A hardware wallet is supposed to be the safest place to keep crypto. This week's Ledger investigation is a reminder that the safety starts with where the device comes from, per CoinDesk and CryptoSlate.

📌 The news

Ledger is investigating reports that wallets bought through CryptoBilis, a Southeast Asian reseller, were drained. A pseudonymous investigator claims more than $86 million was taken from hundreds of wallets, and CryptoSlate puts the estimate near $90 million. Ledger has asked the reseller to halt all sales and shipments.

🔍 Why it matters

‱ Suspected theft addresses span Bitcoin, Ethereum and TRON

‱ Tether has moved to freeze stolen $USDT linked to the case, per CryptoSlate

‱ There is no confirmed evidence that Ledger's own systems or wallet technology were compromised

📊 The numbers

‱ Over $86 million claimed stolen, not yet independently confirmed

‱ Ledger says it has sold more than 7 million devices since 2014

‱ Per DefiLlama data cited by CoinDesk, 2026 has already seen several nine-figure losses, including about $350 million at Bitget last month

⚖ What Ledger told users

‱ If you bought from this reseller in the past 90 days, do not set up the device

‱ If you already activated one, consider moving funds to a new Ledger with a freshly generated recovery phrase

👀 What to watch next

‱ Whether Ledger confirms a supply-chain attack, meaning devices were tampered with before delivery

‱ How much of the stolen stablecoin Tether manages to freeze

━━━━━━━━━━━━

💡 My take: In my view the real lesson is about the recovery phrase. A device that arrives with a phrase already filled in, or from a seller you cannot verify, should be treated as compromised, no matter what brand is printed on the box.

💬 Where did you buy your hardware wallet, and did you check it on arrival?

#Ledger #SelfCustody #Security