Ledger has opened an investigation into reports of fund losses from Southeast Asian customers who bought hardware wallets through CryptoBilis. The company asked the reseller to pause sales and shipments and issued precautions for customers who purchased devices during the previous 90 days.

Key Insights

  • Ledger is investigating loss reports tied to devices purchased from CryptoBilis in Southeast Asia.
  • The company asked CryptoBilis to stop sales and shipments while the inquiry is active.
  • Recent buyers should delay setup, while existing users should consider moving assets to a newly initialized device with a fresh recovery phrase.

The Ledger CryptoBilis investigation matters because hardware wallets are intended to isolate private keys from internet-connected devices. Ledger has not identified a root cause or confirmed the loss estimates circulating online, so claims of a broader product flaw or a supply-chain attack remain unproven.

Ledger CryptoBilis Investigation Triggers Sales Pause

Ledger Support said on Oct. 9 that it was examining reports from users in Southeast Asia who purchased products from CryptoBilis. As a precaution, Ledger asked the reseller to pause all sales and shipments pending the investigation.

The notice focuses on a specific sales channel rather than Ledger devices generally. Ledger’s official reseller directory lists CryptoBilis, but that listing does not establish what caused the reported losses.

That distinction is important because wallet drains can arise from several different failures, including compromised recovery phrases, counterfeit applications, phishing or device tampering. Investigators have not publicly established which, if any, of those explanations applies here.

What Recent CryptoBilis Buyers Should Do

Ledger advised anyone who bought a device from CryptoBilis within the past 90 days and has not initialized it to postpone setup. Customers who already initialized a device were told to consider transferring their assets to a new Ledger signer initialized with a fresh seed phrase.

A fresh phrase must be created on the new device rather than reused from the wallet under review. Moving assets to new addresses can reduce exposure if the original recovery phrase or signing device was compromised, though transaction fees and network confirmation times still apply.

The response follows a broader period of scrutiny around crypto custody and incident tracing. Fusion Market News has previously examined how Chainalysis used AI-assisted tracing after the Bitget breach, the separate Bitget theft investigation, and the THORChain response to a suspected cross-chain exploit.

What the Investigation Still Needs to Establish

Ledger has not said how many customers are affected, which device models are involved or whether the losses share a common technical cause. It also has not confirmed the large loss estimates attributed to independent on-chain researchers.

Those gaps make attribution premature. A reseller connection can identify a useful investigation path, but it does not by itself prove that devices were altered before delivery or that Ledger’s firmware was compromised.

The next observable catalyst is Ledger’s public update on the cause, the affected purchase channels and any remediation for CryptoBilis customers. Until then, buyers covered by the 90-day warning have the clearest actionable guidance: do not initialize an unused device and isolate funds from any wallet created with a device under review.

Elsy Kanana is a financial and cryptocurrency journalist at FusionMarketNews, covering digital assets, blockchain technology, financial markets, and emerging fintech trends. Her reporting focuses on market movements, regulatory developments, and on-chain analytics, delivering clear, data-driven insights to readers worldwide.