The Ledger CryptoBilis hack took $92.9M from 311 wallets. One thief had all the keys
On Friday 9 October, people who had bought Ledger devices from a seller in South East Asia found their crypto gone. We followed every drained wallet on five chains to see how the thief worked and where the money sits now.
- $92.9M
- 3 seconds
- 2 weeks
- 6 in 10
- $10.0M
- 1,254 ETH
01 · What buyers sawWeeks after setting up a Ledger, the money was gone
You buy a Ledger and move your savings onto it. Weeks later you open the app. The balance says zero, and you never sent a thing.
That is what Ledger owners in Indonesia, Malaysia and the Philippines found on Friday 9 October. Ledger says they had bought their devices from CryptoBilis, a shop that sells them in the region. Ledger's post spells it CryptoBillis in one place, and news reports describe it as an official reseller.
Ledger is a French company that makes hardware wallets, small devices that keep the keys to your crypto away from the internet. On the same day it said it was looking into losses among users in South East Asia who bought from CryptoBilis. It asked the reseller to stop all sales, told recent buyers not to set up their devices, and told anyone who had to "consider moving assets to a new Ledger signer (with new seed)".
By then two on-chain researchers had posted the thief's addresses. tanuki42 listed eight and Specter listed ten, with losses above $86 million. Bitquery records every transfer on the chains involved, so we followed each drained wallet and each address the money reached. Our count is $92.9M from 311 wallets on five chains. It is higher because the thief also emptied wallets on BNB Chain and Polygon, and used five TRON addresses that no public list includes.
The record points to one actor who held the keys to every one of those wallets. That person practised for two weeks before the drain, and by the evening was feeding the money into a mixer, a service that hides where coins go. The chain cannot show where the keys leaked from. It can show almost everything else.
02 · The key to a crypto walletWhoever has the 24 words owns the coins
When you set up a Ledger, it shows you 24 words, called the recovery phrase. Those words are the master key to your wallet. Anyone who has them can rebuild the wallet on another device and spend from it, on any chain, without touching your Ledger.
The device's job is to make sure nobody else ever sees those words. That is why Ledger tells buyers to buy only from Ledger or an authorised seller, and CryptoBilis was listed as one. A device that arrives opened, or with words already printed on a card, should never be used.
How the keys leaked this time is not known. Ledger has not said, and some well-known figures, including Binance founder CZ, suggested tampered devices. Hardware wallets have been hit before, as in the Coldcard wallet theft we traced earlier this year. Each case had its own cause. What the chain does show is what happened once the thief had the keys.
03 · Forty-seven minutesThe thief hit five chains in one morning
The first money moved on TRON, a network that many people in Asia use to hold and send USDT, the digital dollar issued by Tether. Within 47 minutes the same thief had emptied wallets on Ethereum, BNB Chain, Polygon and Bitcoin. The full TRON record is in Bitquery's TRON data and the TRON history files on the Data Store.
Most of the money left in the first hour. Then the drains slowed but never stopped. The thief kept emptying wallets through the afternoon, including after Ledger's post, and the last one we saw was at 16:37 UTC.
| Time, UTC | Chain | What happened |
|---|---|---|
| 24 Sep, 16:46 | TRON | A Bybit withdrawal of 14,512 TRX reaches the wallet that funds the thief's TRON address the next day |
| 25 Sep, 09:50 and 09:53 | Ethereum, TRON | The thief's two control addresses get their first money, three minutes apart |
| 26 Sep to 7 Oct | TRON, Ethereum | 21 and 20 small test loops |
| 9 Oct, 05:07:48 | TRON | 13 wallets sign the same approval; the pulls begin |
| 05:07:49 to 05:07:57 | BNB Chain, Polygon | First drains into the thief's EVM addresses |
| 05:07:51 | TRON | 12 more wallets sign; by 05:07:54 the thief has pulled $29.0M |
| 05:07:59 | Ethereum | First Ethereum wallet signs the same kind of approval |
| 05:09 | Ethereum | Three wallets holding about 300 ETH each are emptied |
| 05:54:20 | Bitcoin | 111 wallets emptied in one block, about 203 BTC |
| 05:55 | TRON | A second public drain address starts taking in USDT; it gets $20.1M |
| 09:33 to 09:49 | TRON | $4.8M taken through an address in no public list |
| 12:00 and 12:24 | X | tanuki42 and Specter post the drain addresses |
| 12:09 to 14:10 | TRON | Tether blocks 37 addresses linked to the theft; 20 of them hold $10.0M |
| 13:32 | X | Ledger's statement |
| 15:17 to 15:56 | Ethereum | Three batches, 1,254 ETH, go into Tornado Cash |
| 15:30 | TRON | Tether lifts the block on four OTC-style wallets |
| 16:37 | TRON | Another wallet drained |
04 · One person, all the keysTwenty-five wallets signed the same request within three seconds
On TRON the thief did not send each wallet's USDT straight out. First, each wallet signed an approval, a short note that lets another address move its USDT. Then one address used those approvals to pull the money.
