Ledger users across Europe and beyond are facing a confusing few days, as the hardware wallet maker confirms it is investigating reports of stolen funds linked to a specific reseller, even as a separate, unverified claim of $86 million in losses circulates widely on social media.
On-chain analyst Specter reported that more than $86 million in cryptocurrency had allegedly been stolen from Ledger users, citing inflows from hundreds of wallets across Ethereum, Bitcoin and Tron. An Arkham Intelligence screenshot showing a portfolio labelled "ledger user theft" at approximately $86.96 million has been shared alongside the claim, though the wallet in question could not be located under that name on the Arkham platform itself, leaving the figure unverified.
What Ledger has confirmed is narrower, and specific. In a statement published on X, Ledger Support said: "We are currently investigating reports of balance losses among users in Southeast Asia who purchased products from a reseller called CryptoBillis."
The company issued direct guidance to anyone who may have bought devices through that channel. "We recommend Ledger users who have purchased from this reseller in the last 90 days not to start setup yet, if you haven't already done so," Ledger Support said. "If you have already set up your Ledger device, you should consider transferring your assets to a new Ledger device (with a new seed). We will continue to keep our customers updated on the status as the investigation progresses."
The episode has prompted comment from across the industry. Binance founder Changpeng Zhao weighed in on X, writing: "Ledger is one of the safest hardware wallets in the industry. It has proven itself over the years. But things like this happen sometimes."
A pattern familiar to investigators
Albert Quehenberger, founder and CEO of AQ Forensics, has previously confirmed in an interview with BTC-ECHO that Ledger users have been targeted by scammers. He described a common manipulation tactic in such cases: "Often a supposed security breach is faked. The perpetrators then present themselves as the people who can help and use this pretext to get victims to disclose access data or authorize transactions."
Quehenberger was also direct about the consequences once a seed phrase is exposed. "If the recovery phrase has been disclosed, the wallet must be considered compromised," he said.
Separately from the reseller investigation, phishing emails impersonating Ledger have been circulating, demanding that recipients perform a manual security update by October 15, 2026. There is no confirmed connection between these phishing messages and either the CryptoBillis reseller case or the $86 million figure reported by Specter.
For now, Ledger's own confirmed statement is limited to the reseller-linked losses in Southeast Asia. Users anywhere in Europe who have purchased devices through unofficial or third-party channels, rather than directly from Ledger or its authorised partners, may wish to take note of the company's advice, pending further updates from the investigation.




