On-chain investigationLedger9 October 2026

The Ledger CryptoBilis hack took $92.9M from 311 wallets. One thief had all the keys

On Friday 9 October, people who had bought Ledger devices from a seller in South East Asia found their crypto gone. We followed every drained wallet on five chains to see how the thief worked and where the money sits now.

At a glance
We count $92.9M taken from 311 wallets on TRON, Bitcoin, Ethereum, BNB Chain and Polygon, more than first reported. Ledger links the losses to devices bought through CryptoBilis, its reseller in Indonesia, Malaysia and the Philippines. Dozens of wallets signed the same request within seconds, after two weeks of test runs, which points to one thief holding all the keys. Tether froze $10.0M. About $79M can still be found on the chain, and some of it is now going into Tornado Cash.
$92.9M
Taken from 311 wallets on five chains
3 seconds
For 25 TRON wallets to sign the same approval
$10.0M
USDT frozen by Tether in 20 wallets
1,254 ETH
Sent into Tornado Cash on the afternoon of 9 October
Key findingsEach line has its own share link
  1. $92.9M

    Taken from 311 wallets on five chains, more than the $86M first reported from the ten public addresses.

  2. 3 seconds

    For 25 TRON wallets to sign the same approval. Only someone holding all their keys fits that.

  3. 2 weeks

    Of practice before the drain: 21 small test loops on TRON and 20 on Ethereum.

  4. 6 in 10

    Victim wallets were first funded inside Ledger's 90-day window. More than 8 in 10 were funded from June.

  5. $10.0M

    Frozen by Tether. Another 15.1 million USDD, a stablecoin Tether cannot freeze, sits in the thief's wallets.

  6. 1,254 ETH

    Sent into Tornado Cash in three batches on 9 October. About 14,810 ETH still sat in the thief's wallets.

01 · What buyers sawWeeks after setting up a Ledger, the money was gone

You buy a Ledger and move your savings onto it. Weeks later you open the app. The balance says zero, and you never sent a thing.

That is what Ledger owners in Indonesia, Malaysia and the Philippines found on Friday 9 October. Ledger says they had bought their devices from CryptoBilis, a shop that sells them in the region. Ledger's post spells it CryptoBillis in one place, and news reports describe it as an official reseller.

Ledger is a French company that makes hardware wallets, small devices that keep the keys to your crypto away from the internet. On the same day it said it was looking into losses among users in South East Asia who bought from CryptoBilis. It asked the reseller to stop all sales, told recent buyers not to set up their devices, and told anyone who had to "consider moving assets to a new Ledger signer (with new seed)".

By then two on-chain researchers had posted the thief's addresses. tanuki42 listed eight and Specter listed ten, with losses above $86 million. Bitquery records every transfer on the chains involved, so we followed each drained wallet and each address the money reached. Our count is $92.9M from 311 wallets on five chains. It is higher because the thief also emptied wallets on BNB Chain and Polygon, and used five TRON addresses that no public list includes.

The record points to one actor who held the keys to every one of those wallets. That person practised for two weeks before the drain, and by the evening was feeding the money into a mixer, a service that hides where coins go. The chain cannot show where the keys leaked from. It can show almost everything else.

02 · The key to a crypto walletWhoever has the 24 words owns the coins

When you set up a Ledger, it shows you 24 words, called the recovery phrase. Those words are the master key to your wallet. Anyone who has them can rebuild the wallet on another device and spend from it, on any chain, without touching your Ledger.

The device's job is to make sure nobody else ever sees those words. That is why Ledger tells buyers to buy only from Ledger or an authorised seller, and CryptoBilis was listed as one. A device that arrives opened, or with words already printed on a card, should never be used.

How the keys leaked this time is not known. Ledger has not said, and some well-known figures, including Binance founder CZ, suggested tampered devices. Hardware wallets have been hit before, as in the Coldcard wallet theft we traced earlier this year. Each case had its own cause. What the chain does show is what happened once the thief had the keys.

