Ledger CryptoBilis is the hardware wallet story of the week. Ledger is investigating lost funds from users in South East Asia who bought devices from reseller CryptoBilis. On-chain investigators put the losses above $86 million so far. So if you bought there in the last 90 days, do not set up the device.
I have used Ledger since 2016. However, I have never bought one from a reseller, and this story shows why.
What happened with Ledger and CryptoBilis
Ledger shared the warning in a post on X. First, the company asked CryptoBilis to pause all sales and shipments of Ledger devices. Second, it told recent buyers how to protect themselves.
Meanwhile, the numbers keep growing. Blockchain investigator Specter counts hundreds of affected wallets across Bitcoin, Ethereum and Tron. His estimate sits above $86 million. Earlier, researcher tanuki42 put the figure above $72 million and said it was still rising.
Here is the part that should worry everyone. CryptoBilis was no random marketplace seller. Instead, it appeared on Ledger’s own list of official resellers for Malaysia and the Philippines. As a result, buyers did exactly what most guides tell them to do.
Ledger has not confirmed the cause yet. Therefore, treat every theory below as a theory. This is also a different story from the OneKey bug claim in August. Nobody is pointing at Ledger’s own chip this time. All eyes are on the route the device took to the buyer.
What Ledger tells CryptoBilis buyers to do
The advice covers anyone who bought from CryptoBilis in the last 90 days.
- Not set up yet? Then leave the device in the box.
- Already set up? Then consider moving your assets to a new Ledger signer with a new seed.
Notice the wording. Ledger does not say “update your firmware.” Instead, it says new device and new seed. In other words, Ledger treats both the hardware and the recovery phrase as possibly compromised.
Personally, I would not wait for the final report. Buy a fresh device straight from the manufacturer first. Then create a new seed on it and move everything. My bunker mode guide covers when and how to move coins to a new wallet.
Already lost funds? Then read can stolen crypto be recovered and act fast. The first hours matter most.
How a tampered hardware wallet steals your coins
A hardware wallet is only safe if nobody touched it before you. Sadly, a reseller’s warehouse gives a thief exactly that window. Because of that, supply chain attacks keep coming back. They usually follow one of three playbooks.
The pre-made seed. The box arrives with a recovery phrase already printed on a card. Sometimes the PIN is set too. The attacker kept a copy, so he simply waits for your deposit. A real device always makes you generate the seed yourself.
Modified firmware. Here the device looks normal and even lets you create a seed. However, the tampered software picks from a small list the attacker already knows. Consequently, your “random” 24 words were never random.
A hardware implant. In this case someone opens the device and adds or swaps a part. After that, the implant leaks keys or changes what you sign. Such an attack is the hardest to pull off and the hardest to spot.
Which one hit CryptoBilis buyers? Nobody knows yet. Still, the pattern fits a supply chain attack much better than a remote hack. I covered a similar seed problem in the Coldcard hack this summer.
Never buy a hardware wallet from a reseller
My rule is simple. Buy from the manufacturer’s own website, and nowhere else.
For that reason, skip all of these:
- Amazon, eBay, Shopee, Lazada and other marketplaces
- Local crypto shops and electronics stores
- “Authorized” resellers, as this week shows
- Second-hand devices, even from a friend
- Any wallet you received as a gift or giveaway prize
Yes, Ledger runs official stores on some marketplaces. Even so, I skip them. Returned stock, lookalike sellers and mixed warehouses add risk. Besides, saving ten dollars is a bad trade against your whole stack.
Every extra pair of hands is an extra attack surface. So cut out the middlemen. Shipping from the factory may take a week longer. However, that week is cheap insurance.
When the box arrives, run these checks as well:
- Confirm the device asks you to create a new seed.
- Throw away any pre-filled recovery sheet.
- Run the genuine check in the official app.
- Send a small test amount first.
That said, checks have limits. A clever implant can pass them. Therefore, the purchase source remains your strongest defense.
More ways to protect your crypto
A clean device is step one. After that, good habits do the heavy lifting.
Start with the basics in my cold wallet guide. Next, add a seed phrase passphrase, the cheapest upgrade in crypto. For larger holdings, a multisig wallet removes the single point of failure. One bad device then cannot drain you.
Scammers also target Ledger owners without touching the hardware. For example, a fake Ledger app drained $9.5 million through the App Store. Similarly, phishing emails keep fishing for recovery phrases. Ledger will never ask for your 24 words. Nobody honest ever will.
Still wondering if the brand deserves your trust? Then read is Ledger wallet safe for my longer take. Unsure about holding your own keys at all? In that case, self-custody or exchange compares both routes.
Most daily activity runs through hot wallets anyway. Our reviews of MetaMask, Rabby, Phantom and Trust Wallet cover those. Finally, bookmark our stay safe page for the full checklist.
Keep This Content Free
Security warnings like this one earn us nothing. So if it helped, consider supporting our work through a partner link. Sign up at OKX or Bybit and we receive a small commission. It costs you nothing extra.
Final Words
The Ledger CryptoBilis case is still unfolding, and Ledger promises more updates. However, the lesson is already clear. A hardware wallet is only as safe as its journey to your door. Therefore, buy direct, create your own seed and trust no box that passed through extra hands. I will update this post when Ledger publishes its findings.

FAQ
What is the Ledger CryptoBilis incident?
Ledger is investigating lost funds from South East Asian users who bought devices from reseller CryptoBilis. As a precaution, Ledger asked the reseller to pause all sales and shipments.
Was Ledger itself hacked?
Nothing points that way so far. Ledger has not confirmed a cause, and the investigation is ongoing. However, the reports all trace back to devices from one reseller.
I bought a Ledger from CryptoBilis. What should I do?
Do not set it up if it is still in the box. Already using it? Then move your assets to a new Ledger with a new seed, bought directly from Ledger.
Is it safe to buy a hardware wallet on Amazon?
I never do. Official storefronts exist, but marketplaces add handling steps you cannot verify. So the manufacturer’s own website is the safest source.
How do I know if my hardware wallet was tampered with?
A pre-printed recovery phrase or a pre-set PIN is a clear red flag. Also run the genuine check in the official app. Still, some tampering is invisible, so the purchase source matters most.
Credit: Source link


















