Ledger has asked Southeast Asian reseller CryptoBilis to halt device sales and shipments as it investigates wallet losses that Bitquery estimates at $92.9 million across 311 wallets. The reported $93 million Ledger exploit came to light on October 9, 2026, but the available evidence does not establish a breach of the hardware wallet maker’s core infrastructure.
Key takeaways
- Ledger’s investigation centers on devices purchased through CryptoBilis.
- Bitquery’s loss estimate spans five blockchain networks.
- Ledger issued precautions for CryptoBilis purchases made within the previous 90 days.
- Blockchain tracing and forensic analysis remain underway.
U.Today reports that CryptoBilis holds official distributor status across Indonesia, Malaysia and the Philippines. Ledger’s response focuses on customers who bought hardware wallets through that reseller.
Tracing Ledger’s reported $93 million exploit
Bitquery calculated the reported losses across Bitcoin, Ethereum, TRON, BNB Chain and Polygon. Its estimate followed initial figures above $72 million and a separate assessment by blockchain investigator Specter that put losses above $86 million.
Specter traced suspicious addresses receiving funds from hundreds of wallets on Ethereum, TRON and Bitcoin. According to Bitquery’s analysis, small test transfers took place for roughly two weeks prior to the main outflows, after which coordinated movements occurred across multiple networks.
Researchers also found groups of wallets approving similar requests only seconds apart. Those patterns suggested preparation and a shared point of control.
A reseller-focused investigation and a hardware finding
Nothing in the evidence currently available confirms that a breach occurred within Ledger’s core infrastructure. In reporting published by TheStreet and carried by Yahoo Finance, the company said the information available pointed to an incident isolated to CryptoBilis in Southeast Asia; it also said its infrastructure, systems and services were not compromised.
The company told TheStreet that it had received no reports involving products purchased directly from Ledger.
Binance founder Changpeng Zhao assessed the incident as a localized supply-chain problem involving one vendor. He also urged industry participants to assist with tracing and recovering the assets. His assessment was separate from Ledger’s investigative findings.
Former Mt. Gox CEO Mark Karpelès shared photographs of a Ledger Nano X he said had arrived from Malaysia. He described apparently intact shrink-wrap but reported finding a concealed electronic module in the space normally occupied by screen padding.
Karpelès requested photographs from affected customers to help identify similar hardware modifications.
Ledger’s instructions for CryptoBilis customers
Ledger asked CryptoBilis to stop all sales and shipments while the investigation proceeds. Its customer guidance applies to devices purchased from the reseller during the previous 90 days.
Customers who have not set up their devices were told not to initialize them. For those who had already finished the setup process, the recommendation was to move their holdings to a new Ledger signer with a new seed phrase.
The company said it would provide customers with updates as its investigation advances.
Forensic work and asset tracing continue
Further forensic analysis and blockchain tracing are underway to clarify the cause and support asset recovery. Investigators examining Ledger’s reported $93 million exploit have tracked coordinated transfers and suspicious receiving addresses across multiple networks.
Bitquery’s analysis documented small test transactions over approximately two weeks before the main wallet outflows.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
