- Ledger said it is investigating reports that a number of users have had funds drained, with affected wallets indicated to have been purchased from a Malaysian reseller called CryptoBilis. The Paris-based company has asked that reseller to pause all sales and shipments pending the investigation.
- Ledger advised anyone who bought an unused device from CryptoBilis in the last 90 days not to set it up, and said those already using such devices should consider moving funds to another wallet. The company declined further comment and CryptoBilis did not immediately respond.
- This follows a series of attacks on hardware wallets, including the theft of more than $100 million in bitcoin from wallets hosted by Canada-based Coinkite. Hardware wallets, or cold storage, are typically regarded as among the safest places to hold cryptocurrency because they combine a physical device with private passwords.
- The pattern points to the distribution channel rather than the technology. If compromised devices reached users through one reseller, the security model of the hardware may be intact while the path between manufacturer and customer was not.
What Happened?
The incident is ongoing and the number of affected users and the value of losses have not been disclosed.
Why It Matters?
The attack surface here is one a buyer cannot inspect. A hardware wallet is purchased precisely so the owner need not trust an exchange, yet the device arrives through a chain of manufacturers, distributors and resellers, any of which can be compromised before it reaches the customer. The practical consequence is that where a device was bought matters as much as which device it is, and that is not a question most purchasers think to ask. Ledger’s guidance to leave unused devices from that reseller unopened is the right immediate response. The larger point concerns what self-custody actually achieves. It is marketed as removing counterparty risk, and it does remove exchange risk, but it substitutes reliance on manufacturers, resellers and firmware integrity. Those parties operate with far less regulatory oversight than a custodian, and crucially there is no recovery mechanism. A drained wallet has no deposit insurance, no chargeback and no equivalent of securities investor protection, so the loss is final in a way a brokerage breach is not. Two significant incidents in recent months, including over $100 million of bitcoin through Coinkite, suggest this is a category of risk rather than isolated failures. The timing matters for advisers. The SEC has just proposed rules permitting investment advisers to custody digital assets, and the comment period will define what qualifies as a custodian. Incidents like this strengthen the case for regulated institutional custody with audit trails, segregation of duties and insurance, which cuts against the self-custody premise that originally motivated the technology but favours the channel through which most client assets will actually be held. Advisers holding crypto for clients, or advising clients who self-custody, now have a concrete reason to ask about procurement chains and about what happens when something goes wrong.
What Next?
Ledger’s investigation should establish whether devices were tampered with in transit, whether the reseller was compromised, or whether another mechanism was involved, and the answer determines how widely the risk extends. Watch for disclosure of how many users were affected and how much was taken, neither of which is currently known. For the sector, whether these incidents shift holdings from self-custody toward regulated custodians is the measurable consequence. The SEC custody proposal is where any regulatory response would appear, and the qualified custodian definition is the provision to read closely.
Affected Tickers and Coins: BTC, COIN
Source: Bloomberg