03 · Forty-seven minutesThe thief hit five chains in one morning

The first money moved on TRON, a network that many people in Asia use to hold and send USDT, the digital dollar issued by Tether. Within 47 minutes the same thief had emptied wallets on Ethereum, BNB Chain, Polygon and Bitcoin. The full TRON record is in Bitquery's TRON data and the TRON history files on the Data Store.

The drain, hour by hourmoney taken from victim wallets every 15 minutes, 9 October 2026 (UTC)
MONEY DRAINED FROM VICTIM WALLETS, EVERY 15 MINUTES, 9 OCTOBER 2026 (UTC)TRONBitcoinEthereumBNB ChainPolygon$0M$10M$20M$30M$40M05:0006:0007:0008:0009:0010:0011:0012:0013:0014:0015:0016:0017:00first posts naming drain addressesLedger's statementBitcoin's 111 sweeps landed in one block at 05:54. Swap payouts and moves between the thief's own wallets are left out.
Bars count only money leaving a victim's wallet, in US dollars at 9 October prices. TRON bars are USDT; a small amount of TRX is left out. Most of the money left before 06:00, but drains went on long after the thief's addresses were public.

Most of the money left in the first hour. Then the drains slowed but never stopped. The thief kept emptying wallets through the afternoon, including after Ledger's post, and the last one we saw was at 16:37 UTC.

Time, UTCChainWhat happened
24 Sep, 16:46TRONA Bybit withdrawal of 14,512 TRX reaches the wallet that funds the thief's TRON address the next day
25 Sep, 09:50 and 09:53Ethereum, TRONThe thief's two control addresses get their first money, three minutes apart
26 Sep to 7 OctTRON, Ethereum21 and 20 small test loops
9 Oct, 05:07:48TRON13 wallets sign the same approval; the pulls begin
05:07:49 to 05:07:57BNB Chain, PolygonFirst drains into the thief's EVM addresses
05:07:51TRON12 more wallets sign; by 05:07:54 the thief has pulled $29.0M
05:07:59EthereumFirst Ethereum wallet signs the same kind of approval
05:09EthereumThree wallets holding about 300 ETH each are emptied
05:54:20Bitcoin111 wallets emptied in one block, about 203 BTC
05:55TRONA second public drain address starts taking in USDT; it gets $20.1M
09:33 to 09:49TRON$4.8M taken through an address in no public list
12:00 and 12:24Xtanuki42 and Specter post the drain addresses
12:09 to 14:10TRONTether blocks 37 addresses linked to the theft; 20 of them hold $10.0M
13:32XLedger's statement
15:17 to 15:56EthereumThree batches, 1,254 ETH, go into Tornado Cash
15:30TRONTether lifts the block on four OTC-style wallets
16:37TRONAnother wallet drained

04 · One person, all the keysTwenty-five wallets signed the same request within three seconds

On TRON the thief did not send each wallet's USDT straight out. First, each wallet signed an approval, a short note that lets another address move its USDT. Then one address used those approvals to pull the money.

The record shows 25 wallets signing the same approval for the same address in two blocks, three seconds apart. Every one of them paid its own small network fee. Within six seconds of the first approval, $29 million in USDT had been pulled out, 7 million USDT of it from a single wallet.

The first 40 secondswallets signing the same approval, and the USDT pulled out, 05:07:45 to 05:08:25 UTC
THE FIRST 40 SECONDS, 05:07:45 TO 05:08:25 UTCTRON wallets sign the approvalTRON: USDT pulled outEthereum wallets sign the approvalEthereum: USDT pulled out05:07:4505:07:5505:08:0505:08:1505:08:2513 wallets at 05:07:4812 more at 05:07:51, the next block1 wallet, $1.30M18 wallets, $12.8M6 wallets, $14.9M$78k$6k
Each red square is one wallet signing an approval for the same address. Each green circle is the USDT pulled out in that second, sized by amount. All 25 TRON wallets signed inside two consecutive blocks.

