it.
- Test with a small amount first and confirm sending and receiving work before moving larger sums. This alone does not stop an attacker who waits for a large deposit, so the three steps above matter more.
Storing: do not let one device control everything
- Spread large holdings across several wallets, ideally on devices bought at different times through different channels.
- Consider a multisig wallet for large holdings. Transfers need signatures from several keys, so one compromised device cannot move the funds on its own.
- Set up address alerts. Many block explorers and wallet tools can notify you when a balance changes.
Day to day: recognizing follow-up scams
- Anyone who asks for your seed phrase, for any reason, is a scammer. That includes people claiming to be Ledger support.
- After major incidents, people posing as "official investigators" or "fund recovery experts" often message victims asking for upfront fees or seed phrases. Legitimate organizations do not charge you through unsolicited messages.
5. If you bought a device from CryptoBilis
Ledger recommends the following for anyone who bought from this reseller in the last 90 days.
- Not set up yet: do not set it up. Contact Ledger support.
- Already set up: buy a new device from the official store right away, generate a new seed phrase and move all assets to it. Stop using the old device and the old seed phrase.
If your assets have already been stolen
- Preserve evidence: transaction hashes, your addresses, proof of purchase and dates.
- Report quickly to Ledger support (support.ledger.com), the security emergency group SEAL 911 (X: @SEAL_911) and your local police.
- If stablecoins such as USDT are involved, speed matters most. Issuers can freeze addresses, and there is still a chance before the funds are swapped or bridged.
- Report to exchanges too. As noted above, the attacker's BTC has not moved yet. Exchanges that flag the attacker addresses early improve the odds of stopping it.
6. recoin's view
This incident is a reminder that crypto security depends not only on which wallet you use, but also on where it came from, how it was set up and how it is stored. Even the most secure device fails if the supply channel is compromised.
The on-chain data in this article was independently verified by the recoin team using our own analysis methods. We will keep monitoring this incident and update this article if the funds move.
recoin has on-chain analysis capabilities, but we do not offer fund tracing as an external service. Recovering assets that have already been sent to a third party requires cooperation with exchanges, stablecoin issuers and law enforcement. Please contact the channels listed above first.
What recoin does take on is recovering access to your own wallet: forgotten passwords, wallet.dat files that will not open, wallets left on old PCs or hard drives, multiple encryption layers, or cases where you only remember part of a password. If this sounds like you, or someone you know, feel free to get in touch.
FAQ
Are Ledger hardware wallets still safe?
Based on public information so far, the incident is limited to a single reseller channel, and there is no evidence that the Ledger secure chip itself was broken. Devices bought through official channels and set up by the owner are not affected.
I did not buy from CryptoBilis. Should I be worried?
If you bought from Ledger's official store or an authorized reseller and generated the seed phrase yourself during setup, this incident does not affect you. If your device came from a second-hand site, a social media seller or another unofficial source, we recommend switching to a new device and generating a new seed phrase.
Can stolen assets be recovered?
Sometimes, but there is no guarantee. Stablecoins can be frozen by their issuer, and funds can be stopped when the attacker deposits them at an exchange. The key is to report quickly so security teams and exchanges can flag the attacker addresses.
How can I tell if a hardware wallet has been tampered with?
The clearest sign is a pre-written seed phrase in the box, or instructions asking you to use an existing seed phrase. Also stop using the device if it fails the genuine check or the packaging shows signs of having been opened.
Sources
Update log
- First published, including recoin's on-chain verification data.