Back to News
Bitcoin holder loses 80 BTC worth $5.2 million after moving funds to reseller-bought Ledger

A Bitcoin holder watched 80 BTC, worth $5.2 million, vanish after moving the coins onto a Ledger hardware wallet. The device was not bought from Ledger directly. It came from CryptoBilis, a reseller operating in Southeast Asia.The transfer to the new device happened just one week before the funds disappeared.The 80 BTC loss is not an isolated case. Multiple buyers who purchased Ledger devices through the same reseller have reported significant losses.Ledger confirmed on October 9, 2026, that it is investigating fund losses connected to CryptoBilis. The company is not waiting for the investigation to finish before issuing guidance.Anyone who bought a Ledger from the reseller in the last 90 days has been told not to initialize their device. Ledger is also advising those buyers to move their assets to new Ledger wallets set up with different seed phrases.Another victim reported losing 7 million USDT, a dollar-pegged stablecoin. That user had bought a Ledger device three weeks before the incident.On-chain analysts have tracked assets flowing to theft addresses across several blockchain networks. Trackers have identified $17.7 million in BTC and $29 million worth of ETH equivalents sitting in wallets linked to the thefts.Analysts' estimates of the total damage range from $72 million to over $87 million, spread across numerous victim wallets.The cause has not been confirmed. Speculation centers on two possibilities: supply-chain tampering, where a device is compromised before it reaches the buyer, or phishing attacks that trick users into handing over sensitive information.So far, no reports indicate that Ledger devices bought through official channels have been affected. That points toward a localized issue tied to CryptoBilis.The reseller's footprint covers Southeast Asian markets including Indonesia, Malaysia, and the Philippines.If supply-chain tampering turns out to be the cause, the security model breaks down if someone gets to the hardware first. If phishing is behind the losses, the takeaway shifts toward user behavior and how victims were targeted.For now, the practical steps are straightforward. Anyone who bought a Ledger from CryptoBilis in the past 90 days should follow the company's guidance: do not initialize the device, and move funds to a new Ledger wallet with a different seed phrase.Ledger's investigation will need to determine what actually happened, whether the reseller was complicit or itself a victim, and whether the damage extends beyond the current estimates.