The record shows 25 wallets signing the same approval for the same address in two blocks, three seconds apart. Every one of them paid its own small network fee. Within six seconds of the first approval, $29 million in USDT had been pulled out, 7 million USDT of it from a single wallet.
Eleven seconds after the first TRON approval, an Ethereum wallet signed the same kind of approval for a different address, and a second one followed twelve seconds later. On Bitcoin, 111 wallets were emptied in a single block at 05:54 UTC, each into one of two addresses with a fixed fee. People do not act like this. Software that already held every key does.
There is one other way to get the same picture. A phishing site could collect signed requests from many people over a day and send them all at once. We tested that idea and rate it unlikely. A signed request to send coins names the exact amount. One business wallet sent its whole balance, 4.3 million USDT, to the thief at 09:49 UTC, and that balance had not changed since 03:54. So the request was signed in those six hours, while the drain was already under way. A phishing site would also have needed signatures from 311 wallets on five chains, and the drain was in full swing within an hour.
05 · The practice runsTwo weeks of small tests before the drain
The address that pulled the USDT on TRON was set up on 25 September. Three minutes earlier, the address that did the same job on Ethereum got its first money.
For the next two weeks both ran the same test. Send a wallet a few dollars and some gas, the coin it needs to pay network fees. Have that wallet approve. Pull the dollars back. The TRON address did it 21 times and the Ethereum address 20 times. The last two tests, on 7 October, ran 23 seconds apart.
One test, on 2 October, pulled its three dollars into an address that later took $36 million on the day of the drain. The plan was in place a week before anyone lost a coin.
06 · How much was takenMore than first counted, on more chains
We counted only money that left a victim's wallet. That leaves out swaps the thief made later and money moved between the thief's own wallets, which some early totals counted twice.
| Chain | Victim wallets | Taken | US dollars |
|---|---|---|---|
| TRON | 131 | 70.2M USDT, plus some TRX | $70.5M |
| Bitcoin | 122 | 203.8 BTC | $16.8M |
| Ethereum | 33 | 1,230 ETH, $577,000 in USDT and USDC, 10 billion PEPE | $3.7M |
| BNB Chain | 27 | $1.41M in USDT and USDC, 59.8 BNB | $1.45M |
| Polygon | 13 | 579,773 USDC | $0.58M |
| All chains | 311 | Some wallets were drained on more than one EVM chain, so 58 EVM wallets in all | $92.9M |
On Bitcoin, Ethereum and TRON, the ten public addresses received $85.4M, close to Specter's estimate. Two amounts are in no public tally. The thief took $2.0M on BNB Chain and Polygon, into the same three addresses it used on Ethereum. On TRON it used five more addresses to drain $6.3M, two of them after Ledger's post.
A third Bitcoin address in one public list behaves differently, and we leave it out. It started two days earlier, drains old wallets one at a time, pays much lower fees and shares no wallets with the main two. It holds 9.6 BTC from 154 addresses.
07 · Who lost moneyMost wallets were new, but not all fit Ledger's 90 days
Ledger's advice covers people who bought from the reseller in the last 90 days. We checked when each victim wallet first received money. Of those wallets, 6 in 10 got their first coins inside that window, and more than 8 in 10 got them from June onward.
June stands out. In that month alone, 42 TRON victim wallets got their first coins, just before the 90-day line. A wallet's first payment is not the day its owner bought a device, so this is not proof. But it suggests the risk may reach back about four months, and owners who bought in June should treat Ledger's advice as theirs too.
