Ledger's $93 Million Exploit: Here's What Really Happened
Key Summary
Ledger is investigating reports of cryptocurrency losses among customers in Southeast Asia who purchased hardware wallets through CryptoBilis, a reseller listed as an official distributor in Indonesia, Malaysia, and the Philippines. The incident is believed to be a supply chain attack, with losses estimated above $72 million, but subsequent analysis by Bitquery expanded the reported total to $92.9 million. Ledger devices are designed to keep private keys offline, but maliciously modified hardware or a compromised supply chain could potentially undermine that protection.
Ledger $93 Million Exploit: What Really Happened
Investigation Underway
Ledger is investigating reports of loss of funds from users in South East Asia who purchased products from a reseller named CryptoBillis. As a precaution, and pending the results of our investigation, we have asked CryptoBilis to pause all sales and shipments of Ledger devices. We recommend Ledger users who purchased from this reseller in the last 90 days to not initiate set up if you have not done so yet. If you have set up your Ledger device, consider moving assets to a new Ledger signer (with new seed).\n\n
Analysis by Bitquery
Blockchain investigator Specter separately reported tracing suspicious addresses that received funds from hundreds of victim wallets across Ethereum, TRON, and Bitcoin, estimating losses above $86 million. Bitquery's analysis identified small test transactions over approximately two weeks before the main outflows, followed by coordinated transfers across multiple networks. Researchers also observed groups of wallets signing similar requests within seconds of one another. These patterns suggest preparation and a possible common point of control, but blockchain transactions alone cannot establish how the attacker gained access to the wallets.\n\n
Tether Freeze
The investigation has produced several developments in tracking the stolen assets. Tether reportedly froze approximately $10 million in USDT across 20 wallets associated with the suspected theft. The action prevents the affected USDT from being transferred through those addresses, but does not automatically return the funds to victims. At the analysis cutoff, approximately 14,810 ETH remained in a group of suspected attacker-controlled wallets. Researchers also identified around 203.8 BTC in associated Bitcoin addresses, with those funds reportedly unmoved at that point. Bitquery's analysis further identified the movement of approximately 1,254 ETH through Tornado Cash and Zcash. The funds reportedly later appeared in three new wallets, including one holding about 2.1 million USDC.\n\n
Industry Response
Binance founder Changpeng Zhao, commonly known as CZ, said the information available at the time pointed toward a localized supply-chain incident involving one vendor. He suggested that a small number of customers may have received counterfeit or tampered devices, while calling on industry participants to help trace and recover the assets. This remains an assessment, not a confirmed finding from Ledger's investigation.