Ledger theft probe points to reseller CryptoBilis and possible supply-chain tampering

Ledger theft probe points to reseller CryptoBilis and possible supply-chain tampering

N
News Editor
2026-10-10 05:57:52
A wave of theft reports from Ledger users has pushed a hardware-wallet security scare into the spotlight, with on-chain investigator Specter estimating losses of more than $86 million across Ethereum, TRON, Bitcoin and other networks. Ledger said it is investigating a case affecting users in Southeast Asia and pointed to reseller CryptoBilis, telling customers who bought devices through that channel in the past 90 days not to initialize them, while advising those who already set up devices to create a new Ledger signing device with a new recovery phrase and move funds. The case has drawn added attention because of claims that some devices may have been counterfeit or physically altered. Former Mt. Gox CEO Mark Karpelès said he had warned about Ledger devices carrying hidden SIM cards capable of transmitting stolen seed phrases, and later said a device he bought in Malaysia appeared sealed but contained a suspicious module under the screen padding. SlowMist chief information security officer 23pds said the setup could have captured seed phrases shown during initialization and sent them out over LTE or eSIM, though that remains a technical hypothesis rather than a confirmed explanation. Questions have also spread to CryptoBilis itself, including its ownership change, internal controls and sales suspension across Malaysia, the Philippines and Indonesia. At the same time, blockchain analysts have traced stolen funds into Tornado Cash, while Tether has frozen part of the related USDT. Ledger has not yet released a full recovery plan or compensation arrangement.

Ledger, long treated by many users as one of the safest ways to self-custody crypto, is now at the center of a large theft investigation.

On Oct. 9, on-chain investigator Specter said reports from Ledger users had been appearing on X and Reddit. After tracing the addresses involved, Specter said the wallets tied to the case had received funds from hundreds of wallets across Ethereum, TRON, Bitcoin and other major blockchains, with total losses exceeding $86 million.

Ledger points investigators to CryptoBilis

After the thefts came to light, Ledger issued a statement that directed attention to a reseller called CryptoBilis.

Ledger said it was investigating an asset theft case affecting users in Southeast Asia and that the affected users had previously bought devices through CryptoBilis. The company said it had asked the reseller to halt sales and shipments. It also advised users who bought devices through that channel in the past 90 days not to initialize them. Users who had already completed setup were told to create a new Ledger signing device with a new recovery phrase and move assets to a new wallet.

Suspicion centers on hidden SIM-card modules

A more specific warning had already come from former Mt. Gox CEO Mark Karpelès. On Oct. 8, Karpelès said counterfeit or tampered Ledger devices with hidden SIM cards were being sold, and that those SIM cards could transmit stolen seed phrases.

After the incident surfaced, Karpelès added that a Ledger hardware wallet he bought in Malaysia appeared sealed on the outside, but contained a suspicious module with a SIM-card chip under the screen padding.

Based on that, SlowMist chief information security officer 23pds said attackers may have used a malicious module to capture data shown on the device screen, record the recovery phrase when users initialized the wallet and viewed the seed phrase, and then transmit the information through LTE or eSIM.

The risk in that kind of attack is that it can bypass the usual assumptions users make about hardware-wallet security. A secure element can protect private keys from direct extraction, but it may not stop external hardware from capturing what appears on the screen. In other words, even if the core secure element is not broken, physical tampering could still expose the recovery phrase.

That mechanism, however, remains a technical hypothesis. The exact cause of this security incident has not been confirmed. Another view cited in the original report held that the attackers may have moved on Oct. 9 because Karpelès' warning was spreading and they feared the operation had been exposed, prompting them to start moving funds.

If that attack path is eventually confirmed, the issue would go beyond the security of a single wallet model. It would raise a broader question about whether self-custody remains trustworthy when users cannot verify that a device stayed intact from factory to delivery.

CryptoBilis faces scrutiny over ownership and operations

As the investigation widened, more details emerged about CryptoBilis.

Public information described CryptoBilis as a Web3 e-commerce and self-custody tools seller based in Petaling Jaya, Malaysia, with hardware wallets among its products. The company was co-founded by Arravind Prabu and Vimal Selvamany, with Prabu serving as CEO and Selvamany as CTO.

After the incident drew attention, Arravind Prabu said on X that claims he was still operating CryptoBilis were inaccurate. He said the company had been acquired in March this year and that the original management team had exited all operations, management and system access. For the current incident, he told people to contact a current person in charge, Nicholas Chang, at nicholas@cryptobilis.com.

