Cryptelio

Hacks & Exploits

Ledger Investigates $86 Million Drain from Hardware Wallet Users Amid Security Concerns

Cryptelio Editorial Published 9 Oct 2026 · 14:02 UTC

Ledger, a prominent hardware wallet manufacturer, is currently investigating a significant security breach that reportedly led to over $86 million being drained from its users' wallets. The incident, flagged by on-chain analyst Specter, suggests a coordinated attack affecting wallets across Ethereum, TRON, and Bitcoin networks.

In response to the alarming reports, Ledger has instructed a Southeast Asian reseller, CryptoBilis, to halt all sales of its hardware wallets. This precautionary measure affects customers who purchased devices from CryptoBilis in the last 90 days, advising them not to set up their wallets and to transfer their funds to new devices with new seed phrases.

The nature of the attack remains unclear, with various theories circulating within the crypto community. Potential causes include vulnerabilities in Ledger's hardware or firmware, compromised seed phrases, or phishing attacks tricking users into revealing sensitive information. Ledger has yet to confirm any specific vulnerabilities or the total amount lost.

This incident follows a troubling trend in hardware wallet security, as earlier this year, a fake Ledger Live app drained approximately $9.5 million from users. Additionally, a flaw in a competing hardware wallet, Coldcard, resulted in significant losses for Bitcoin holders. As Ledger continues its investigation, users are urged to remain vigilant and verify the sources of their software and transactions.

Latest Developments on Ledger Investigation

  • Date of Announcement: October 9, 2026
  • Investigation Focus: Significant fund losses linked to devices purchased from CryptoBilis, an authorized Ledger reseller.
  • Customer Guidance: Users who bought from CryptoBilis in the last 90 days should not initialize their devices. Those who have already set up their devices are advised to transfer assets to a new Ledger device with a fresh seed phrase.
  • Estimated Losses: Over $86 million drained from affected Ledger wallets, primarily on Bitcoin, Ethereum, and TRON networks.
  • Potential Causes: Theories include tampered devices, phishing attacks, or other vulnerabilities, but no definitive cause has been established yet.
  • Supply Chain Concerns: The incident raises questions about the effectiveness of Ledger's Genuine Check system in detecting physical modifications to devices.
  • Current Scope: The investigation is limited to the CryptoBilis channel and buyers from the last 90 days, with no evidence of a broader breach affecting all Ledger devices.

Latest Developments

Tether has frozen nearly $90 million in USDT linked to thefts from Ledger hardware wallet users, as reported on October 9, 2026.

Estimated losses from these thefts exceed $86 million, with some tracking services estimating closer to $90 million.

The stolen assets were primarily from the Bitcoin, Ethereum, and Tron networks.

Ledger has advised customers who purchased devices in the last three months not to initialize new hardware and to exercise caution when moving their assets.

Initial speculation suggests that the thefts may have resulted from tampering in the supply chain rather than a flaw in Ledger's core hardware.

Tether's ability to freeze funds is due to its control over USDT, allowing it to blacklist addresses associated with thefts.

Investigators are still working to determine how the devices were compromised and whether other distributors are affected.

New Developments in Ledger Wallet Investigation

  • A crypto trader lost 80 Bitcoin (BTC), valued at approximately $6.6 million, after transferring the coins to a new Ledger hardware wallet.
  • The theft occurred just 10 days after the coins were deposited into the device, which was purchased from a Southeast Asian reseller, CryptoBilis.
  • Ledger has paused sales from the reseller and advised recent buyers not to set up their devices while the investigation is ongoing.
  • Estimates of the total losses linked to this incident have risen, with blockchain analytics firm Arkham reporting losses above $80 million, while MistTrack suggests the figure could reach $90 million.
  • Tether has frozen USDT tokens at addresses associated with the theft, indicating a proactive response to the situation.
  • Ledger has not confirmed whether any devices were tampered with and has promised to provide updates as the investigation continues.

FAQ

What is the recent security breach involving Ledger?

Ledger is investigating a significant security breach that has reportedly led to over $86 million being drained from its users' wallets across Ethereum, TRON, and Bitcoin networks.

What actions has Ledger taken in response to the security concerns?

Ledger has instructed its Southeast Asian reseller, CryptoBilis, to halt all sales of its hardware wallets and advised customers who purchased devices from CryptoBilis in the last 90 days not to set up their wallets and to transfer their funds to new devices.

What are some theories about the cause of the attack?

Theories regarding the cause of the attack include vulnerabilities in Ledger's hardware or firmware, compromised seed phrases, or phishing attacks that trick users into revealing sensitive information.

Has Ledger confirmed any specific vulnerabilities related to the breach?

As of now, Ledger has not confirmed any specific vulnerabilities or the total amount lost due to the security breach.

What should users do to protect their funds during this investigation?

Users are urged to remain vigilant, verify the sources of their software and transactions, and consider transferring their funds to new devices with new seed phrases.

Read story →