Ledger CryptoBilis Reseller Supply-Chain Drain
An estimated $86 million was drained from Ledger users who bought devices from reseller CryptoBilis, in a suspected supply-chain attack that captured their seed phrases.
Vuln-watch · relayed from a public source; see Source & attribution below
Summary
An estimated $86 million was drained from Ledger users who bought devices from reseller CryptoBilis, in a suspected supply-chain attack that captured their seed phrases.
Incident
- Victim: Ledger users (CryptoBilis)
- Date (UTC): 2026-10-09
- Estimated loss: $86.0M
- Chain(s): Ethereum, Bitcoin, Tron
- Attack type: private key compromise
- Funds status: stolen
Recommended actions
- If you use Ledger users (CryptoBilis), move funds to a fresh wallet with a new seed phrase once the vendor confirms the root cause
- Update the wallet software only from official sources
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
Full analysis on Blockchain Breaches, 0xCERT's incident archive: https://www.blockchainbreaches.com/en/breaches/ledger-cryptobilis-2026. Primary sources: https://news.bitcoin.com/security/ledger-investigating-86m-drained-crypto-hardware-wallets/ ; https://cryptopotato.com/ledger-investigates-86m-crypto-drain-as-reseller-supply-chain-fears-grow ; https://www.financemagnates.com/cryptocurrency/ledger-probes-reseller-supply-chain-as-analysts-track-80m-in-suspected-drains/ ; https://www.tftc.io/ledger-cryptobilis-reseller-86m-drained-funds.
References
- https://www.blockchainbreaches.com/en/breaches/ledger-cryptobilis-2026
- https://news.bitcoin.com/security/ledger-investigating-86m-drained-crypto-hardware-wallets/
- https://cryptopotato.com/ledger-investigates-86m-crypto-drain-as-reseller-supply-chain-fears-grow
- https://www.financemagnates.com/cryptocurrency/ledger-probes-reseller-supply-chain-as-analysts-track-80m-in-suspected-drains/
- https://www.tftc.io/ledger-cryptobilis-reseller-86m-drained-funds
Indicators of compromise
All IOC feeds →- address0x033636e45d519bebb7b5c2520ca6ce56fbdb4f7aReported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Ethereum
- address0x69c8f401cfc6cd40ac94691d6d7c48e3b7a47841Reported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Ethereum
- address0x83aeac166f6832ae3500000a24510a95a052a599Reported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Ethereum
- addressTBkcUMYC7CkTK99tkTnaStQVBastfrs9d9Reported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Tron
- addressTCGE3xp6YGRKXxDZiLfysgJW3f22KfMNsWReported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Tron
- addressTK6DWNpNe1w2iJRNFpU8aHdrPTATxvXT6CReported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Tron
- addressTSDWtuZ2pARUVz4v3PkL2hi3iXPjowAr5aReported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Tron
- addressbc1qgqheemzla77pesl227hdtgf5ykz62d0zvld26nReported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Bitcoin
- addressbc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dlReported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Bitcoin
- addressbc1qqnkwurxs99xkx5t4yffqhq3u6qwy0qpjyujtm9Reported theft collection address (Specter, on-chain investigator; not confirmed by Ledger) · Bitcoin
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-10-09 · last updated 2026-10-10
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0232/signed.txt | gpg --verify