Ledger Probes $86M Theft Reports Linked to Southeast Asia Reseller

Ledger is investigating reports that users in Southeast Asia lost crypto after buying devices through CryptoBilis, an authorised reseller in Indonesia, Malaysia and the Philippines. Ledger has asked the company to stop selling and shipping its devices while the inquiry continues. The alleged losses are not confirmed: blockchain researchers estimate between $72 million and nearly $87 million in assets, including BTC, ETH and USDT. Ledger has not confirmed the number of affected users or whether any devices were tampered with. Former CryptoBilis co-founder Arravind Prabu says he and his partner left the company after its ownership changed in 2026; public records cited in the report identify a new shareholder. Ledger advises users who bought a device from CryptoBilis within the past 90 days and have not set it up to pause activation. Users who have already stored funds on one should consider creating a new wallet with a fresh seed phrase and transferring their assets. The investigation is focused on a possible supply-chain attack, but there is no evidence that Ledger’s firmware, security chip or backend systems were compromised. The warning is limited to recent CryptoBilis buyers, not all Ledger users.
Neutral
The reports raise a serious security concern, but the market impact appears limited and the claims remain unverified. The estimated $72 million to nearly $87 million in losses is significant for affected users, yet it is small relative to the overall crypto market. Ledger has not confirmed device tampering or a compromise of its firmware, security chip or backend systems, and its warning applies only to recent CryptoBilis customers. In the short term, traders may react with caution around hardware-wallet providers and self-custody, while affected users could move funds to newly generated wallets. That may create some temporary on-chain flows, but there is no clear reason to expect broad selling of BTC or ETH based on the available information. Similar wallet-security incidents have often produced short-lived confidence shocks, with wider market effects depending on whether investigators establish a systemic vulnerability or disclose substantially larger losses. Longer term, a confirmed breach involving an authorised reseller could increase scrutiny of device provenance, packaging checks and verification procedures across the hardware-wallet sector. Until more evidence emerges, the event is best viewed as a localized security risk rather than a broad market catalyst.