A crypto holder watched 80 Bitcoin vanish in minutes after moving the coins onto a fresh Ledger hardware wallet.
The device came from Southeast Asian reseller CryptoBillis, and the loss wiped out both the original $5.2 million purchase and a $1.38 million paper profit.
On-chain trackers first flagged the empty wallet on Friday, October 9, 2026.
Four months earlier the same investor had bought the 80 BTC near $65,000 each. The position sat quietly while Bitcoin climbed.
Then, roughly a week before the drain, the holder purchased a Ledger through CryptoBillis and transferred every coin onto the new device.
On October 9, the entire balance left in a single transaction headed for addresses already linked to stolen funds.

What Exactly Happened to This Ledger User?
Lookonchain documented the timeline: coins arrived on September 29 and disappeared at 05:54 UTC on October 9.
The address now shows zero. Meanwhile, investigators counted similar drains across hundreds of wallets that had also bought Ledger devices from the same reseller.
Total losses tied to the pattern later climbed past $86 million and, in some tallies, near $93 million across Bitcoin, Ethereum, Tron and other chains.
Did the CryptoBillis Device Arrive Already Compromised?
Ledger has not confirmed the precise method. However, the company quickly asked CryptoBilis (also spelled CryptoBillis) to pause all sales and shipments.
In parallel, Ledger told anyone who bought from the reseller in the previous 90 days not to initialise the device.
Those who had already set one up received advice to move assets onto a brand-new Ledger created with a fresh seed phrase.
Notably, Ledger stated it found no evidence that its own systems, firmware or official sales channel had been breached.

Is Ledger Itself Hacked, or Is This a Supply-Chain Problem?
On current public evidence the answer points away from a company-wide breach.
Instead, the pattern centres on devices that passed through one authorised regional reseller serving Malaysia, Indonesia and the Philippines.
Furthermore, multiple on-chain researchers observed that many victim wallets signed transfers in tight clusters, suggesting a single party already held the recovery phrases.
In addition, some devices reportedly passed software integrity checks yet still emptied, which raises questions about possible physical tampering or pre-loaded seeds before the units reached customers.
What Should Recent CryptoBillis Buyers Do Right Now?
Ledger’s guidance remains clear: leave unopened devices powered off and unused.
Move any funds already loaded onto a new, independently purchased Ledger with a completely new seed.
Beyond that, buyers can verify the purchase channel against Ledger’s official reseller list and avoid any third-party seller that cannot prove sealed, factory-direct stock.

Subsequently, monitoring the wallet address on a block explorer provides an early warning if unexpected outgoing transactions appear.
Hardware wallets still offer strong offline key storage when the supply chain stays intact.
This episode nevertheless shows why many long-time users insist on buying only through the manufacturer’s own store or carefully vetted partners.
The 80-BTC loss serves as a costly reminder that even the best cold-storage device cannot protect funds if the recovery phrase is already known to someone else before the box is opened.

