- Onchain investigator Specter reports more than $86 million in suspected cryptocurrency thefts involving Ledger users across Bitcoin, Ethereum and TRON.
- Arkham Intelligence identifies 98 addresses holding approximately $86.96 million in cryptocurrency.
- Ledger is investigating reports involving Southeast Asian reseller CryptoBilis and has asked it to suspend sales and shipments.
- Security researchers are seeking evidence that could determine whether the thefts share a common cause.
Ledger is investigating cryptocurrency theft reports involving customers in Southeast Asia after onchain researchers traced more than $86 million in suspected losses from wallets associated with its hardware devices.
The company has asked reseller CryptoBilis to suspend sales and shipments while it investigates reports involving customers who purchased devices through the distributor.
Separately, blockchain investigator Specter identified ten suspected theft addresses across Bitcoin, Ethereum and TRON. An Arkham Intelligence dashboard, shared by CoinBureau, labeled “ledger user theft” shows a broader cluster of 98 addresses holding approximately $86.96 million in digital assets.
The developments introduce two distinct investigative questions: where the cryptocurrency moved and whether the reported incidents share a common method of compromise.
Ledger’s reseller investigation is a significant new lead, although the company has not established that the entire amount traced by researchers originated from devices distributed through CryptoBilis.
Ledger Investigates Southeast Asian Reseller
According to an October 9 statement reported by Unchained, Ledger is examining reports of lost funds from users who purchased products through CryptoBilis, a reseller operating in Southeast Asia.
The company asked the distributor to stop selling and shipping Ledger devices pending the investigation.
Ledger also issued specific guidance to customers who bought devices from CryptoBilis during the preceding 90 days. Customers who have not completed setup were advised to postpone initializing their devices, while those already using them were told to consider transferring assets to accounts generated using a new recovery phrase on a new Ledger signer.
That recommendation goes beyond ordinary precautions against malicious token approvals.
A recovery phrase determines the private keys associated with a wallet. If the phrase is exposed, an attacker may reconstruct the wallet elsewhere without obtaining physical access to the original device.
Moving cryptocurrency to another Ledger device while continuing to use the same compromised phrase would therefore leave the assets exposed.
However, the precautionary advice does not establish that CryptoBilis supplied tampered devices, that recovery phrases were compromised during distribution or that the reseller caused the reported losses.
Ledger’s statement did not confirm the $86 million estimate or provide a number of affected customers.
The distinction is particularly relevant because at least one publicly reported victim said their Ledger had been purchased directly from the company’s official website.
That account has not been independently connected to the reseller investigation.
Onchain Trail Reveals Concentrated Crypto Holdings
Specter began tracing suspicious transactions after complaints from Ledger users appeared on X and Reddit.
There have been a reports on X and Reddit of wallet-draining by Ledger users.
I traced the theft addresses and identified inflows from more hundreds of victim wallets across several major blockchains, including Ethereum, TRON, and Bitcoin.
Total losses $86M+
bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl
TK6DWNpNe1w2iJRNFpU8aHdrPTATxvXT6C
TBkcUMYC7CkTK99tkTnaStQVBastfrs9d9
TCGE3xp6YGRKXxDZiLfysgJW3f22KfMNsW
0x69c8f401cfc6cd40ac94691d6d7c48e3b7a47841
0x033636e45d519bebb7b5c2520ca6ce56fbdb4f7a
0x83aeac166f6832ae3500000a24510a95a052a599
bc1qqnkwurxs99xkx5t4yffqhq3u6qwy0qpjyujtm9
bc1qgqheemzla77pesl227hdtgf5ykz62d0zvld26n
TSDWtuZ2pARUVz4v3PkL2hi3iXPjowAr5a— Specter (@SpecterAnalyst) October 9, 2026
The investigator published ten receiving addresses associated with suspected thefts from hundreds of wallets. Those addresses held more than $25 million when the publication reviewed them, indicating that substantial funds had already moved beyond the initially identified destinations.
Security researcher tanuki42 had earlier flagged eight addresses and estimated losses above $72 million. Specter’s subsequent tracing expanded the address list and the reported total.
The Arkham dashboard provides a separate portfolio snapshot, showing where major balances are concentrated within its labeled cluster.
