Arkham Intelligence flagged a sweeping set of drains this week that emptied wallets belonging to Ledger hardware-wallet owners.
The tracker labelled the activity “Ledger Drainer” and placed the running total above $80 million spread across Bitcoin, Ethereum and Tron.
Ledger itself confirmed it is investigating while the precise method of key compromise remains unconfirmed.

How Much Money Left Wallets in the Ledger $80M Hack?
On-chain tallies started in the low seventies of millions and climbed quickly.
Arkham’s custom entity captured more than $80 million in combined value at the time of its public post.
Parallel researchers later counted figures ranging from $86 million to nearly $93 million once additional chains and addresses entered the picture.
Notably, the largest single Bitcoin loss alone reached 80 BTC, while TRON stablecoin sweeps accounted for the bulk of the dollar total.
Which Chains Did the Ledger Drainer Target Most Heavily?
Bitcoin, Ethereum and TRON absorbed the heaviest hits. Tron carried tens of millions in USDT, Bitcoin saw more than 200 BTC leave victim addresses, and Ethereum lost over a thousand ETH plus assorted tokens.
In addition, smaller amounts appeared on BNB Chain and Polygon. Meanwhile, the same set of collector addresses received funds from hundreds of separate victim wallets, pointing to one coordinated actor holding many recovery phrases at once.

Has Anyone Confirmed the Exact Cause of These Ledger Losses?
Ledger stated it found no evidence that its own infrastructure, firmware or official sales channel suffered a breach.
Instead, the company linked the reports to devices purchased through one Southeast Asian reseller, CryptoBilis (also written CryptoBillis).
Following that assessment, Ledger asked the reseller to halt all sales and shipments.
At the same time, the firm advised anyone who bought from that channel in the prior 90 days to avoid initialising an unused device and to move already-loaded funds onto a fresh Ledger created with an entirely new seed.

What Practical Steps Can Affected Users Take Right Now?
Anyone who acquired a Ledger through the flagged reseller should treat the device as potentially compromised until proven otherwise.
Beyond that, users can open the Arkham entity page that tracks the drainer’s addresses and watch outgoing movements in real time.
In parallel, exchanging any remaining balances onto a new hardware wallet bought directly from Ledger’s own store removes the risk of a pre-shared seed.
Interest in supply-chain verification has risen sharply among long-term holders who previously treated authorized resellers as fully equivalent to factory channels.
The episode leaves a clear lesson: even the strongest cold-storage design fails if the recovery phrase is known to an outsider before the box reaches the buyer.
Tracking tools such as Arkham’s labelled entity now give the community visibility that was harder to obtain in earlier incidents.

