Ledger is investigating reports that customers in Southeast Asia lost funds held on hardware wallets bought through a third-party reseller called CryptoBillis, a case that has drawn scrutiny over the risks of purchasing hardware wallets outside official channels.

The company said it became aware of the situation on October 9, 2026, and has since asked CryptoBillis to stop selling and shipping Ledger devices while the inquiry continues. "As a precautionary measure, and pending the results of our investigation, we have asked CryptoBillis to suspend all sales and shipments of Ledger devices," Ledger said.

An on-chain researcher known as Specter has estimated that approximately $86 million was drained from affected wallets, with Bitcoin, Ethereum and Tron among the cryptocurrencies involved. The figure comes from independent on-chain analysis rather than a confirmed tally from Ledger itself, and the exact cause of the losses has not been established.

Ledger has issued specific guidance for customers who bought devices from CryptoBillis in the past 90 days. Those who have not yet set up their device are being told to hold off. "We recommend that Ledger users who have purchased from this reseller in the last 90 days do not begin setup if they have not already done so," the company said.

For users who have already completed setup, Ledger is recommending a full migration of funds to a new device with a freshly generated seed phrase, rather than simply resetting the existing one. "If you have already set up your Ledger device, consider moving the assets to a new Ledger signer (with a new seed)," the company said.

An unresolved supply chain question

Ledger has not specified whether the losses stem from compromised devices, counterfeit hardware, or some other failure tied to the reseller's supply chain. The company has committed only to ongoing communication as facts emerge. "We will continue to update customers as the investigation progresses," Ledger said.

The episode follows separate reporting by outlet CriptoNoticias on a flaw previously identified in Ledger's Ethereum application, which reportedly allowed one transaction to be displayed on a device's screen while a different transaction was actually being signed. It is not established whether that vulnerability has any connection to the CryptoBillis case.

For European buyers, the incident is a reminder that Ledger devices purchased through unauthorised or third-party resellers outside the company's own storefront and verified partners carry risks that the manufacturer cannot fully vet or guarantee. Ledger has not named any authorised distributors as part of this specific advisory, and has not disclosed how many customers were affected in total.