ARKHAM INTELLIGENCE · WALLET CLUSTER
$86.96M
98 addresses tracked · October 9, 2026
| ASSET | AMOUNT | VALUE |
|---|---|---|
| ETH Ethereum |
16,843 | $42.15M 48.5% |
| BTC Bitcoin |
211.199 | $17.56M 20.2% |
| USDT Tether |
16.5M | $16.50M 19.0% |
| USDD Stablecoin |
10.523M | $10.52M 12.1% |
Source: Arkham Intelligence, October 9, 2026. Rounded valuations; smaller holdings excluded. Portfolio value does not independently establish theft losses.
Ethereum represents nearly half of the displayed value, while Bitcoin accounts for roughly one-fifth. Stablecoins make up most of the remaining major positions.
These distinctions matter for asset recovery. Native Bitcoin cannot be frozen by a token issuer, while certain stablecoins include administrative controls that may allow balances to be restricted under appropriate circumstances.
The two headline estimates also require careful interpretation.
Specter’s figure concerns suspected unauthorized transfers. Arkham’s displayed balance measures cryptocurrency held by a labeled set of addresses at a particular point in time.
Funds transferred repeatedly between attacker-controlled wallets can complicate loss calculations, and changes in market prices can affect the value of a portfolio after the original transactions.
The 98 addresses shown by Arkham also do not represent a verified count of individual victims.
One person may own several affected wallets, while one attacker can control multiple receiving addresses.
Among the destinations publicly associated with the investigation is Bitcoin address bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl, which reportedly received more than 211 BTC.
Tracking subsequent movements from the address may help establish whether funds reached centralized exchanges, where investigators could potentially seek account information or intervention through applicable legal procedures.
Why Bitcoin Complicates the Attack Theory
A common route for cryptocurrency theft involves malicious token approvals.
On Ethereum and TRON, users can authorize another address or contract to spend specified tokens on their behalf. If the permission is excessive or granted to a malicious party, tokens may be transferred later without an additional signature from the wallet owner.
Native Bitcoin does not use that authorization model.
Its unspent transaction output, or UTXO, structure requires a transaction to satisfy Bitcoin-specific spending conditions. An unauthorized USDT approval on TRON cannot independently transfer BTC from a Bitcoin address.
If investigators establish that native Bitcoin was taken directly from affected users, they will need to determine how the relevant transactions were signed.
A compromised recovery phrase could explain movements across multiple networks because one phrase may derive accounts on different blockchains.
Other explanations include exposed private keys, unauthorized physical access with the necessary credentials or separate attacks targeting different users.
There is also a limitation to interpreting destination balances: Bitcoin appearing in a suspected receiving wallet does not prove that BTC was the asset originally stolen. Criminals may exchange other cryptocurrency for Bitcoin after the initial transfers.
The original transaction histories, rather than the final composition of receiving wallets, will be decisive in identifying the attack method.
Ledger Stax User Reports Nearly $100,000 Loss
One October 9 Reddit complaint illustrates the difficulty of establishing how a transaction was authorized.
The user reported losing nearly $100,000 in USDT from a wallet associated with a Ledger Stax device.
According to the post, the recovery phrase had been handwritten and stored in a safe. The user claimed the wallet was used primarily to receive cryptocurrency and had not been used to approve transactions knowingly.
In subsequent comments, the user identified a TRON transaction described as an unauthorized approval granting unlimited USDT spending permission.
The transaction hash was:
- 3cdf99929cea12ed7963f19077425643cc3ad82ba116759e201254e0a04a92cc
An approval can explain how a designated spender gained permission to move tokens. However, its existence does not establish whether the authorization came from exposed recovery credentials, a deceptive signing interface or another technical failure.
The user later said Ledger support had suggested possible recovery-phrase exposure after observing unauthorized movements across several accounts.
That remains the user’s description of a private support assessment rather than a published forensic finding.
In a public response, an account marked as official Ledger Customer Success advised preserving transaction information and avoiding further deposits to addresses that might remain compromised.
This warning is particularly important for token approvals. A malicious allowance can remain valid even after existing funds are removed, creating a risk that newly deposited tokens will also be transferred.
The Reddit complaint does not establish a connection between that transaction and every wallet included in the broader onchain investigation.
Security Alliance Coordinates Reports as Stablecoins Offer Recovery Options
The Security Alliance has urged users whose funds moved to the flagged addresses to seek assistance through SEAL 911, its cryptocurrency incident-response initiative.
