Key Notes
- Specter estimates more than $86 million in suspected theft associated with Ledger user reports across Bitcoin, Ethereum and TRON.
- His initial claim of hundreds of affected wallets remains preliminary, and the 98 addresses in his screenshot do not establish a verified victim count.
- The cause of the reported outflows is unknown, with no demonstrated Ledger device vulnerability or independently audited loss total.
Onchain investigator Specter has flagged more than $86 million in suspected cryptocurrency theft linked to reports from Ledger users, raising questions about unexplained wallet outflows across Bitcoin, Ethereum and TRON.
In an October 9 post on X, the analyst said he reviewed complaints on X and Reddit and traced addresses he associated with the thefts. His preliminary findings do not establish that Ledger hardware devices were compromised.
Specter outlines his preliminary investigation into theft reports from Ledger users.
— Specter (@SpecterAnalyst) October 9, 2026
The cause remains unknown. The material published so far does not identify a shared vulnerability, explain how transactions were authorized or demonstrate that private keys were extracted from a Ledger device.
What Specter’s Initial Evidence Shows
Specter published Bitcoin, Ethereum and TRON addresses and initially described inflows from hundreds of victim wallets. In a subsequent clarification, however, he said he had not yet established the actual number of wallets and was continuing to identify other suspected theft addresses.
A screenshot accompanying the report shows an Arkham portfolio labeled “ledger user theft,” containing 98 addresses and a displayed balance of approximately $86.96 million. That is the value shown for the analyst’s grouped addresses, rather than an independently audited total of unique victims’ losses.
Another image collects social-media complaints from people describing missing funds and saying they had kept their recovery phrases offline. These accounts provide leads for an investigation, but do not independently establish how access was obtained.
The Loss Estimate and Attack Method Remain Unverified
CoinScreamer has not independently verified the complete address cluster or the aggregate loss estimate. The $86 million figure should therefore be treated as Specter’s preliminary assessment, subject to further tracing and reconciliation.
An address count is also different from a victim count: one person can control several addresses, while funds can move through multiple collection wallets. Establishing a final loss total requires identifying the original unauthorized transfers and avoiding double counting money as it moves between addresses.
The published evidence does not establish whether the reports share a single cause. Their association with Ledger users warrants investigation, but it does not by itself distinguish a device vulnerability from other ways an attacker could obtain spending authority.
Why a Wallet Drain Does Not Identify the Failure
Ledger’s existing security guide explains that a recovery phrase can restore a wallet on another compatible device. Someone who obtains that backup can consequently access the corresponding assets without possessing the original hardware wallet.
The guide also emphasizes reviewing transaction details on the device’s trusted display. Protecting a private key and understanding what a signature authorizes are separate parts of wallet security. CoinScreamer has previously covered clear signing, which makes transaction instructions easier to inspect before approval.
These are general security considerations, not established explanations for Specter’s findings. The investigation has not demonstrated recovery-phrase exposure, deceptive signing or a hardware-level exploit as the common cause of the reported losses.
Existing Ledger Guidance Warns Against Recovery Scams
Ledger’s ongoing phishing warnings say its staff will never ask users to disclose their recovery phrase. The company documents fake applications, support impersonation and fraudulent messages directing people to websites that request wallet backups or unauthorized transactions.
That guidance predates this report and should not be read as Ledger’s explanation of the alleged theft cluster. For now, the unresolved questions are the verified losses, the number of affected owners and the mechanism behind the outflows; none is settled by the portfolio screenshot alone.
Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.