ActiveInvestorMag
Crypto & Financial Engineering

Ledger traces an 86 million dollar wallet drain to a single reseller

The hardware wallet maker asked a Malaysian and Philippine reseller to pause sales after users reported drained accounts.

October 9, 2026Evening edition7 outlets Assembled by machine

Watercolour landscape whose skyline traces bitcoin in dollars, 2010 to 2026, on a log scale.
Bitcoin, 2010 to 2026

Ledger is investigating reported crypto thefts of about 86 million dollars linked to wallet sales by the reseller CryptoBilis2. BigGo Finance reported the company probing an 86 million dollar crypto drain tied to a Southeast Asian reseller4, and BitPinas reported that Ledger asked CryptoBilis, which is based in Malaysia and the Philippines, to pause sales amid user reports of drained wallets7.

U.Today reported Ledger investigating the theft reports6, and FXDailyReport reported the hardware wallet maker hit with an 86 million dollar theft5. The figure is as reported by users and has not been confirmed by any audit2,5.

Reports of unauthorised outflows came from users rather than from the company, and Ledger’s response so far has been to investigate and to ask the reseller to stop selling2,7. Neither Ledger nor the reseller has published a finding6.

Why it matters to investors

Binance co-founder Changpeng Zhao said the evidence points to a supply chain attack localised to one vendor, possibly involving counterfeit devices4. He attributed the thefts to a localised supply chain attack in a post on the platform X7, and pointed to compromised devices as the likely route2. FXDailyReport also reported his view that the attack appears to involve a single vendor5. The assessment is his, not the company’s4,7.

Crypto-Economy reported Zhao recommending a wait of at least two weeks before a newly purchased hardware wallet is trusted with substantial crypto, which is an admission that a buyer cannot verify a device on receipt1.

The significance is not the amount but the attack surface. Hardware wallets are sold on the premise that self-custody removes counterparty risk. An attack executed through the distribution channel reinstates a counterparty, the reseller, at the point of purchase rather than the point of storage4,7. Insurance, audit and custody arrangements built around exchange failure do not address that.

What to watch

Zhao urged crypto investors to impose a strict “quarantine” period on new hardware wallets3, recommending waiting at least two weeks before trusting a newly purchased device with substantial holdings1. That is practical advice rather than a fix, and it points to the open questions.

Watch whether Ledger’s investigation confirms the thefts were confined to CryptoBilis or finds other resellers affected, which is the difference between a vendor failure and a channel failure2,7. Watch whether the devices involved turn out to be counterfeit or genuine units that were tampered with, since the two imply different controls4. And watch whether Ledger moves from asking a reseller to pause sales to revoking authorisation outright7.

Sources

  1. Binance Founder CZ Warns Crypto Users to Quarantine New Wallets After $86M Hack, crypto-economy.com (2026-10-09)
  2. Ledger Investigates Reported $86 Million Crypto Theft Linked to CryptoBilis Wallet Sales, hokanews.com (2026-10-09)
  3. Binance Founder CZ Urges Wallet ‘Quarantine’ After $86 Million Ledger Reseller Hack, tradingview.com (2026-10-09)
  4. Ledger Probes $86 Million Crypto Drain Tied to Southeast Asian Reseller - BigGo Finance, finance.biggo.com (2026-10-09)
  5. Ledger Hardware Crypto Wallet Hit with $86 Million Theft, fxdailyreport.com (2026-10-09)
  6. Ledger Investigates Crypto Theft Reports - U.Today, u.today (2026-10-09)
  7. Ledger Asks MY and PH-based CryptoBilis to Pause Sales Amid User Reports of Drained ..., bitpinas.com (2026-10-09)

Assembled by Edwin, my AI assistant powered by Claude, from the public excerpts of the outlets numbered above. No human wrote or checked it before publication, so read the sources before you act on it.