🚨 Please get in contact with us ASAP if your funds were drained to these addresses.
@SEAL_911 Telegram: [@]seal_911_bot
— Security Alliance (@_SEAL_Org) October 9, 2026
The organization connects affected users with security researchers who can investigate active thefts and help coordinate responses.
For tracing purposes, the most useful evidence includes:
- Original transaction hashes: Records showing how and when funds left affected wallets.
- Recipient addresses: Destinations that can be linked to unauthorized transfers and subsequent asset movements.
- Signing and approval records: Evidence distinguishing direct transfers from transactions involving delegated spending permissions.
- Common exposure patterns: Information about device provenance, applications, recovery procedures or services shared by affected users.
The asset mix identified on Arkham also creates potential intervention points.
Tether can freeze USDT at designated addresses under certain circumstances. In December 2023, the issuer used that capability during a security incident involving Ledger Connect Kit.
In that incident, attackers compromised software publishing credentials associated with a former Ledger employee and distributed malicious code through a library used by decentralized applications.
The code redirected users toward fraudulent transactions. Ledger’s official incident report documented the software compromise and Tether’s subsequent freezing of USDT belonging to the attacker.
The case demonstrated that software surrounding a hardware wallet can create security exposure without requiring private keys to be extracted from the device itself.
For the current investigation, the practical questions are whether suspected stolen stablecoins remain at identifiable addresses and whether their ownership can be established to a standard sufficient for intervention.
USDD would require separate examination of its contract controls and applicable procedures.
There has been no confirmation that the stablecoins in the newly identified Arkham cluster have been frozen. Even if funds are restricted, reimbursement would still require ownership verification and further coordination.
Ledger’s August Security Disclosures Provide Technical Context
Ledger disclosed several transaction-signing vulnerabilities in August, highlighting why hardware wallet security depends on more than isolated private-key storage.
Security Bulletin 024 described a problem in the Ethereum application’s transaction-review process.
A counting error could cause the device to display fewer operations than the signed transaction actually authorized. In a demonstrated scenario involving 257 operations, the device reviewed only one while producing a signature covering the complete batch.
The issue required specific conditions, including a compromised host and a compatible transaction structure. Ledger said the proof of concept was tested without transferring real funds on a public blockchain.
Security Bulletin 025 identified a separate weakness in the Ethereum application’s swap process.
Under narrowly defined conditions, the application could authorize a token spending permission when it was expected to sign a payment. The resulting approval was limited to the address and quantity already accepted in the swap workflow.
It could not grant an arbitrary unlimited allowance to an attacker-selected address.
Ledger said it had no evidence that the latter vulnerability had been exploited. Both issues were corrected in Ethereum application version 1.22.3.
These disclosures illustrate why transaction parsing and trusted-screen verification are critical. A device may protect its private keys while application software incorrectly interprets the operation being authorized.
Neither August security bulletin has been connected to the current theft reports.
What the Investigation Could Establish Next
Ledger’s decision to suspend sales through a specific reseller creates an additional line of investigation alongside the onchain tracing.
If affected devices share a distribution channel, investigators may examine how the products were handled before reaching customers and whether any common setup or recovery procedure created an opportunity for compromise.
If thefts also involve users who purchased directly from Ledger or through unrelated channels, researchers would need to determine whether those cases share the same cause.
The available evidence does not yet resolve that question.
For customers who purchased devices through CryptoBilis in the specified period, Ledger’s targeted guidance should take priority over general security advice.
Other users concerned about unauthorized activity should review transaction histories, identify suspicious spending permissions and verify application updates through official Ledger channels.
Anyone who believes their recovery phrase has been exposed should understand that the associated accounts remain vulnerable regardless of which physical device is used to access them.
The size of the tracked portfolio gives the investigation financial significance, but it does not identify the security failure behind the transfers.
That determination will depend on connecting individual victim transactions with evidence from devices, software, recovery credentials and distribution records.
A common cause would point toward a coordinated compromise requiring targeted remediation. Unrelated signing and credential-exposure incidents would require a different response.
The most important finding now is not another increase in the estimated loss total, but evidence explaining how attackers obtained control of funds that users believed were protected by hardware wallets.



