Ledger Users Lose $86M as CZ Points to Supply-Chain Attack

Ledger is investigating losses exceeding $86 million reported by users in Southeast Asia who bought hardware wallets from reseller CryptoBilis. Changpeng Zhao suggested the thefts may stem from a supply-chain attack tied to a single vendor, while Ledger has not confirmed the cause or number of devices affected. Arkham grouped 152 addresses under a 'ledger-drainer' label holding about $71.6 million, and Tether froze some USDT linked to the incident.
On Oct. 9, 2026, Ledger said it was investigating losses among Southeast Asian buyers who used reseller CryptoBilis. Analyst estimates varied: Specter cited over $86 million across Bitcoin, Ethereum and Tron, MistTrack near $90 million, while Arkham’s “ledger-drainer” cluster of 152 addresses held about $71.6 million.
CZ described the pattern as likely a supply-chain compromise involving one seller, suggesting buyers may have received counterfeit or altered Ledger devices. Ledger has not confirmed the cause or how many devices are involved. Tether froze USDT on addresses linked to the thefts, according to MistTrack; a separate THORChain-related freeze of roughly $1.45 million was later released and has no confirmed connection.
The incident may deepen doubts about hardware-wallet supply chains, especially for buyers in regions relying on third-party resellers. Crypto holders could become more cautious about verifying devices and sources, potentially slowing adoption of self-custody. Exchanges, issuers like Tether, and blockchain analysts may face pressure to trace and freeze stolen assets faster. If tampered