Finst

Ledger Pauses CryptoBilis Sales After Loss Reports

Ledger is investigating reports of losses at CryptoBilis in Malaysia, Indonesia, and the Philippines. Buyers of the hardware wallets are being told to double-check their seed phrase and device.

Ledger Pauses CryptoBilis Sales After Loss Reports

Key Takeaways

  • Ledger asked reseller CryptoBilis in Southeast Asia to temporarily pause sales of hardware wallets after reports of losses.
  • Buyers who purchased from CryptoBilis in the past 90 days were told not to set up their device yet or move funds to a new device.
  • The estimate of more than $86 million comes from analyst Specter, but Ledger has not confirmed that amount and is not saying the device was tampered with.

Ledger asked a reseller in Southeast Asia to temporarily stop selling hardware wallets while the company investigates reports that buyers lost money. The move came shortly after an analyst estimated the suspected loss at more than $86 million (€76.9 million). Ledger has not confirmed that amount and is also not saying the devices were tampered with.

Warning for Recent Buyers

Ledger Support named the seller CryptoBilis on Friday. The shop, based in Malaysia, sells crypto merchandise and Ledger devices and also operates in Indonesia and the Philippines. According to Ledger, the warning applies only to recent buyers from this one reseller in Southeast Asia.

People who bought from CryptoBilis in the past 90 days were told not to set up the device yet. Anyone who had already done so was asked to move funds to a new device with a new seed phrase. That seed phrase is the 24-word backup that gives access to a crypto wallet.

“As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices,” Ledger Support said.

Where the $86 Million (€76.9 Million) Comes From

The estimate comes from Specter, an analyst who tracks public blockchain data. According to him, funds were traced from hundreds of affected wallets on Ethereum, TRON, and Bitcoin. On public mempool data, three Bitcoin addresses Specter mentioned were together holding about 211 BTC on Friday at 13:44 UTC, and that balance had still not moved at the time.

Ledger has not adopted that estimate and has also not explained how the funds disappeared from the wallets. For now, that makes the case mainly an investigation into possible problems with hardware wallet distribution or use, not a confirmed breach at Ledger itself.

New Focus on Wallet Security

For European crypto users, this matters because hardware wallets are often seen as one of the safest ways to store crypto offline. At the same time, the case shows that risks can also come up outside the official manufacturer, for example through resellers or fake devices.

The warning also comes after a series of other security incidents in the industry. In April, fake versions of Ledger Live showed up in the Apple App Store, and in July Coldcard reported a firmware bug that weakened seed phrase generation. Ledger says it will share updates once the investigation has moved further along.

Other hardware wallets have already shown how fragile the chain around storage and key generation can be. For example, a flaw in key generation led to a major Bitcoin theft at Coldcard.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.