Community users then asked why the ownership change had not been publicly announced earlier, especially when the account's latest post had shown a Lamborghini. Prabu replied that the post had been published by the new management team, and that the original team was bound by confidentiality terms in the contract and could not publicly announce the transaction until Oct. 19. He also said the original team no longer had access to the company's account, backend or operating systems.

The claim that the original management had already exited operations came from the former CEO's public statement. What happened inside the company after the handover has not been independently verified.

Another line of inquiry came from the company's equity records. Bitcoin News reported after the incident that share transfer records showed an individual named JIAMING, with a registered address in Heilongjiang, China, had held 100% of CryptoBilis shares since Aug. 3.

At least from public records, that suggests CryptoBilis had indeed changed hands months before the suspected supply-chain attack. But there is still no conclusive evidence on the details of the transaction, how the new management actually operated the business, or whether the new shareholder had any connection to the devices involved. The report explicitly noted that the registered address and acquisition timing alone are not enough to tie the shareholder directly to the thefts.

CryptoBilis later said through its official X account that it had suspended hardware-wallet sales and shipments across all stores and online channels in Malaysia, the Philippines and Indonesia, and had temporarily closed its physical stores. The company said the move was meant to support the Ledger security investigation and allow independent experts to review its internal processes. It added that customer service would proactively contact buyers with undelivered orders, and that further updates were expected within three business days.

As of publication, the central questions remained unresolved: at what point the devices were tampered with, whether the existing supply chain had been exploited, and whether the current management team could provide records detailed enough to reconstruct the delivery process.

On-chain losses show several fund trails

Current on-chain tracking suggests the incident is notable not only for its scale but also for the different paths the funds have taken.

Galaxy head of research Alex Thorn said bitcoin losses tied to the Ledger-CryptoBilis supply-chain incident stood at 213.42 BTC, worth about $17.7 million at the time. About 92% of that bitcoin had been held for less than 90 days when it was consolidated. The tracked BTC had not yet been spent and was sitting in three consolidation addresses.

Individual cases were also severe. Lookonchain said a user identified by the address label TY24Ya bought a related Ledger device three weeks earlier and then deposited 7 million USDT into the wallet, only to have the full amount drained in about 10 hours. In another case, a user bought 80 BTC for about $5.2 million four months earlier and at one point was sitting on an unrealized profit of about $1.38 million. After buying a Ledger device from CryptoBilis one week ago and transferring all 80 BTC into it, that user suffered a total loss.

Attackers have already started laundering funds

Not long after the thefts, the attackers began laundering and mixing the proceeds.

On-chain analytics firm Onchain Lens said the suspected attackers had deposited 430.2 ETH, worth about $1.07 million, into Tornado Cash through four wallets in an apparent attempt to break the traceability path on Ethereum.

At the same time, parts of the industry began trying to contain the stolen funds. Tether has frozen some of the USDT linked to the incident. The hackers, however, moved quickly after that step and used SUN.io and the USDD PSM mechanism in the TRON ecosystem to rapidly swap unfrozen USDT into USDD, a more censorship-resistant decentralized stablecoin. Some of those transfers also involved a Binance hot wallet, which the original report said could become a clue in identifying the attackers.

For now, recovery efforts depend heavily on whether investigators can quickly identify and intercept funds that remain on centralized platforms or in stablecoin addresses that can still be frozen. Assets that have already entered mixing protocols, moved across chains or passed through more complex routes may become harder to trace and recover.

Ledger has not yet published a full recovery plan or disclosed any compensation arrangement for victims. Whether assets can be recovered, and who will ultimately bear responsibility, remains unsettled.

Hardware wallets are no longer being treated as an absolute answer

For years, cold wallets have been seen as one of the most reliable ways to self-custody crypto assets, and Ledger has been one of the most recognizable brands in that market. Compared with exchange custody, holding private keys directly was supposed to reduce dependence on third parties.

This incident has put a different question on the table. If a device is physically altered before it reaches the buyer, then even intact packaging and an uncompromised secure element may not be enough to keep funds safe.

The exact attack path has not been finally established, and the case does not by itself invalidate the overall security model of hardware wallets. It does, however, show that security depends not only on the device, but also on the purchase channel, the initialization process and how the recovery phrase is handled.

If the risk starts at the supply-chain level, even a self-custody setup widely seen as the safest option can fail. The remaining answers will depend on what the investigation uncovers next.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.