Eleven seconds after the first TRON approval, an Ethereum wallet signed the same kind of approval for a different address, and a second one followed twelve seconds later. On Bitcoin, 111 wallets were emptied in a single block at 05:54 UTC, each into one of two addresses with a fixed fee. People do not act like this. Software that already held every key does.

There is one other way to get the same picture. A phishing site could collect signed requests from many people over a day and send them all at once. We tested that idea and rate it unlikely. A signed request to send coins names the exact amount. One business wallet sent its whole balance, 4.3 million USDT, to the thief at 09:49 UTC, and that balance had not changed since 03:54. So the request was signed in those six hours, while the drain was already under way. A phishing site would also have needed signatures from 311 wallets on five chains, and the drain was in full swing within an hour.

05 · The practice runsTwo weeks of small tests before the drain

The address that pulled the USDT on TRON was set up on 25 September. Three minutes earlier, the address that did the same job on Ethereum got its first money.

For the next two weeks both ran the same test. Send a wallet a few dollars and some gas, the coin it needs to pay network fees. Have that wallet approve. Pull the dollars back. The TRON address did it 21 times and the Ethereum address 20 times. The last two tests, on 7 October, ran 23 seconds apart.

Two weeks of practicesmall test loops run by the thief's TRON and Ethereum addresses, 25 September to 9 October 2026
TEST LOOPS BEFORE THE DRAIN: EACH DOT IS ONE SMALL PULL-BACK25 Sep27 Sep29 Sep1 Oct3 Oct5 Oct7 Oct9 OctTRON21 loopsEthereum20 loopscontrol wallets fundeddrainEach loop: send a few dollars and some gas to a wallet, have it approve, pull the coins back.
Each dot is the thief's address pulling a few dollars back from a wallet it had funded minutes earlier. The two addresses got their first money three minutes apart on 25 September.

One test, on 2 October, pulled its three dollars into an address that later took $36 million on the day of the drain. The plan was in place a week before anyone lost a coin.

06 · How much was takenMore than first counted, on more chains

We counted only money that left a victim's wallet. That leaves out swaps the thief made later and money moved between the thief's own wallets, which some early totals counted twice.

Where the money was takenmoney taken from victim wallets, by chain, in US dollars at 9 October prices
MONEY TAKEN FROM VICTIMS, BY CHAIN (US DOLLARS AT 9 OCTOBER PRICES)TRON$70.5MBitcoin$16.8MEthereum$3.68MBNB Chain$1.45MPolygon$0.58M
Victim wallets only. Full histories for BNB Chain and Polygon are on the Bitquery Data Store, like the other three chains.
ChainVictim walletsTakenUS dollars
TRON13170.2M USDT, plus some TRX$70.5M
Bitcoin122203.8 BTC$16.8M
Ethereum331,230 ETH, $577,000 in USDT and USDC, 10 billion PEPE$3.7M
BNB Chain27$1.41M in USDT and USDC, 59.8 BNB$1.45M
Polygon13579,773 USDC$0.58M
All chains311Some wallets were drained on more than one EVM chain, so 58 EVM wallets in all$92.9M

On Bitcoin, Ethereum and TRON, the ten public addresses received $85.4M, close to Specter's estimate. Two amounts are in no public tally. The thief took $2.0M on BNB Chain and Polygon, into the same three addresses it used on Ethereum. On TRON it used five more addresses to drain $6.3M, two of them after Ledger's post.

A third Bitcoin address in one public list behaves differently, and we leave it out. It started two days earlier, drains old wallets one at a time, pays much lower fees and shares no wallets with the main two. It holds 9.6 BTC from 154 addresses.

07 · Who lost moneyMost wallets were new, but not all fit Ledger's 90 days

Ledger's advice covers people who bought from the reseller in the last 90 days. We checked when each victim wallet first received money. Of those wallets, 6 in 10 got their first coins inside that window, and more than 8 in 10 got them from June onward.

