Ledger confirmed an unauthorized hardware implant in a device sold by reseller CryptoBilis, with investigator estimates putting losses above $86 million, while PeckShield traced $3.89 million to Binance deposits.

A hardware wallet receiving a bitcoin transaction. Photo: FlippyFlink via Wikimedia Commons (CC BY-SA 4.0). Source
Hardware wallet maker Ledger confirmed on Oct. 10 that one device sold by Southeast Asian reseller CryptoBilis contained an unauthorized hardware implant, after days of user reports about drained wallets.
Ledger published the finding in a Saturday post on X and said it was contacting users as part of its ongoing investigation. Investigator Specter estimated the losses may exceed $86 million across Bitcoin, Ethereum and Tron, Cointelegraph reported.
The company asked anyone with information to write to its bounty program at bounty@ledger.fr, according to the same post.
CryptoBilis confirmed in the post that it had ceased sales of all hardware wallet inventory until the investigation ends. Ledger said it was in active communication with the reseller on next steps, Cointelegraph wrote.
Independent estimates describe a wider range. Losses sit between $72 million and $93.2 million across 311 to 315 wallets on several blockchains, Crypto Briefing found. The affected devices were bought from CryptoBilis within the last three months, and the implant case is the first confirmed physical tampering of a Ledger device tied to a reseller, the report said.
Most of the money was in one place. Roughly $70 million of the stolen funds sat in USDT on Tron, with the rest spread across Bitcoin, Ethereum, BNB Chain, Polygon and Solana, which suggests the attackers swept whatever the exposed seed phrases unlocked, according to the report.
The implant gave attackers access to users recovery phrases, Crypto Briefing wrote. Ledger stressed that its own systems and direct sales channels were not affected, and it reminded resellers that returned products should never go back on shelves.
Ledger told CryptoBilis buyers who have not set up their devices to leave them alone. Buyers who already set up a device should move assets to a new signer with a fresh seed phrase, the company said in its Saturday post.
Cointelegraph noted on Friday that CryptoBilis was listed as an authorized Ledger reseller in Indonesia, Malaysia and the Philippines. Ledger has not confirmed how many customers were affected or the total value of reported losses.
In a statement to Cointelegraph, the company said the incident appeared isolated to the single reseller and its market. Ledger added that its infrastructure, systems and services were not compromised and that the investigation continued, Cointelegraph wrote.
CryptoBilis has ceased operations while investigators work, and the reseller may have changed ownership, a detail that could matter for establishing when tampered units entered its stock, Crypto Briefing reported.
Blockchain security firm PeckShield flagged fresh movement on Oct. 11. About $3.89 million drained from the compromised wallets landed in Binance deposit addresses on Tron, Crypto Briefing reported.
The transfers spanned two days and included about 3.685 million USDT plus 615,000 TRX, the report said. Some of the funds passed through intermediary wallets that also handle money for other clients, which complicates any freeze or attribution effort.
That was not the first exchange-bound flow. Earlier on Oct. 11, about $10 million in USDT tied to the incident had already reached Binance deposit addresses, according to the same report.
The $3.89 million is a slice of a larger campaign. Total losses are estimated between $86 million and $94.5 million across more than 300 wallets, with the drains starting Oct. 9 and the heaviest losses tied to CryptoBilis-bought devices, Crypto Briefing found.
Tether froze about $10 million in USDT tied to the attack, the report said. The attacker appears to have anticipated the freeze by swapping some funds into USDD, a separate stablecoin outside Tether control, and mixers also entered the flow.
For victims, the Binance deposits open a concrete path. A centralized exchange can link deposit addresses to account holders, which gives law enforcement a next step, though the shared intermediary wallets mean any action needs proof that a specific account belongs to the attacker, Crypto Briefing noted.
Ledger pointed users with questions to official support at support.ledger.com. The company has not shared how many CryptoBilis devices were tampered with or whether the loss estimates will move again.