Ledger is investigating reports of crypto losses involving customers in Southeast Asia who bought devices from one reseller, CryptoBilis. On-chain researchers have associated more than $86 million in Bitcoin, Ethereum and Tron transfers with suspected theft addresses, but neither the total nor the cause has been confirmed. There is currently no evidence of a Ledger-wide hardware or firmware exploit.

The short version

  • Ledger has confirmed an investigation into fund losses reported by CryptoBilis customers in Southeast Asia.
  • The $86 million figure is an on-chain estimate, not a final loss total verified by Ledger.
  • Device tampering and a supply-chain compromise are possibilities under investigation, not established findings.
  • Ledger has advised people who bought from CryptoBilis within the past 90 days not to initialize unused devices and to consider moving funds to a new signer with a new seed if setup is complete.
  • Published notices do not name SIAMBC or connect SIAMBC-supplied products with the incident.

What happened in the reported $86 million Ledger case

On October 9, 2026, Ledger said it was investigating loss reports from users in Southeast Asia who had purchased devices through CryptoBilis, a reseller operating across Malaysia, Indonesia and the Philippines. Ledger asked the reseller to pause sales and shipments while the investigation continues.

The scale of the story came from blockchain analysis rather than a confirmed victim ledger. Researchers traced transfers on Bitcoin, Ethereum and Tron to suspected theft addresses, with estimates moving from more than $72 million to above $86 million. Those calculations have not been independently confirmed, and different estimates may include overlapping transactions.

Do not treat the headline total as a forensic conclusion. Funds arriving at a flagged address do not prove that every transfer had the same cause or that every wallet used modified hardware. Device inspection, purchase records and victim reports are still needed.

Confirmed facts versus open questions

Question Current position
Is Ledger investigating? Yes. Its public notice concerns Southeast Asian users who purchased through CryptoBilis.
Were reseller sales paused? Ledger said it asked CryptoBilis to stop sales and shipments as a precaution.
Is $86 million the confirmed loss? No. It is an on-chain estimate and may change as addresses and reports are verified.
Were devices physically modified? That is one theory being examined. No final technical report has been published.
Is there a global Ledger vulnerability? No evidence currently supports that conclusion.
Are SIAMBC devices named in the case? No published warning or report currently links SIAMBC inventory to this incident.

Was Ledger hacked?

“Ledger hack” is a useful search phrase but an imprecise description of the evidence. It suggests a remote compromise affecting every Ledger device. The investigation instead focuses on customers of one reseller, which makes a supply-chain issue, pre-seeded device or physical modification more plausible areas to examine.

A pre-seeded wallet can be emptied without a remote device exploit. If an attacker generated or copied the recovery phrase before delivery, they can recreate the wallet elsewhere and sign transactions after the buyer deposits funds. The hardware can remain locked in a drawer while the theft occurs.

A hardware implant is another possibility discussed publicly, but it requires direct examination of affected devices. Until that work is complete, it should be described as a hypothesis rather than the cause.

If you bought from CryptoBilis in the past 90 days

  1. Unopened or not initialized: do not begin setup and do not use any PIN or recovery words supplied in the package. Contact Ledger through its official support channel.
  2. Initialized but unfunded: stop using the device. Do not reuse that recovery phrase in another wallet.
  3. Initialized and funded: consider moving assets to addresses created from a completely new recovery phrase on a device with a verified source. Send a small test transaction first.
  4. Unknown outgoing transaction found: secure remaining assets, preserve transaction IDs, receipts and photos, then contact official support and the appropriate authorities.

A new device is not enough if the seed stays the same. Restoring the old recovery phrase recreates the same wallet. If that phrase was copied, the attacker retains access. Generate a new phrase and transfer assets to new addresses.

What every Ledger user should check

  • Confirm where the device was purchased and retain the receipt or order number.
  • Install Ledger Wallet only from the official website or app store listing and complete Genuine Check.
  • Update the app and device firmware only through official Ledger software.
  • Review outgoing transactions and token approvals for every account you use.
  • Never type a recovery phrase into a website, computer, phone, support form or remote-access session.
  • Ignore unsolicited messages claiming to be Ledger or SIAMBC support.

What customers in Thailand can expect from SIAMBC

Ledger devices sold by SIAMBC are genuine products obtained through a traceable supply channel and are not connected to the reseller under investigation. SIAMBC does not preconfigure recovery phrases or PINs and does not modify the hardware before delivery. Each customer initializes the device, chooses the PIN and generates a fresh recovery phrase on the device.