The money came from the places you would expect for buyers in the region. Bitcoin victims had been paid from Binance, Indodax in Indonesia, OKX and Bybit. Two victims were already named on X by Lookonchain, and the record backs both. One TRON wallet, first funded on 15 September, lost 7 million USDT in the first wave. One Bitcoin wallet got 80 BTC on 29 September and lost all of it in the block at 05:54.
At least one victim was a business. One drained TRON wallet had taken in 33.5 million USDT since 1 October and paid most of it out again to 29 different wallets, the pattern of a business.
08 · Where the money wentInto bridges, swap services and a stablecoin Tether can't touch
Almost all the TRON money was in USDT, which Tether can freeze. The thief moved fast to get it out of reach, and in the first hours the dollars scattered.
The biggest share, 20 million USDT, crossed to Ethereum in 40 equal pieces through the USDT0 bridge, a service that moves USDT between chains. Five fresh wallets swapped it on UniswapX for 7,994 ETH. Another 14.9 million was swapped into USDD, a different stablecoin that Tether cannot freeze. Most of the rest went through swap services such as Relay.link, HiFiSwap and NEAR Intents, which paid the thief back in ETH. We traced the same pattern in the NEAR Intents theft and the $110 million TRON laundering case. Each payout here can be followed wallet by wallet with the Bitquery MCP.
09 · Where it is nowAbout $79M can still be found
The Bitcoin has not moved since it was taken. The largest pile is about 14,810 ETH in a handful of wallets on Ethereum, most of it bought with the stolen USDT. The 15.1 million USDD sits in 7 wallets on TRON. That leaves about $11M that has been spent through other services or that we have not yet followed to the end. You can watch any of these wallets yourself with the Bitquery MCP, and the full histories are sold as files for Bitcoin and Ethereum.
10 · Tether's freeze, then the mixer$10.0M frozen, and the first coins into Tornado Cash
Tether can block any address that holds its USDT. About ten minutes after the first public post, it started blocking addresses linked to the theft, 37 of them over the next two hours. Twenty still held half a million USDT each, so $10 million is now stuck. A block stops the coins moving. It does not send them back to victims, though Tether can later destroy blocked coins and reissue them. News sites reported the freeze the same afternoon.
At 15:30 UTC Tether lifted the block on four wallets. They belong to an OTC-style group, dealers who swap crypto for cash away from the big exchanges. The thief had paid the group about $3.0M, but the wallets held other people's money too.
From 15:17 UTC the thief began sending ETH into Tornado Cash, a mixer that breaks the link between the wallet that pays in and the wallet that later takes out. Three batches of about 400 ETH each went in within 40 minutes, 1,254 ETH in all. We saw no new batch by our data cut-off. If it keeps going at that pace, the ETH could be through the mixer within a day. Our Tornado Cash audit explains how the mixer works and what it hides.
11 · The leadsWhere investigators could ask for records
The chain can't name the thief. It does show places that keep records about their users.
| Lead | What the chain shows | How strong |
|---|---|---|
| Bybit | A withdrawal of 14,512 TRX on 24 September (b284a2…686e) reached the wallet that set up the thief's TRON address the next day | Strong on the money flow |
| Aeroswap | Paid 0.031 ETH five minutes after that withdrawal to 0x444f…2d99, which set up the thief's Ethereum address | Moderate |
| Binance | Two deposit addresses got $794,000 and $557,000 from OTC-style wallets that the thief had paid $3.0M | Moderate: the OTC wallets also held other people's money |
| A vault service | The thief paid in through 12 deposit addresses at TEcDij…Y4XC, which kept about $4.0M | The service's records name the depositor |
| A high-volume service | TZG47z…MrvF took $3.7M in 19 deposits | Owner not known |
| Swap services | Relay.link, HiFiSwap, NEAR Intents, Mayan, LI.FI and Bridgers each handled part of the money | Order records may hold refund addresses and other details |
| Gate.io | 60 BNB reached a Gate.io deposit through a trader's wallet that had paid that deposit 55 times since July 2024 | Weak: the trader looks like a paid counterparty |
The strongest lead is how the thief paid for gas. The TRON address that ran the drain was funded from an address that had withdrawn 14,512 TRX from Bybit the day before. An exchange that sends a withdrawal knows the account it came from. The Ethereum side was funded through Aeroswap, an instant swap service, five minutes after that withdrawal. Other leads are weaker. Money from an exchange shows where funds came from. It does not show who owns the wallet that got them. The same caution applies to the OTC-style group and to a trader who received the thief's BNB and moved it to Gate.io. We show how such dead ends happen in our piece on an $812 million wallet nobody flagged.
