Ledger users lost more than $86 million on October 9, 2026 on Bitcoin, Ethereum and Tron. Binance founder Changpeng Zhao (CZ) believes these thefts stem from a supply chain attack, linked to a single seller. Ledger is investigating and the cause is not confirmed.

In brief
- $86 million stolen from Ledger users.
- Ledger is investigating reported losses among buyers of CryptoBilis, in Southeast Asia, and has requested a suspension of its sales.
- Changpeng Zhao (CZ) talks about supply chain attack.
- Tether froze $1.45 million in USDT, raised after three hours.
Hack Ledger: What happened and how much was stolen?
On October 9, 2026, Ledger announced that it was investigating losses of funds among users in Southeast Asia who purchased their physical wallet from the reseller CryptoBilis. Analyst Specter puts these losses at more than $86 million, on Bitcoin, Ethereum and Tron. Ledger has not confirmed the cause or the number of devices affected. Where did the funds go? Arkham has grouped 152 addresses under the label “ledger drainer”their portfolio worth $71.6 million. Arkham tracing also shows outflows to other addresses, ranging from $500,000 to $4 million each.
Three counts, three results. Specter is talking about more than $86 million. MistTrack places the losses close to 90 million. Arkham shows 71.6 million. The discrepancy partly comes from the scope because the capture attached to Specter’s post shows another Arkham entity, valued at around $87 million. It’s like three watches that don’t display the same second: they describe the same event, not at the same minute.
| Active | Quantity held | Value (USD) |
| Ether (ETH) | 11,822 ETH | $29.4 million |
| Bitcoin (BTC) | 213,371 BTC | $17.68 million |
| USDD | 13.646 M USDD | $13.65 million |
| Tether (USDT) | 10.849M USDT | $10.85 million |
Tether also reacted. According to MistTrack, the issuer froze USDT on addresses linked to the thefts. Do not confuse this freeze with that of THORChain, the same day that approximately 1.45 million USDT was locked in its vaults on Tron, then released approximately three hours later. Tether did not explain this second freeze, and no link with the thefts is confirmed.
What does CZ say about Ledger wallets being hacked?
On October 9, 2026, CZ (Changpeng Zhao) ruled on X that the thefts appear linked to a supply chain attack, limited to a single seller. This type of attack involves trapping a product before it reaches the customer. Here is his message:
Based on available information, this appears localized to a supply chain attack with a single vendor. A small number of people have likely purchased fake Ledgers (or doctored Ledgers).
Three scenarios therefore remain open:
- Counterfeit: a fake device that imitates the Ledger;
- Physical modification: a real device to which a component has been added or altered;
- Recovery phrase known to a third party, whatever the cause.
In a second message, CZ advises waiting a few weeks before putting a large sum in a new wallet. Except the threat is hard to see. Ledger’s Genuine Check does not detect a physical modification as long as the original chip remains intact, according to Ledger documentation on Genuine Check. It remains useful against counterfeits.
Mark Karpelès, former CEO of Mt. Gox, presented on X a Ledger that he says has been modified, with a hidden implant. According to him, such a device could read the screen and retrieve the recovery phrase during setup. He also asked CryptoBilis to open devices in stock for inspection. Nothing establishes at this stage that this device comes from CryptoBilis, nor that this implant explains the thefts. No source consulted also says how long after the purchase the funds disappeared.
What does Ledger recommend to CryptoBilis buyers?
On October 9, 2026, Ledger Support requested that CryptoBilis suspend all its sales and shipments of Ledger devices. Ledger recommends that customers of this reseller in the last 90 days do not initialize their device. Those who have already done so may consider moving their funds to a new device, with a new recovery phrase.
Victims of this Hack Ledger should therefore remain careful because no one, not even fake technical support, needs this phrase. Ledger directs its customers to its official support channels, where they can open a ticket. The alert targets buyers in Southeast Asia and a single reseller. Ledger does not cite any other reseller at this stage.
As of October 10, 2026, no end date for the investigation has been announced, despite the release of Changpeng Zhao (CZ). Future communications from Ledger and MistTrack will certainly reveal whether these thefts come from hardware implants or some other mechanism. Do you think this Ledger hack could expand to European customers?
Maximize your Tremplin.io experience with our ‘Read to Earn’ program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
