Ledger users in Malaysia, Indonesia and the Philippines face a widening picture of what went wrong after the suspension of CryptoBilis, the brand's authorised reseller in the region. On-chain investigators now put the theft total above $92 million, and it has emerged that the company quietly changed ownership months before the losses came to light.
Ledger and the investigator Specter first flagged losses of $86 million from affected wallets. Bitquery has since updated that figure to $92.9 million, spread across 311 wallets and five blockchains including Bitcoin, Ethereum and Tron. A separate tally from John Kamal of Yfarmx puts the total slightly higher, at $93.4 million across 471 addresses. Ledger has not validated either figure. By Friday evening, Bitquery said roughly $79 million of the stolen funds remained traceable on-chain.
Chainalysis has identified what it called "a sophisticated cross-chain laundering operation" behind the movement of funds, which passed in part through the Tornado Cash mixer. Tether has frozen approximately $10 million in USDT linked to the thefts.
A sale kept quiet
CryptoBilis, founded in Kuala Lumpur in 2020, built its business as Ledger's authorised distributor across the three countries, also selling Trezor and Tangem hardware wallets before suspending all sales and closing its stores. It has now emerged that the company changed hands in March 2026. Since August 3, 100% of its capital has belonged to an individual named Jiaming, based in China's Heilongjiang province.
A CryptoBilis co-founder confirmed the sale, saying simply: "We are no longer part of the company." The former founders were bound by a confidentiality agreement preventing them from disclosing the change of ownership; that agreement expires on October 19. Ledger said: "We have no indication that Ledger's security infrastructure, systems, or services have been compromised."
A spy chip inside the case
Separately, former Mt. Gox chief executive Mark Karpelès published photos on Friday of a Ledger device sourced from Malaysia, showing a second circuit board fitted with an LTE module, an eSIM and an antenna, concealed in the space meant for the screen's padding. 23pds, head of security at SlowMist, described an identical scheme. Karpelès later clarified that his units did not come through an authorised reseller but were discounted Ledgers bought via Amazon and other platforms, and that two of the devices he examined contained the implant. He wrote: "My spy-implanted ledger came from Malaysia, and had flawless shrink wrap. Even opening it, at first you don't see the implant which is cleverly hidden where the screen's padding is supposed to be."
Users who bought a device from the reseller within the past 90 days are advised not to configure it. Those who have already set one up are urged to migrate their funds to a new Ledger with a freshly generated recovery phrase.
Ledger is the third hardware wallet brand to suffer losses since July. D'CENT saw 6,678 wallets emptied in September, following a flaw previously identified in Coldcard devices.