How new were the victims' wallets?month each victim wallet first received money, as a share of wallets per chain
WHEN EACH VICTIM WALLET FIRST RECEIVED MONEY (SHARE OF WALLETS, BY CHAIN)2024–2025Jan–May 2026June 20261–10 JulyLast 90 daysTRON124271131 walletsBitcoin2210101367122 walletsEthereum32833 walletsLedger asked people who bought from the reseller in the last 90 days to act.
Teal is Ledger's 90-day window. June 2026 is the large amber block, just before it. A wallet's first payment is a clue to when its owner started using it. It does not prove when the device was bought.

June stands out. In that month alone, 42 TRON victim wallets got their first coins, just before the 90-day line. A wallet's first payment is not the day its owner bought a device, so this is not proof. But it suggests the risk may reach back about four months, and owners who bought in June should treat Ledger's advice as theirs too.

The money came from the places you would expect for buyers in the region. Bitcoin victims had been paid from Binance, Indodax in Indonesia, OKX and Bybit. Two victims were already named on X by Lookonchain, and the record backs both. One TRON wallet, first funded on 15 September, lost 7 million USDT in the first wave. One Bitcoin wallet got 80 BTC on 29 September and lost all of it in the block at 05:54.

At least one victim was a business. One drained TRON wallet had taken in 33.5 million USDT since 1 October and paid most of it out again to 29 different wallets, the pattern of a business.

08 · Where the money wentInto bridges, swap services and a stablecoin Tether can't touch

Almost all the TRON money was in USDT, which Tether can freeze. The thief moved fast to get it out of reach, and in the first hours the dollars scattered.

Where the stolen dollars went firstfirst service or wallet reached by the USDT stolen on TRON, in millions
FIRST STOP FOR THE STOLEN USDT ON TRON (MILLIONS OF DOLLARS)USDT0 bridge to Ethereum20.0Swapped into USDD14.9Frozen by Tether10.0Relay.link9.4Unnamed vault service4.6Unnamed high-volume service3.7HiFiSwap3.4OTC-style wallets3.0NEAR Intents1.6Bridgers0.6Other0.2Two services sent some money back and it was sent on again, so the bars add to slightly more than the 70.2M stolen.
Green is frozen by Tether, red was turned into USDD, which Tether cannot freeze. Blue went on through a bridge or swap service, most of it ending up as ETH.

The biggest share, 20 million USDT, crossed to Ethereum in 40 equal pieces through the USDT0 bridge, a service that moves USDT between chains. Five fresh wallets swapped it on UniswapX for 7,994 ETH. Another 14.9 million was swapped into USDD, a different stablecoin that Tether cannot freeze. Most of the rest went through swap services such as Relay.link, HiFiSwap and NEAR Intents, which paid the thief back in ETH. We traced the same pattern in the NEAR Intents theft and the $110 million TRON laundering case. Each payout here can be followed wallet by wallet with the Bitquery MCP.

09 · Where it is nowAbout $79M can still be found

Where the $92.9M sits nowsplit of everything taken, at 16:45 UTC on 9 October
WHERE THE MONEY SITS AT 16:45 UTC, 9 OCTOBER$16.8M$36.9M$15.1M$10.0M$11.1MBitcoin, never moved: $16.8METH in attacker wallets: $36.9MUSDD on TRON: $15.1MUSDT frozen by Tether: $10.0MInto Tornado Cash: $3.12MSpent or not yet traced: $11.1METH, BTC and BNB at 9 October prices; USDT and USDD at $1. Swaps and fees mean the parts are an estimate of the whole.
Grey is money spent through other services or not yet followed to the end. The ETH in attacker wallets was mostly bought with the stolen USDT.

The Bitcoin has not moved since it was taken. The largest pile is about 14,810 ETH in a handful of wallets on Ethereum, most of it bought with the stolen USDT. The 15.1 million USDD sits in 7 wallets on TRON. That leaves about $11M that has been spent through other services or that we have not yet followed to the end. You can watch any of these wallets yourself with the Bitquery MCP, and the full histories are sold as files for Bitcoin and Ethereum.

