Tether freezes stolen USDT as Ledger reseller breach approaches $90 million
A supply chain breach tied to a single Ledger hardware wallet reseller in Southeast Asia has pushed suspected losses toward $90 million, prompting Tether to freeze stolen USDT as investigators scramble to trace the funds. The episode raises fresh questions about how thoroughly authorized resellers vet the devices they distribute before they reach customers.
- Suspected Ledger wallet thefts linked to reseller CryptoBilis now approach $90 million, according to MistTrack.
- Ledger asked CryptoBilis to pause sales and told recent buyers not to initialize unconfigured devices.
- Former Mt. Gox CEO Mark Karpelès is inspecting unsold CryptoBilis wallets for hidden spying implants.
- $90M estimated losses from the breach, according to MistTrack
- $86M initial estimate from investigator Specter before MistTrack revised it higher
- 90 days lookback window Ledger set for flagged CryptoBilis purchases
- 3 countries where CryptoBilis is listed as an authorized Ledger reseller
Ledger said on October 9 it was investigating reports that customers lost funds after buying hardware wallets from CryptoBilis, an authorized reseller operating across Malaysia, Indonesia and the Philippines, according to reporting by CryptoSlate. The company asked CryptoBilis to immediately pause sales and shipments while it investigates, and advised anyone who bought a device from the reseller in the past 90 days not to initialize it if setup was not already complete.
Customers who had already configured their wallets were told to consider moving their holdings to a new Ledger device set up with a fresh recovery phrase. Ledger has not said how many devices may be compromised.
CryptoBilis sat inside Ledger’s official reseller network
CryptoBilis appears in Ledger’s own reseller directory for the three Southeast Asian markets, which is the arrangement customers typically rely on to avoid counterfeit or pre-compromised hardware. That status is now central to the investigation, since the suspected losses trace back to one distributor rather than a broad flaw in Ledger’s devices.
Binance founder Changpeng Zhao weighed in on X, framing the incident as narrow in scope rather than a systemic failure of Ledger’s security model.
Based on information so far, it seems to be localized to a supply chain attack with one vendor.
Changpeng Zhao, founder, Binance
Zhao, posting on X, said a limited number of customers may have received counterfeit or tampered devices and called on the industry to help trace and recover the stolen assets, adding he expects “all BNB ecosystem players (and all industry)” to assist.
Karpelès probes CryptoBilis stock for hardware implants
Former Mt. Gox CEO Mark Karpelès is pursuing a separate line of inquiry. He asked CryptoBilis to open unsold Ledger wallets so their circuit boards could be checked for unauthorized components, according to his post on X.
The concern touches a known limit in Ledger’s own authentication process. The company’s security documentation acknowledges that its Genuine Check system verifies the device’s Secure Element but cannot necessarily detect physical modifications elsewhere in the hardware if that chip is untouched, meaning a tampered unit could still pass the check. No confirmed evidence has tied hardware implants to the reported thefts, and Ledger has not said whether counterfeit parts, physical tampering or another method is responsible.
MistTrack lifts the loss estimate past $86 million to near $90 million
On-chain investigator Specter first estimated the thefts at more than $86 million, tracing inflows from hundreds of suspected victim wallets into addresses across Bitcoin, Ethereum and Tron, according to a post on X. Blockchain security firm MistTrack later put the figure closer to $90 million, a roughly $4 million increase over Specter’s initial count, though neither estimate has been independently verified.
MistTrack said it observed Tether freezing USDT connected to the incident after several affected users contacted its team. The freeze relies on administrative controls built into USDT that let Tether block transfers from designated addresses, a tool it has used before; the stablecoin issuer froze 134 wallets tied to a separate sanctions case earlier this year.
Tether cannot freeze native Bitcoin or Ethereum directly, so recovery of assets on those chains depends on cooperation from exchanges and law enforcement. MistTrack has not disclosed the dollar value of the USDT it restricted, leaving the share of the roughly $90 million that might ultimately be recovered unclear.
The BlockWest read. The real exposure here sits with resellers, not Ledger’s firmware. Any treasury or custodian buying hardware wallets at scale now has to audit its supply chain the way it audits counterparties, verifying devices arrived sealed and unmodified before funding them. Tether’s freeze buys time but does not return funds, so the recovery question now rests on exchanges and Southeast Asian authorities acting on CryptoBilis, not on Ledger’s code.
Ledger has not disclosed the total number of affected devices or confirmed whether counterfeit parts, tampering, or another method caused the losses, and Karpelès’s inspection of CryptoBilis’s unsold stock has yet to produce public findings. Investigators are watching whether MistTrack discloses the dollar value of the frozen USDT, which would determine how much of the nearly $90 million can realistically be recovered.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
