Ledger, the maker of hardware wallets, is investigating a serious incident involving one of its official partners in Southeast Asia. The company has urged customers who bought devices from the Malaysian reseller CryptoBilis in the past three months not to set them up, and those who already have to move funds to a fresh device with a newly generated recovery phrase.
On-chain researchers tracking the drains have put the losses near $90 million so far, concentrated among buyers in Indonesia, Malaysia, and the Philippines.
CryptoBilis, based in Kuala Lumpur and listed on Ledger’s own reseller directory for those three markets, had long marketed itself as an authorized seller of genuine, sealed devices.
Reports of emptied wallets began circulating on social platforms in early October 2026.
Investigators such as Specter and MistTrack followed inflows from hundreds of victim addresses across Bitcoin, Ethereum, and Tron networks, with estimates ranging from the low $70 millions to just under $93 million.
Ledger has stated that its own systems and directly sold products appear unaffected, framing the problem as limited to this particular reseller and market.
Later updates from the firm confirmed that at least one affected device contained an unauthorized hardware implant, supporting suspicions of physical tampering in the supply chain.
Adding another layer of concern, company records indicate CryptoBilis changed hands earlier in 2026.
By early August, full ownership had passed to an individual with a registered address in China’s Heilongjiang province.
A former co-founder confirmed the March sale and said the original team had stepped away from operations and management, noting that confidentiality restrictions limited further details.
While no public evidence yet ties the ownership shift directly to the compromised devices, the timing and non-disclosure elements have fueled discussion in security circles about transparency in authorized reseller channels.
This episode highlights persistent risks in hardware wallet ecosystems.
Earlier in 2026, Coldcard devices from Coinkite suffered a long-hidden seed generation flaw dating back to 2021 firmware.
A build error caused some models to fall back on weak software randomness instead of proper hardware entropy, leaving seeds with far less security than advertised—roughly 40 bits on older units and around 70 bits on newer ones, well below the 128-bit standard.
Attackers exploited the weakness starting in late July, draining well over $100 million in Bitcoin from thousands of addresses across multiple waves. Firmware fixes arrived quickly, but existing weak seeds required full migration.
Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices.…
— Ledger Support (@Ledger_Support) October 9, 2026
Ledger and Trezor have also faced repeated third-party data exposures and supply-chain worries over the years, even when their core products held up.
Together these cases illustrate how difficult it remains to secure private keys end-to-end, whether through physical devices or the surrounding distribution and software layers.
Centralized platforms have not offered a clear alternative.
In September 2026, the exchange Bitget suffered a major breach in which attackers drained roughly $387.5 million from its hot and warm wallets by compromising a backend system and spoofing transaction data that the platform then signed.
Private keys themselves were not stolen, yet customer funds still left the platform; the firm later said its protection fund would cover losses.
Non-custodial DeFi interfaces present their own friction.
Wallets from providers such as Blockchain.com frequently show zero or missing balances on certain chains due to sync delays, account-type confusion between trading and self-custody sections, or network-specific activation requirements (for example, needing a small native token deposit before Tron assets appear).
Signing in can also be cumbersome, involving recovery phrases, single-sign-on limitations, or multi-step verification that frustrates everyday users.
Display problems do not usually mean funds are gone, but they erode confidence and complicate recovery.
Taken together, these incidents suggest that neither hardware wallets, exchange custody, nor polished non-custodial apps have yet reached the reliability and simplicity needed for broad mainstream use.
As the industry looks toward 2027, repeated supply-chain compromises, entropy failures, exchange drains, and everyday usability gaps continue to show that secure, convenient digital asset custody remains an unsolved problem.