A hacker linked to the theft of funds from customers of a Ledger-authorized reseller has moved 430.2 ETH, worth roughly $1.07 million, through the Tornado Cash mixer, according to on-chain analytics firm Onchain Lens. The firm said the transfer was split across four independent addresses in an apparent attempt to obscure the trail before the funds reached the privacy protocol.
Onchain Lens has publicly asked Binance to examine the movements and act against any accounts connected to the stolen assets. "We are tagging Binance to investigate these transfers and block any account linked to the stolen funds as soon as possible," the firm said. "The activity on the network continues to develop and we will keep tracking it."
As of publication, Binance had not confirmed whether it has taken preventive action against the profiles identified by investigators.
Origins of the breach
The theft traces back to an alert Ledger issued on October 9, 2026, warning that devices sold by its authorized reseller CryptoBillis in Southeast Asia had been compromised. Ledger halted the reseller's operations and urged anyone who had purchased a device from CryptoBillis within the preceding 90 days to avoid setting it up and to migrate any funds already held on it to a new, uncompromised key.
Since the alert, the attacker has worked across multiple blockchains to move and disguise the proceeds. Tether has frozen part of the attacker's USDT holdings, and the attacker has responded by converting stablecoins into USDD through SUN.io and its PSM mechanism, a route that appears designed to sidestep further freezes. Monitoring tools from Arkham have shown that only a fraction of the capital has reached an active Binance wallet so far.
Scale of remaining exposure
Addresses linked to the attacker are still estimated to hold $70.60 million in assorted assets, including 11,406 ETH worth roughly $28.35 million, 213.37 BTC worth around $17.65 million, 13.64 million USDD and 10.90 million USDT. The figures underscore that despite partial freezes and the mixer transfer now under scrutiny, the bulk of the stolen funds remains in the attacker's control.
Commenting on the case, Chad Barraford described it as "unprecedented."
For European Ledger customers, the episode is a reminder that the vulnerability lies not in Ledger's own hardware but in the supply chain of third-party resellers. Buyers who purchased devices through unauthorized or compromised channels in the region covered by the alert are advised to treat any associated keys as unsafe and to move funds accordingly.