When we checked, none of the thief's wallets carried a theft label in the label sets we use. An exchange screening deposits against such labels would not have caught this money on the day.
12 · What we know and what to doThe keys leaked. How is still open
Here is what the chain settles. One actor held the keys to every drained wallet. It tested the method for two weeks, then ran it across five chains in under an hour. Here is what it can't settle: whether the keys leaked from the devices, from the reseller, from a printed card, from an app or from somewhere else. That answer will come from Ledger's own look at the devices.
If you bought a Ledger from CryptoBilis, follow Ledger's advice, even if you bought it before July. Don't set up a device you have not used yet. If you already use one, set up a new device with a new recovery phrase and move your coins to it. Never use a device that arrives with words already written down. Similar lessons came out of the Bitget hack and the TradeWiz drain: once someone else holds your keys, the coins can be gone in seconds.
| Claim on X | Who said it | What the chain shows |
|---|---|---|
| Losses above $86M | Specter | Close: the ten public addresses got $85.4M. All in, we count $92.9M |
| Tether froze USDT linked to the thefts | News reports | Confirmed: $10.0M frozen in 20 wallets |
| A victim lost 7M USDT three weeks after buying | Lookonchain | The wallet was first funded on 15 September and lost 7,001,000 USDT at 05:07:54 |
| A victim lost 80 BTC | Lookonchain | 80 BTC arrived on 29 September and was swept in the block at 05:54 |
| The theft wallets are not labelled anywhere | Security researcher Tay | True of the label sets we checked, on the day |
| Devices were tampered with | CZ and others | The chain cannot test this |
13 · How we did thisMethod
We started from the ten addresses posted by tanuki42 and Specter. We read every payment into and out of them on all five chains from Bitquery's data, and followed the money until it reached a service, a frozen wallet or a wallet that has not moved. We left out money the thief moved between its own wallets, payouts from swap services, and fake tokens sent by scammers who copy addresses. Dollar values use prices from the morning of 9 October. A second, independent check rebuilt every figure from the raw data without seeing our notes. The data stops at 16:45 UTC on 9 October. The thief may have moved since. Our address poisoning study explains why copied addresses fill these wallets with fake transfers, and Bitquery's address labels are the label set we checked first.
Balances and totals were read at 16:45 UTC on 9 October. The thief's wallets were still moving money when we stopped, so later figures will differ.
Dollar values use prices from the morning of 9 October: BTC $82,300, ETH $2,490, BNB $742. USDT, USDC and USDD are counted at $1.
We count money that left a victim's wallet. Payouts from swap services into the thief's addresses, money the thief moved between its own wallets, and fake tokens sent by scammers who copy addresses are left out.
A victim wallet is not a victim person. One owner can have several wallets, and some EVM wallets were drained on more than one chain.
On TRON we count a wallet as a victim when it lost at least $10 in USDT. A few more wallets lost smaller amounts or only TRX; their coins are in the dollar total but not in the wallet count.
The first payment into a wallet tells us when it started to be used. It does not tell us when its owner bought a device.
Exchange and service names come from Bitquery's address labels and from how the money behaves. A payment from an exchange shows where money came from. It does not show who owns the wallet that received it.
We could not find the source of a few small payouts into the thief's Ethereum wallets, and we have not followed every payment past the first service it reached.
