Ledger probes $86M crypto breach involving Malaysian distributor



Ledger is investigating reports of more than $86 million in crypto losses involving customers who purchased its hardware wallets through CryptoBilis, an authorized reseller operating in Southeast Asia.

Ledger investigates suspected supply-chain security breach

Ledger’s official support account confirmed the investigation on Friday and asked CryptoBilis to suspend sales and shipments during the period. The reseller operates across Malaysia, Indonesia and the Philippines.

Onchain investigator Specter initially estimated losses at more than $86 million, tracing transactions from hundreds of wallets across Bitcoin, Ethereum and TRON. However, the figure has not been confirmed by Ledger.

A separate investigation by blockchain analytics firm Bitquery estimated that approximately $92.9 million had been stolen from 311 wallets across five networks: Bitcoin (BTC), Ethereum (ETH), TRON, BNB Chain (BSC) and Polygon (POL).

Bitquery also reported coordinated activity in some transactions, suggesting the attacker may have controlled the keys to multiple affected wallets.

The cause of the losses remains unclear, and Ledger has not confirmed that its devices were compromised.

However, Binance co-founder Changpeng Zhao (CZ) stated that the incident could involve a localized supply-chain attack, with some customers potentially purchasing counterfeit or tampered devices.

He also called on the wider crypto industry to help trace and recover the stolen assets.

“I expect and know all BNB ecosystem players (and all industry) to help trace and recover the funds,” CZ wrote in an X post.

Ledger has advised customers who purchased devices from CryptoBilis within the past 90 days and have not initialized them to avoid setting them up.

“If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed). We will continue to inform customers of updates as the investigation progresses,” the firm stated on X.

The incident has renewed concerns about hardware wallet security as other devices have faced vulnerabilities this year.

In August, TRM Labs reported that a firmware flaw affected certain Coldcard wallets and led to the theft of an estimated 1,816 BTC, worth approximately $116 million at the time, starting on July 30.

Crypto industry debate AI threats to blockchain security

The crypto market has also raised concerns about the security of cryptographic systems after Ethereum Foundation researcher Justin Drake warned that advances in AI could undermine the Elliptic Curve Digital Signature Algorithm (ECDSA), which secures Bitcoin and Ethereum transactions.

Drake urged large crypto holders to consider gradually moving funds to fresh addresses whose public keys have never been exposed, describing the precaution as “bunker mode.”

Ethereum co-founder Vitalik Buterin acknowledged the potential threat but cautioned against rushed wallet migrations, warning that mistakes could result in permanent fund losses.

Bitcoin investor Willy Woo argued that quantum computing fears pose a price-volatility risk rather than an existential threat to Bitcoin. He estimated a 25% chance that a future soft fork could freeze 1.7 million lost Satoshi-era BTC.