10 · Tether's freeze, then the mixer$10.0M frozen, and the first coins into Tornado Cash

Tether can block any address that holds its USDT. About ten minutes after the first public post, it started blocking addresses linked to the theft, 37 of them over the next two hours. Twenty still held half a million USDT each, so $10 million is now stuck. A block stops the coins moving. It does not send them back to victims, though Tether can later destroy blocked coins and reissue them. News sites reported the freeze the same afternoon.

At 15:30 UTC Tether lifted the block on four wallets. They belong to an OTC-style group, dealers who swap crypto for cash away from the big exchanges. The thief had paid the group about $3.0M, but the wallets held other people's money too.

The afternoon of 9 Octoberpublic posts, Tether's actions and the thief's mixing, 11:30 to 17:00 UTC
THE AFTERNOON OF 9 OCTOBER (UTC)12:0013:0014:0015:0016:0017:0012:00 tanuki42 posts 8 drain addresses12:09 Tether starts blacklisting12:24 Specter posts 10 addresses13:32 Ledger's statement14:10 Last blacklisting, 37 in all15:17 Tornado batch 1: 389 ETH15:30 Tether unfreezes 4 OTC-style wallets15:42 Tornado batch 2: 434 ETH15:54 Tornado batch 3: 430 ETH16:37 Another wallet drained
Tether acted about ten minutes after the first public post. The mixing started less than two hours after Ledger's statement.

From 15:17 UTC the thief began sending ETH into Tornado Cash, a mixer that breaks the link between the wallet that pays in and the wallet that later takes out. Three batches of about 400 ETH each went in within 40 minutes, 1,254 ETH in all. We saw no new batch by our data cut-off. If it keeps going at that pace, the ETH could be through the mixer within a day. Our Tornado Cash audit explains how the mixer works and what it hides.

11 · The leadsWhere investigators could ask for records

The chain can't name the thief. It does show places that keep records about their users.

LeadWhat the chain showsHow strong
BybitA withdrawal of 14,512 TRX on 24 September (b284a2…686e) reached the wallet that set up the thief's TRON address the next dayStrong on the money flow
AeroswapPaid 0.031 ETH five minutes after that withdrawal to 0x444f…2d99, which set up the thief's Ethereum addressModerate
BinanceTwo deposit addresses got $794,000 and $557,000 from OTC-style wallets that the thief had paid $3.0MModerate: the OTC wallets also held other people's money
A vault serviceThe thief paid in through 12 deposit addresses at TEcDij…Y4XC, which kept about $4.0MThe service's records name the depositor
A high-volume serviceTZG47z…MrvF took $3.7M in 19 depositsOwner not known
Swap servicesRelay.link, HiFiSwap, NEAR Intents, Mayan, LI.FI and Bridgers each handled part of the moneyOrder records may hold refund addresses and other details
Gate.io60 BNB reached a Gate.io deposit through a trader's wallet that had paid that deposit 55 times since July 2024Weak: the trader looks like a paid counterparty

The strongest lead is how the thief paid for gas. The TRON address that ran the drain was funded from an address that had withdrawn 14,512 TRX from Bybit the day before. An exchange that sends a withdrawal knows the account it came from. The Ethereum side was funded through Aeroswap, an instant swap service, five minutes after that withdrawal. Other leads are weaker. Money from an exchange shows where funds came from. It does not show who owns the wallet that got them. The same caution applies to the OTC-style group and to a trader who received the thief's BNB and moved it to Gate.io. We show how such dead ends happen in our piece on an $812 million wallet nobody flagged.

When we checked, none of the thief's wallets carried a theft label in the label sets we use. An exchange screening deposits against such labels would not have caught this money on the day.

12 · What we know and what to doThe keys leaked. How is still open

Here is what the chain settles. One actor held the keys to every drained wallet. It tested the method for two weeks, then ran it across five chains in under an hour. Here is what it can't settle: whether the keys leaked from the devices, from the reseller, from a printed card, from an app or from somewhere else. That answer will come from Ledger's own look at the devices.

