A hardware wallet is supposed to be the safest place to keep crypto. This week's Ledger investigation is a reminder that the safety starts with where the device comes from, per CoinDesk and CryptoSlate.
📌 The news
Ledger is investigating reports that wallets bought through CryptoBilis, a Southeast Asian reseller, were drained. A pseudonymous investigator claims more than $86 million was taken from hundreds of wallets, and CryptoSlate puts the estimate near $90 million. Ledger has asked the reseller to halt all sales and shipments.
🔍 Why it matters
• Suspected theft addresses span Bitcoin, Ethereum and TRON
• Tether has moved to freeze stolen $USDT linked to the case, per CryptoSlate
• There is no confirmed evidence that Ledger's own systems or wallet technology were compromised
📊 The numbers
• Over $86 million claimed stolen, not yet independently confirmed
• Ledger says it has sold more than 7 million devices since 2014
• Per DefiLlama data cited by CoinDesk, 2026 has already seen several nine-figure losses, including about $350 million at Bitget last month
⚖️ What Ledger told users
• If you bought from this reseller in the past 90 days, do not set up the device
• If you already activated one, consider moving funds to a new Ledger with a freshly generated recovery phrase
👀 What to watch next
• Whether Ledger confirms a supply-chain attack, meaning devices were tampered with before delivery
• How much of the stolen stablecoin Tether manages to freeze
━━━━━━━━━━━━
💡 My take: In my view the real lesson is about the recovery phrase. A device that arrives with a phrase already filled in, or from a seller you cannot verify, should be treated as compromised, no matter what brand is printed on the box.
💬 Where did you buy your hardware wallet, and did you check it on arrival?
#Ledger #SelfCustody #Security