Ledger Investigates $86 Million Drain from Hardware Wallet Users Amid Security Concerns
Ledger, a prominent hardware wallet manufacturer, is currently investigating a significant security breach that reportedly led to over $86 million being drained from its users' wallets. The incident, flagged by on-chain analyst Specter, suggests a coordinated attack affecting wallets across Ethereum, TRON, and Bitcoin networks.
In response to the alarming reports, Ledger has instructed a Southeast Asian reseller, CryptoBilis, to halt all sales of its hardware wallets. This precautionary measure affects customers who purchased devices from CryptoBilis in the last 90 days, advising them not to set up their wallets and to transfer their funds to new devices with new seed phrases.
The nature of the attack remains unclear, with various theories circulating within the crypto community. Potential causes include vulnerabilities in Ledger's hardware or firmware, compromised seed phrases, or phishing attacks tricking users into revealing sensitive information. Ledger has yet to confirm any specific vulnerabilities or the total amount lost.
This incident follows a troubling trend in hardware wallet security, as earlier this year, a fake Ledger Live app drained approximately $9.5 million from users. Additionally, a flaw in a competing hardware wallet, Coldcard, resulted in significant losses for Bitcoin holders. As Ledger continues its investigation, users are urged to remain vigilant and verify the sources of their software and transactions.
Updated 14:31 UTC
Latest Developments on Ledger Investigation
- Date of Announcement: October 9, 2026
- Investigation Focus: Significant fund losses linked to devices purchased from CryptoBilis, an authorized Ledger reseller.
- Customer Guidance: Users who bought from CryptoBilis in the last 90 days should not initialize their devices. Those who have already set up their devices are advised to transfer assets to a new Ledger device with a fresh seed phrase.
- Estimated Losses: Over $86 million drained from affected Ledger wallets, primarily on Bitcoin, Ethereum, and TRON networks.
- Potential Causes: Theories include tampered devices, phishing attacks, or other vulnerabilities, but no definitive cause has been established yet.
- Supply Chain Concerns: The incident raises questions about the effectiveness of Ledger's Genuine Check system in detecting physical modifications to devices.
- Current Scope: The investigation is limited to the CryptoBilis channel and buyers from the last 90 days, with no evidence of a broader breach affecting all Ledger devices.
FAQ
What is the recent security breach involving Ledger?
Ledger is investigating a significant security breach that has reportedly led to over $86 million being drained from its users' wallets across Ethereum, TRON, and Bitcoin networks.
What actions has Ledger taken in response to the security concerns?
Ledger has instructed its Southeast Asian reseller, CryptoBilis, to halt all sales of its hardware wallets and advised customers who purchased devices from CryptoBilis in the last 90 days not to set up their wallets and to transfer their funds to new devices.
What are some theories about the cause of the attack?
Theories regarding the cause of the attack include vulnerabilities in Ledger's hardware or firmware, compromised seed phrases, or phishing attacks that trick users into revealing sensitive information.
Has Ledger confirmed any specific vulnerabilities related to the breach?
As of now, Ledger has not confirmed any specific vulnerabilities or the total amount lost due to the security breach.
What should users do to protect their funds during this investigation?
Users are urged to remain vigilant, verify the sources of their software and transactions, and consider transferring their funds to new devices with new seed phrases.
Comments
Comments are moderated before publish.
No comments yet — be the first.