A hardware wallet is supposed to be the safest place to keep crypto. This week's Ledger investigation is a reminder that the safety starts with where the device comes from, per CoinDesk and CryptoSlate.
đ The news
Ledger is investigating reports that wallets bought through CryptoBilis, a Southeast Asian reseller, were drained. A pseudonymous investigator claims more than $86 million was taken from hundreds of wallets, and CryptoSlate puts the estimate near $90 million. Ledger has asked the reseller to halt all sales and shipments.
đ Why it matters
âą Suspected theft addresses span Bitcoin, Ethereum and TRON
âą Tether has moved to freeze stolen $USDT linked to the case, per CryptoSlate
âą There is no confirmed evidence that Ledger's own systems or wallet technology were compromised
đ The numbers
âą Over $86 million claimed stolen, not yet independently confirmed
âą Ledger says it has sold more than 7 million devices since 2014
âą Per DefiLlama data cited by CoinDesk, 2026 has already seen several nine-figure losses, including about $350 million at Bitget last month
âïž What Ledger told users
âą If you bought from this reseller in the past 90 days, do not set up the device
âą If you already activated one, consider moving funds to a new Ledger with a freshly generated recovery phrase
đ What to watch next
âą Whether Ledger confirms a supply-chain attack, meaning devices were tampered with before delivery
âą How much of the stolen stablecoin Tether manages to freeze
ââââââââââââ
đĄ My take: In my view the real lesson is about the recovery phrase. A device that arrives with a phrase already filled in, or from a seller you cannot verify, should be treated as compromised, no matter what brand is printed on the box.
đŹ Where did you buy your hardware wallet, and did you check it on arrival?
#Ledger #SelfCustody #Security