Ledger has told Southeast Asian reseller CryptoBilis to stop selling and shipping Ledger hardware wallets while the company investigates reports that some buyers later lost funds. The warning is limited to customers who purchased through that reseller in the past 90 days, and Ledger has not said whether any devices were tampered with.

The action followed claims from on-chain investigator Specter, who said suspected losses tied to affected users had climbed above $86 million. Ledger has not confirmed that amount and has not explained how the funds may have left customer wallets.

Precautionary pause for one reseller

Ledger Support identified the reseller as CryptoBilis, a Malaysian shop founded in 2020 that sells crypto-related merchandise and Ledger devices. The company also operates in Indonesia and the Philippines.

In a support statement, Ledger said it had asked CryptoBilis to pause all sales and shipments of Ledger products while the review is underway. The measure was described as precautionary and remains in place pending the outcome of the investigation.

Advice for recent buyers

Ledger’s guidance applies only to people who bought a device from CryptoBilis within the last 90 days. Those customers were told not to set up the wallet if they had not yet started using it.

Customers who had already initialized their device were advised to move their assets to a different device and create a new seed phrase. The company did not extend that warning to Ledger buyers outside the reseller channel in question.

Unconfirmed estimate of losses

The reported scale of the incident comes from Specter, an investigator who tracks public blockchain activity. According to Specter, funds linked to hundreds of victim wallets were traced across Ethereum, TRON, and Bitcoin.

Public blockchain records cited in the report showed three Bitcoin addresses holding about 211 BTC in total, and those coins had not moved as of 13:44 UTC on Friday. Even so, Ledger has not endorsed the estimate of more than $86 million in suspected losses.

What remains unknown

A central unanswered question is whether any CryptoBilis devices were altered before reaching customers. Ledger has not said that tampering occurred, and the company has not described a confirmed mechanism that would explain the drains.

The broader risk is not new. Devices obtained outside official storefronts have previously raised security concerns: in April, fake Ledger units listed on a Chinese marketplace reportedly transmitted PINs and seed phrases to attackers. In a separate case in August, a firmware bug affecting Coldcard was reported to have led to about $70 million in Bitcoin losses.

Next step in the investigation

For now, the only confirmed operational change is the sales halt involving CryptoBilis and the safety guidance issued to that reseller’s recent customers. The status of the devices already sold through the shop remains under investigation.

Ledger said it will provide further updates as the investigation progresses. Until then, whether the affected devices were compromised before delivery, or whether another cause explains the reported wallet drains, has not been established.

Source: beincrypto.com