Ledger, the French hardware wallet maker, confirmed on 10 October 2026 that a device belonging to one victim of a wallet-draining incident contained an unauthorised hardware implant, and later said every confirmed case involved devices sold through CryptoBilis, its authorised reseller in Southeast Asia. The Ledger CryptoBilis incident began with a wave of drained wallets on 9 October 2026. Ledger has not said how much was taken.

What Ledger has confirmed about the CryptoBilis devices

Ledger’s statements have been narrow. In a post from its support account on 10 October, the company said one affected user’s device contained an unauthorised hardware implant and that it had no indication its own security infrastructure, systems or services had been compromised. It said CryptoBilis had stopped selling its entire hardware wallet inventory until the investigation ends. It also thanked the SEAL 911 security group for its help and said it was working with law enforcement.

A follow-up from Ledger’s main account, billed as a 72-hour update, went further. “To date, all confirmed cases related to the disclosed draining incident of Oct 9th, 2026, involve devices sold through the Southeast Asia reseller CryptoBilis,” Ledger wrote. “The volume of impacted devices is limited,” it added, and its direct sales channels remain unaffected. Ledger also said it was reminding authorised resellers and distributors “to source products only through authorized channels and never to restock returned products.”

The scale of the Ledger CryptoBilis losses

No official figure exists yet. On-chain analysts have produced estimates, and they roughly agree. Bitquery put the total at about $92.9 million drained from 311 addresses, and a researcher known as Yfarmx put suspected losses at $93.4 million across 471 addresses, according to Bitcoin.com News. Ledger has not verified either number or confirmed that every tracked address is tied to a CryptoBilis device. For now the totals are best read as an upper bound.

Hardware wallet makers have dealt with tampered devices before, mostly counterfeits sold through online marketplaces. That is why Ledger and its rivals have told buyers for years to purchase only from the manufacturer or an authorised reseller. The Ledger CryptoBilis case breaks that advice, because the affected devices came through the authorised route.

The method is clearer than the scale. Mark Karpelès, the former Mt. Gox chief executive, published a teardown of a modified Ledger Nano X containing a concealed circuit board and cellular hardware, the same Bitcoin.com News report said. The working theory is that the implant read the recovery phrase as it travelled to the device’s screen during setup and then sent it out over a mobile network. If so, the attackers never had to break the secure element, the chip Ledger’s security model is built around, because they read the phrase on its way to the screen.

Why the Ledger CryptoBilis attack is a distribution problem

The Ledger CryptoBilis attack shows that the reseller channel, not the secure chip, is the most exposed part of Ledger’s security model. Hardware wallets are sold on the promise that your keys never leave a tamper-resistant chip. Ledger’s genuine check proves the chip is authentic. It does not prove that nothing else was added to the board. Ledger’s own guidance on checking hardware integrity asks users to compare a device’s insides with a published reference layout, which almost no buyer will ever do. A recovery phrase shown on a screen has to pass through ordinary circuitry to get there, and anything placed on that path can read it.

The Ledger CryptoBilis case puts authorised resellers inside the security perimeter, whether Ledger likes it or not. The line about never restocking returned products is the most telling thing in the 72-hour update. It reads like a description of how tampered units could have got into the channel: a device bought, opened, modified, returned and sold again as new. Ledger has not said that is what happened, but it is now telling resellers to stop doing it.

Compensation is the other open question in the Ledger CryptoBilis case. Replies to Ledger’s posts filled up with victims asking whether the company would repay them, arguing that CryptoBilis was an authorised reseller Ledger had chosen. Ledger has not announced a compensation or recovery plan. Its advice is not to set up an unused CryptoBilis device, and to move funds from one already in use to a new device with a fresh seed. That prevents further losses but does nothing about the ones already incurred.

The rest of the industry was already looking for ways around the seed phrase before the Ledger CryptoBilis losses. On 9 October 2026 Fintechbits covered Bron’s face-based recovery for self-custody wallets, and institutional custodians such as BitGo sell multi-party controls so that no single device holds everything. The Ledger CryptoBilis case will push more holders of large balances toward those models.

What to Watch Next After the Ledger CryptoBilis Incident

The first thing to watch is whether investigators find implants in devices sold outside Southeast Asia. There are unconfirmed reports of a tampered unit bought from a European reseller, and confirmation would turn one bad distributor into a problem with the whole channel. The second is the stronger anti-tampering measures Ledger says it is developing, and whether any of them can protect devices already in customers’ hands. Compensation will matter just as much, because Ledger’s handling of its 2020 customer data leak still colours how users see the company, and users will judge a refusal to cover losses from an authorised channel against that history.