Loading prices…
STKR NewsSTKR News0 of 3 free this month
Markets

Ledger investigates wallet drains involving CryptoBilis buyers; estimate tops $86 million in losses

A massive security breach involving Ledger reseller CryptoBilis has left users $86 million poorer, reminding builders that the supply chain is the weakest link in self-custody.

Originally on The Block →
AB

Adrian Boysel

Contributor

Oct 9, 2026

4 min read

Photo illustration / STKR News

We talk a lot about code audits and smart contract risks, but we often ignore the physical journey a piece of plastic and silicon takes before it hits your desk. The recent reports coming out of Southeast Asia regarding Ledger and its official reseller, CryptoBilis, are a cold shower for anyone who thinks a hardware wallet is a magic shield.

Ledger is currently investigating a wave of wallet drains that allegedly target users who purchased devices through this specific third-party vendor. The numbers being tossed around aren't small change. We are looking at estimates topping $86 million in evaporated capital. For those of us building in this space, this isn't just a headline about a hack; it is a fundamental breakdown of the trust model we sell to the public.

The Supply Chain is the Real Attack Surface

As a founder, you learn quickly that your product is only as secure as its weakest touchpoint. In the case of hardware wallets, the device itself might be a fortress, but the distribution network is often a series of unlocked doors. The reports suggest that users in Malaysia and surrounding regions, who did the "right thing" by buying from an authorized partner, found their addresses drained shortly after setup.

This points to a classic supply chain compromise. If a bad actor gets their hands on a shipment of devices before they reach the customer, they don't need to crack Ledger's secure element. They just need to swap the recovery sheet with a pre-configured one or modify the firmware. When the user sets it up, they aren't generating their own keys; they are using keys the attacker already owns.

Why Authorized Resellers Aren't a Guarantee

We tell new users to avoid eBay and Amazon and stick to "authorized resellers." It’s the standard advice. But this incident shows that even official channels can be compromised. CryptoBilis was a major player in the region, not some fly-by-night operation. If an internal employee or a logistics partner at a high-volume reseller goes rogue, the entire reputation of the hardware manufacturer is on the line.

Ledger is in a tough spot here. They don't control the physical security of a warehouse in Kuala Lumpur or the hiring practices of a local distributor. However, the brand name on the box is theirs. When $86 million disappears, the victim doesn't blame the delivery driver; they blame the logo on the device.

The Builder Perspective: Can We Fix Trust?

For those of us building infrastructure or wallet-as-a-service layers, this is a wake-up call about the limitations of physical self-custody for the masses. We’ve spent years telling people to "be their own bank," but we rarely mention that being your own bank also means being your own chief of security, logistics manager, and vault inspector.

If a technical user can get fooled by a sophisticated supply chain attack, what hope does a retail user have? This is why I’ve been leaning more toward skeptical optimism regarding Multi-Party Computation (MPC) and account abstraction. The idea that a single physical device holds the keys to a kingdom is becoming a legacy mindset that carries too much localized risk.

The $86 Million Question

The scale of this loss is staggering. To put $86 million in perspective, that is larger than many Series B funding rounds for the very startups trying to secure these assets. The fact that this stayed under the radar until it reached this magnitude suggests a coordinated, long-term effort by the attackers. They weren't just grabbing a few bucks; they were harvesting access over time.

Ledger’s response will be a case study in crisis management. If they can’t verify the integrity of their reseller network, the value proposition of the hardware wallet begins to erode. For builders, the takeaway is clear: don't rely on a single point of failure, even if that point is made of secure-grade silicon.

What This Means for the Future of Custody

I expect to see a pivot in how we handle hardware setup. We need better on-device attestation that doesn't just check if the software is genuine, but verifies that the entropy used to create the keys wasn't tampered with physically. We also need to stop treating authorized resellers as a binary "safe" or "unsafe" category.

If you are building a product that requires users to hold their own keys, you need to account for the fact that their hardware might be compromised from day one. Multi-sig setups and social recovery aren't just features anymore; they are necessities. The "gold standard" of a single hardware wallet is looking more like a single point of failure every day.

Practical Advice for Founders

  • Diversify your corporate treasury: Never keep your startup's runway on a single device or even a single brand of hardware.
  • Audit your team's hygiene: It doesn't matter how good your dev-ops is if your CTO bought their Ledger from a compromised source two years ago.
  • Build for resilience: Assume the user's local environment is compromised. How does your dApp or protocol protect them then?

The CryptoBilis situation is a tragedy for the individuals who lost their life savings, but for the industry, it's a necessary lesson. We are moving out of the era of "trust this box" and into an era where we must verify every step of the journey. If we can't secure the physical path from the factory to the pocket, we haven't actually solved the problem of digital ownership.


Read the original at The Block →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses