Ledger Says Limited Devices Affected in CryptoBilis Crypto Theft
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Ledger confirms limited device impact in its 72-hour update on the CryptoBilis crypto wallet theft investigation.
- The company says its systems remain unaffected as authorities investigate the incident involving its Southeast Asian reseller.
- Ledger advises affected customers to secure their funds and announces stronger hardware protection and reseller security measures.
Crypto hardware wallet maker Ledger has issued a 72-hour update on the CryptoBilis theft investigation, saying only a limited number of devices are affected. The company is working with authorities and contacting customers after reports of stolen cryptocurrency linked to its Southeast Asian reseller.
In an official X statement on October 11, Ledger said all confirmed cases involving the October 9 theft were linked to devices sold through CryptoBilis. The company also confirmed that its internal systems and direct sales channels remain unaffected.
72 hour update on reseller CryptoBilis incident 🔽
As the investigation continues, we are working with relevant authorities. The volume of impacted devices is limited. We know this is concerning, especially for those directly affected, and we are reaching out to impacted users.…
— Ledger (@Ledger) October 11, 2026
Ledger Says CryptoBilis Incident Is Limited to Reseller Devices
Ledger said investigators are still examining how the affected hardware wallets were compromised. However, the company has not disclosed the exact number of affected devices or confirmed the total financial losses. Earlier, on October 10, Ledger confirmed finding an unauthorized hardware implant inside one affected customer’s device. The discovery raised concerns about possible tampering before the wallet reached its buyer.
Situation Update: Ledger can confirm that one of the impacted users’ devices contained an unauthorized hardware implant. Ledger is reaching out to impacted users as part of the ongoing investigation. If you have information regarding the investigation, please reach out to…
— Ledger Support (@Ledger_Support) October 10, 2026
The hardware wallet contains the private keys that will be used for accessing the cryptocurrency. Attackers can exploit such hardware devices through modification prior to shipment and obtain confidential data during setup. Meanwhile, blockchain researchers have reported substantial losses linked to the incident. Blockchain analytics firm Bitquery estimated that approximately $92.9 million in cryptocurrency was drained from 311 wallets. However, Ledger has not independently confirmed that figure.
According to Ledger, CryptoBilis has ceased from the sale of its hardware wallets during the ongoing investigations. In addition, Ledger advised that those affected should report the issues to the local authorities.
Ledger Reviews Reseller Security and Hardware Protection
After the incident, Ledger said it is reviewing its distribution network and strengthening measures to prevent hardware tampering. The company reminded authorized resellers to purchase products only through approved distribution channels. It also warned them against reselling returned devices, which could carry additional security risks.
Ledger is working on stronger hardware protections and reseller controls. It also plans to cooperate with security researchers and other manufacturers to improve how devices are handled throughout the supply chain. The company thanked security response group SEAL 911 for supporting the investigation.
Meanwhile, Ledger warned customers not to buy devices from unauthorized sellers. Such products may be counterfeit or modified without the buyer’s knowledge. The company said the incident raises broader concerns about physical hardware security across the cryptocurrency industry.
Ledger Advises CryptoBilis Buyers to Move Funds to New Devices
Ledger has issued specific safety instructions for customers who purchased hardware wallets through CryptoBilis. Customers who have not initialized their devices should avoid setting them up. Those already using an affected or potentially compromised device should transfer their cryptocurrency to a new Ledger device with a newly generated recovery phrase.
Ledger also warned customers about scammers attempting to exploit the incident. The company said it never contacts users through unsolicited calls or direct messages asking for their 24-word recovery phrases. Affected customers can contact Ledger Support, which remains available around the clock.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







