Ledger Warns CryptoBilis Buyers as Analyst Fears Wider Losses
Ledger is investigating reports of missing funds among CryptoBilis customers as analysts trace suspected thefts across several networks. Photo: Ledger
Technology & Security

Ledger Warns CryptoBilis Buyers as Analyst Fears Wider Losses

Ledger has asked CryptoBilis to pause sales as Darkfost warns losses could exceed an early $86 million estimate; the cause remains unconfirmed.

Make us preferred on Google

Key Notes

  • Ledger has asked CryptoBilis to pause sales and shipments, warning customers who bought devices from the reseller within the past 90 days.
  • Darkfost suspects a wider compromise and larger losses, but has not published a revised total or a confirmed attack mechanism.
  • The earlier $86 million estimate remains unverified, while Ledger says its own infrastructure, systems and services were not compromised.

Ledger has asked reseller CryptoBilis to suspend sales and shipments while it investigates reports of missing cryptocurrency from customers in Southeast Asia. The warning gives recent buyers a specific precaution to follow as onchain researchers investigate suspected thefts previously estimated at more than $86 million.

Analyst Darkfost has now warned that the damage could be more widespread than early reports suggest. After beginning to trace the funds, he said the scale was unlike anything he had personally investigated and raised the possibility of a compromise involving devices supplied through CryptoBilis.

That is an investigative hypothesis, not a confirmed finding. Neither Darkfost’s post nor Ledger’s public warning establishes how access to the wallets was obtained, the final loss total or the number of affected customers.

Ledger’s Warning Targets Recent CryptoBilis Buyers

In its October 9 customer warning, Ledger said people who purchased from CryptoBilis within the past 90 days should not initialize devices that have not yet been set up. Customers who have already completed setup were advised to consider moving assets to a new Ledger signer with a new recovery seed.

The request to pause sales and shipments was described as a precaution pending the investigation. Ledger directed customers with questions to its official support channels and said it would provide further updates. The notice does not instruct every Ledger owner to move funds, regardless of where or when a device was purchased.

The company separately told Cointelegraph that the incident appeared isolated to the reseller and affected market. It said it had received no reports involving purchases directly from Ledger, and that its infrastructure, systems and services had not been compromised. The investigation remains ongoing.

Darkfost Raises the Possibility of Wider Losses

Darkfost’s concern goes beyond the initial dollar estimate. He suspects a broader compromise through the reseller rather than an isolated wallet exploit, and urged owners of recently purchased Ledger devices to consider moving funds to exchanges or other wallets, depending on the assets involved.

His recommendation is broader than Ledger’s reseller-specific notice. The post does not provide a revised dollar total, identify a confirmed hardware modification or demonstrate that all recently sold Ledger devices are affected. It should not be read as proof of a vulnerability across the company’s product range.

The analyst also argued that an incident involving devices compromised before sale would be difficult to contain. That concern explains the focus on preventing further exposure, but it does not establish that this was the attack method or that a particular remote remedy has been tested and ruled out.

The $86 Million Figure Remains a Preliminary Estimate

CoinScreamer’s earlier report covered investigator Specter’s assessment of more than $86 million in suspected thefts across Bitcoin, Ethereum and TRON. The estimate came from tracing addresses associated with reported losses, rather than a confirmed accounting released by Ledger.

Specter initially referred to hundreds of victim wallets, then clarified that the actual wallet count had not been established. That distinction remains relevant: an address cluster can contain collection wallets and subsequent transfers, not just separate victims.

Blockchain analytics platform Arkham has also published a tracking update describing more than $80 million reportedly taken from Ledger users across the same three networks. Arkham explicitly said the cause was unconfirmed. Its post does not reconcile that figure with Specter’s estimate or establish a separate pool of losses.

The figures therefore should not be added together. A verified total would require identifying the original unauthorized outflows, establishing which customers and devices were involved, and avoiding double counting as funds move between addresses. Darkfost’s warning indicates concern about scope; it does not complete that reconciliation.

Why the Warning Specifies a New Recovery Seed

Ledger’s existing security guidance explains that a recovery phrase restores the same wallet on another compatible device. If someone else knows that phrase, simply importing it into replacement hardware does not remove their access. This is the distinction between replacing a device and creating a new wallet with different keys.

That is general security context, not evidence that recovery phrases caused these losses. The guidance also stresses generating a recovery phrase yourself and rejecting preconfigured devices. Separately, CoinScreamer has covered clear signing, which addresses the different risk of approving transaction instructions without understanding them.

Ledger’s phishing warnings say its staff will never request a customer’s recovery phrase. Fraudulent support messages or recovery websites can create a second risk for people reacting to theft reports; those existing warnings do not establish the cause of the current investigation.

The next material update is a supported explanation of the failure and a clearer account of affected purchases and losses. For now, Ledger’s confirmed action is the reseller sales-pause request and targeted customer warning, while the wider compromise theory remains under investigation.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

News, Technology & Security