| What | Address or transaction |
|---|---|
| TRON drain address (public) | TK6DWN…XT6C |
| TRON drain address (public) | TBkcUM…s9d9 |
| TRON drain address (public) | TCGE3x…MNsW |
| TRON drain address (public) | TSDWtu…Ar5a |
| TRON drain address (not in public lists) | TYohhJ…UfGj |
| TRON drain address (not in public lists) | TELKRM…ZznW |
| TRON drain address (not in public lists) | TQoTZG…P9FQ |
| TRON drain address (not in public lists) | TRTVHp…2bzE |
| TRON drain address (not in public lists) | TRMHXE…GpDQ |
| Thief's TRON control address | TAzdU7…CSYQ |
| Wallet that funded it from Bybit | TWGHw7…Bf3E |
| EVM drain address (public; also used on BNB Chain and Polygon) | 0x69c8…7841 |
| EVM drain address (public; also used on BNB Chain and Polygon) | 0x0336…4f7a |
| EVM drain address (public; also used on BNB Chain and Polygon) | 0x83ae…a599 |
| Thief's Ethereum control address | 0x3818…f8f2 |
| ETH holding wallet | 0x468b…2a4e |
| ETH holding wallet | 0xfa4e…b0e2 |
| ETH holding wallet | 0x064a…7160 |
| ETH holding wallet | 0xb88d…1856 |
| ETH holding wallet | 0x131c…fa6a |
| ETH holding wallet | 0x40eb…e88c |
| ETH holding wallet (small) | 0x9400…40d6 |
| Bitcoin drain address (public) | bc1qjq…49dl |
| Bitcoin drain address (public) | bc1qqn…jtm9 |
| Bitcoin address in one public list, likely a separate operation | bc1qgq…d26n |
Follow the stolen money in plain English
Every transfer, approval and balance in this story comes from Bitquery's data for the five chains involved. The Bitquery MCP server puts that data behind an AI assistant, so you can ask where a wallet's money went or what labels an address carries, without writing the query yourself. The full histories are also sold as files on the Bitquery Data Store, for TRON, Bitcoin, Ethereum, BNB Chain and Polygon.
FAQ
Was Ledger hacked?
Nothing public so far shows a break-in at Ledger itself. Wallets of people who bought Ledger devices from the reseller CryptoBilis were drained by someone who held their keys. Ledger is investigating how those keys leaked and has paused sales through that reseller.
What is CryptoBilis?
CryptoBilis, also spelled CryptoBillis, is a crypto hardware shop that sells Ledger devices in Indonesia, Malaysia and the Philippines. News reports describe it as an official Ledger reseller. On 9 October 2026 Ledger asked it to stop all sales and shipments of Ledger devices while it investigates.
How much was stolen in the Ledger CryptoBilis hack?
We count $92.9M taken from 311 wallets on TRON, Bitcoin, Ethereum, BNB Chain and Polygon. Most of it was USDT on TRON. Early counts of about $86 million covered only the ten public addresses.
Can a Ledger be hacked?
The device is built so the recovery phrase never leaves it. If someone else gets that phrase, they control the wallet without the device. That can happen through a tampered device, a pre-printed recovery card, a fake app or a phishing site. In this case the thief clearly held the keys. How they got them is not yet known.
Is my Ledger safe if I bought it from a reseller?
If you bought from CryptoBilis, follow Ledger's advice: don't set up an unused device, and move your coins to a new device with a new recovery phrase. Many victim wallets were first funded in June 2026, before Ledger's 90-day window, so earlier buyers should take the same step.
Can the stolen crypto be recovered?
About $10 million in USDT is frozen by Tether, which can later reissue frozen coins. The Bitcoin has not moved, and most of the ETH still sits in known wallets. Money that went through Tornado Cash or into USDD is harder to recover.
Is this the same as the 2023 Ledger hack?
No. In December 2023 a fake version of Ledger's Connect Kit code library drained people who used certain crypto websites for a few hours. In 2020 a breach exposed customer emails and home addresses. This case is different: the thief held the recovery keys of hundreds of wallets and emptied them directly.
This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, and nothing in it is a recommendation to buy, sell, or hold any token or asset.
The findings describe transfers, approvals and balances observed on TRON, Bitcoin, Ethereum, BNB Chain and Polygon between 24 September and 9 October 2026. Attributions come from Bitquery's address labels and from on-chain behaviour; they may be incomplete or incorrect and may be revised as more data becomes available.
References to Ledger, CryptoBilis, Tether, Bybit, Binance, Gate.io, Aeroswap or any other named company, service or protocol describe what the record shows about addresses and transactions linked to them. They are not statements about any party's security practices, compliance or conduct, and nothing here asserts that any named party acted unlawfully or negligently. The wallets that received the drained funds are described by their behaviour and attributed to nobody.
Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.
Reported by Gaurav Agarwal for Bitquery Research, with AI tools; every figure was checked against the raw data.