Customers can complete Genuine Check in Ledger Wallet before depositing assets, inspect the package and device on arrival, and contact the Thailand-based support team with an order number if anything appears unusual. Local after-sales support and warranty service are available under the applicable terms. SIAMBC support will never request a PIN or recovery phrase.

What Ledger Genuine Check can and cannot prove

Genuine Check uses cryptographic attestation from the Secure Element inside the device. Ledger Wallet challenges the device and verifies its response, helping detect counterfeits that cannot authenticate as genuine Ledger hardware. This check also occurs during sensitive operations such as firmware updates and app installation.

Attestation has limits. A genuine Secure Element could potentially remain in a device that has received an unauthorized physical modification. That is why provenance still matters: authenticity checking complements, rather than replaces, a trusted distribution path.

A safe first-time setup should look like this

  • You choose the PIN yourself; no PIN is supplied by the seller.
  • The device generates and displays the recovery phrase during setup.
  • No recovery sheet arrives with words already printed or written on it.
  • You complete Genuine Check before depositing a significant amount.
  • You test receiving and sending with a small value first.

Buy Ledger through a verifiable channel

Genuine Ledger Nano S Plus from SIAMBC

Ledger

Ledger Nano S Plus

฿2,480

  • USB-C connection without Bluetooth
  • Designed for desktop and Android use
  • You create the PIN and recovery phrase during setup
Add to cart
Genuine Ledger Nano X from SIAMBC

Ledger

Ledger Nano X

฿3,360

  • Bluetooth support for iPhone and Android
  • Built-in battery for portable use
  • Verify addresses and transactions on the device display
Add to cart
Genuine Ledger Flex from SIAMBC

Ledger

Ledger Flex

From ฿8,384

  • E Ink touchscreen for clearer transaction review
  • Bluetooth, USB-C and NFC connectivity
  • Works with iPhone, Android and desktop
Choose a colour

Frequently asked questions

Should every Ledger user move funds immediately?

No. The current advisory specifically concerns recent CryptoBilis customers. Other users should verify purchase provenance, run Genuine Check and monitor their accounts instead of making rushed transfers.

Has the $86 million loss been confirmed?

No. It remains an estimate based on blockchain activity and suspected theft addresses.

Does passing Genuine Check guarantee complete safety?

It verifies cryptographic authenticity, but it cannot certify every detail of a device's physical custody history. Trusted sourcing and self-initialization remain essential.

What if recovery words were included in the box?

Do not use them. A legitimate new Ledger does not arrive with a preconfigured PIN or recovery phrase. Stop setup and contact the seller or Ledger through official channels.

Will Ledger or SIAMBC ask for my 24 words?

No. Anyone requesting them is attempting to take control of the wallet.

Conclusion

This is a serious incident, but the evidence available on October 10, 2026 points to purchases through one Southeast Asian reseller, not a universal Ledger compromise. The reported $86 million total and suspected device tampering remain under investigation.

Users can reduce supply-chain risk by buying through a verifiable source, choosing their own PIN, generating the recovery phrase on the device, completing Genuine Check and never sharing the phrase. If a device's origin is uncertain, a truly fresh wallet requires a new seed and new addresses, not merely a replacement device.

Latest Stories

View all

Ledger hardware wallets under inspection following reports of suspected supply-chain tampering

Was Ledger Hacked? What the Reported $86 Million Wallet Theft Means

Ledger is investigating reported losses tied to CryptoBilis customers in Southeast Asia. Here is what is confirmed, what remains uncertain and how users should respond safely.

Read moreabout Was Ledger Hacked? What the Reported $86 Million Wallet Theft Means

Ledger Nano X and Tangem Wallet cards representing a secure crypto wallet migration

Moving Crypto from Ledger to Tangem: Import the Seed or Start Fresh?

Move crypto from Ledger to Tangem safely. Compare a fresh wallet transfer with importing your recovery phrase, and avoid network, gas and passphrase mistakes.

Read moreabout Moving Crypto from Ledger to Tangem: Import the Seed or Start Fresh?

Thai SEC logo with Bitcoin and Ethereum representing Thailand's domestic crypto ETF framework

Thailand Opens the Door to Domestic Crypto ETFs: What the New SEC Rules Mean

Thailand’s SEC has introduced a domestic crypto ETF framework effective 16 October 2026. Here is how the Bitcoin- and Ethereum-focused rules work, what investors will own, and which risks remain.

Read moreabout Thailand Opens the Door to Domestic Crypto ETFs: What the New SEC Rules Mean