CryptoBilis sold its business in March 2026, months before buyers of its Ledger devices lost their funds. A Chinese national named Jiaming has held 100% of the shares since August 3. Meanwhile, an NDA stopped the founders from announcing the deal. So Ledger kept listing the shop as an authorized reseller while a stranger owned it.
That changes the story completely. Yesterday I covered the first Ledger warning as a reseller problem. Today, however, it looks more like a takeover problem. Below I walk through the records, the NDA and what it means for your own wallet.
CryptoBilis sold in March: what the records show
Corporate records surfaced on X late Friday. According to those filings, one person named Jiaming now owns every share of CryptoBilis. His registered address sits in Heilongjiang province, China. The share transfer became final on August 3.
Soon after, former CEO Arravind Prabu confirmed the sale. He co-founded the Malaysian shop with CTO Vimal Selvamany. In his statement, Prabu said the deal closed in March. At that point, the original owners left every operational, managerial and administrative role. They also handed over all system access.
“We are no longer part of the company,” he wrote. In addition, he urged the current management to handle the crisis openly. The founders did keep helping with event coordination. Beyond that, they say they had no view into daily operations.
The NDA that expires on October 19
Users asked Prabu the obvious question. Why did nobody announce the sale? His answer was an NDA with the buyer. As a result, the founders stayed silent for seven months.
Here comes the strange part. According to Prabu, that NDA ends on October 19. The drains, however, hit the news on October 9. In other words, the wallets emptied ten days before the founders could speak.
To me, that timing matters. Once the NDA lapsed, the sale would have become public. After that, Ledger and its customers would have asked hard questions. So anyone abusing the shop faced a closing window.
Still, timing is not proof. Investigators have found no confirmed link between the new owner and the tampering. Therefore, treat the takeover theory as a strong suspicion, not a verdict.
The timeline so far
- March 2026: The acquisition closes. Founders step away under an NDA.
- Mid-July: Ledger’s 90-day warning window starts here.
- August 3: Jiaming holds 100% of the shares on record.
- October 9: Ledger asks CryptoBilis to pause all sales. Hours later, the ownership records surface.
- October 10: Reports confirm closed stores in Malaysia, Indonesia and the Philippines.
- October 19: The NDA reportedly expires.
Loss estimates keep moving as well. Arkham tracked more than $80 million across Bitcoin, Ethereum and Tron. Specter counted above $86 million, and newer estimates sit near $91 million. Ledger has confirmed none of these figures yet.
How the tampered devices reportedly worked
Researchers describe a physical attack, not a software hack. Reportedly, some devices carried a hidden module that captures the recovery phrase. With those words, a thief can rebuild the wallet anywhere. Early reports mention the Nano X and Nano S Plus, although nobody has verified that.
Mark Karpelès added fuel overnight. He posted photos of an implant inside two Ledger devices. However, his units came from discounted listings on Amazon and other platforms. They did not come from an authorized reseller. Consequently, the problem may reach beyond one shop. Ledger has not commented on those photos.
CryptoBilis also paused every other brand it sells, including Trezor and Tangem. For that reason, I would distrust any hardware wallet bought there recently. This summer’s Coldcard hack already showed how fast a compromised seed turns into empty wallets.
Why an authorized badge is not enough
Here is the lesson I take from this. An “authorized reseller” badge describes a company at one moment. It says nothing about who owns that company today.
Think about how cheap such an attack could be. Buying a small regional shop costs far less than $86 million. In return, a buyer gets a trusted name, a Ledger listing and loyal customers. Then every box passes through his hands first.
Ledger apparently missed the change of control too. Because of that, the official reseller list gave buyers false comfort for months. I expect manufacturers to add ownership checks after this. Until then, my rule stays simple. Order straight from the manufacturer’s own website.
What to do if you bought from CryptoBilis
Ledger’s advice covers purchases from the last 90 days. Personally, I would apply it to anything bought since March.
- Leave a sealed device sealed. Do not set it up.
- Already using it? Then move your funds out today.
- Send them to a wallet with a brand-new seed.
- Never reuse the old recovery phrase anywhere.
- Contact Ledger only through its official support site.
Speed matters here, because the attacker may already hold your old seed.
Also, watch for follow-up scams. Fake “refund” and “investigation” messages usually target victims next. We explained that playbook in our post on Ledger phishing emails.
Protect yourself beyond the device
One compromised wallet should never mean losing everything. First, read my cold wallet guide for the basics. Second, consider a multisig wallet for larger sums. With multisig, one bad device cannot drain you alone.
Wondering whether the brand itself still deserves trust? My longer take on is Ledger wallet safe covers that. Likewise, self-custody or exchange weighs both routes honestly. Finally, our stay safe page lists the full checklist.
Keep This Content Free
Following a story like this means hours of digging through filings and threads. If it helped you, consider signing up through a partner link. Both OKX and Bybit pay us a small commission. You pay nothing extra.
Final Words
CryptoBilis sold quietly, and its customers paid the price. Whether the new owner planned the drain remains unproven. Nevertheless, the timeline raises questions that Ledger must answer. Until those answers arrive, buy direct and generate your own seed. I will update this post as the investigation moves.
FAQ
Was CryptoBilis sold before the Ledger drains?
Yes. Former CEO Arravind Prabu confirmed the acquisition closed in March 2026. The drains surfaced on October 9, about seven months later.
Who owns CryptoBilis now?
Corporate records list an individual named Jiaming with 100% of the shares since August 3. His registered address is in Heilongjiang province, China.
Why did the founders stay quiet about the sale?
They signed an NDA with the buyer. According to Prabu, that agreement expires on October 19.
Is the new owner behind the theft?
Nobody has proven that. Investigators report no confirmed link between the ownership change and the tampered devices so far.
How much was stolen?
Estimates range from $80 million to roughly $91 million. Ledger has not confirmed an official number.
Are Trezor or Tangem wallets from CryptoBilis affected?
That is unknown. However, CryptoBilis paused sales of all brands, so I would treat any recent purchase with caution.
Credit: Source link


















