$86M Gone: Ledger's Reseller Just Became the Biggest Supply-Chain Threat in Crypto
Hardware wallets were supposed to be the safe option, and now tens of millions of dollars have vanished from wallets purchased through a single Ledger reseller called CryptoBilis.
Ledger has confirmed an active investigation into what could be one of the most damaging supply-chain attacks ever recorded in the crypto hardware space. The number currently being cited is $86 million in drained funds, and the attack vector is chilling in its simplicity: compromised devices sold before they ever reached the customer.
How Supply-Chain Attacks Work, and Why This One Hits Different
A supply-chain attack means the device was tampered with between the manufacturer and your hands. You could do everything right, set up your wallet correctly, never click a phishing link, never share your seed phrase, and still lose everything. The threat was baked in before the box was even opened.
This is not a Ledger software bug. This is not a user error story. This is the scenario the entire hardware wallet industry has quietly feared and publicly downplayed for years.
CryptoBilis operated as an authorized reseller, which means customers had every reason to trust the product they received. That trust is now the crime scene.
What We Know and What We Don't
Ledger has not yet confirmed the full scope of affected wallets or disclosed how the devices were compromised at the reseller level. The investigation is ongoing. What is confirmed is that the theft is linked specifically to wallets purchased through CryptoBilis, and that Ledger is treating this as a serious, active incident.
The $86 million figure puts this alongside some of the largest DeFi exploits in recent memory, except this one targeted people who thought they had already moved beyond DeFi risk.
What Crypto Holders Should Do Right Now
If you purchased a Ledger device through any third-party reseller, not directly from Ledger's official website, this is the moment to act:
- Check your purchase source. If CryptoBilis appears anywhere in your order history, treat your device as compromised. - Do not move funds using a potentially affected device. Any transaction signed on a tampered device may expose your keys. - Transfer to a clean wallet immediately if you have any doubt about your device's origin. - Watch for Ledger's official guidance. The company is expected to release further detail as the investigation progresses.
The broader implication here extends beyond Ledger. Every hardware wallet manufacturer that relies on a reseller network now faces the same question: how secure is the chain between factory and front door?
The answer, right now, is not secure enough.