If you bought a Ledger from CryptoBilis, follow Ledger's advice, even if you bought it before July. Don't set up a device you have not used yet. If you already use one, set up a new device with a new recovery phrase and move your coins to it. Never use a device that arrives with words already written down. Similar lessons came out of the Bitget hack and the TradeWiz drain: once someone else holds your keys, the coins can be gone in seconds.

Claim on XWho said itWhat the chain shows
Losses above $86MSpecterClose: the ten public addresses got $85.4M. All in, we count $92.9M
Tether froze USDT linked to the theftsNews reportsConfirmed: $10.0M frozen in 20 wallets
A victim lost 7M USDT three weeks after buyingLookonchainThe wallet was first funded on 15 September and lost 7,001,000 USDT at 05:07:54
A victim lost 80 BTCLookonchain80 BTC arrived on 29 September and was swept in the block at 05:54
The theft wallets are not labelled anywhereSecurity researcher TayTrue of the label sets we checked, on the day
Devices were tampered withCZ and othersThe chain cannot test this

13 · How we did thisMethod

We started from the ten addresses posted by tanuki42 and Specter. We read every payment into and out of them on all five chains from Bitquery's data, and followed the money until it reached a service, a frozen wallet or a wallet that has not moved. We left out money the thief moved between its own wallets, payouts from swap services, and fake tokens sent by scammers who copy addresses. Dollar values use prices from the morning of 9 October. A second, independent check rebuilt every figure from the raw data without seeing our notes. The data stops at 16:45 UTC on 9 October. The thief may have moved since. Our address poisoning study explains why copied addresses fill these wallets with fake transfers, and Bitquery's address labels are the label set we checked first.

Limits on these figures

Balances and totals were read at 16:45 UTC on 9 October. The thief's wallets were still moving money when we stopped, so later figures will differ.

Dollar values use prices from the morning of 9 October: BTC $82,300, ETH $2,490, BNB $742. USDT, USDC and USDD are counted at $1.

We count money that left a victim's wallet. Payouts from swap services into the thief's addresses, money the thief moved between its own wallets, and fake tokens sent by scammers who copy addresses are left out.

A victim wallet is not a victim person. One owner can have several wallets, and some EVM wallets were drained on more than one chain.

On TRON we count a wallet as a victim when it lost at least $10 in USDT. A few more wallets lost smaller amounts or only TRX; their coins are in the dollar total but not in the wallet count.

The first payment into a wallet tells us when it started to be used. It does not tell us when its owner bought a device.

Exchange and service names come from Bitquery's address labels and from how the money behaves. A payment from an exchange shows where money came from. It does not show who owns the wallet that received it.

We could not find the source of a few small payouts into the thief's Ethereum wallets, and we have not followed every payment past the first service it reached.

WhatAddress or transaction
TRON drain address (public)TK6DWN…XT6C
TRON drain address (public)TBkcUM…s9d9
TRON drain address (public)TCGE3x…MNsW
TRON drain address (public)TSDWtu…Ar5a
TRON drain address (not in public lists)TYohhJ…UfGj
TRON drain address (not in public lists)TELKRM…ZznW
TRON drain address (not in public lists)TQoTZG…P9FQ
TRON drain address (not in public lists)TRTVHp…2bzE
TRON drain address (not in public lists)TRMHXE…GpDQ
Thief's TRON control addressTAzdU7…CSYQ
Wallet that funded it from BybitTWGHw7…Bf3E
EVM drain address (public; also used on BNB Chain and Polygon)0x69c8…7841
EVM drain address (public; also used on BNB Chain and Polygon)0x0336…4f7a
EVM drain address (public; also used on BNB Chain and Polygon)0x83ae…a599
Thief's Ethereum control address0x3818…f8f2
ETH holding wallet0x468b…2a4e
ETH holding wallet0xfa4e…b0e2
ETH holding wallet0x064a…7160
ETH holding wallet0xb88d…1856
ETH holding wallet0x131c…fa6a
ETH holding wallet0x40eb…e88c
ETH holding wallet (small)0x9400…40d6
Bitcoin drain address (public)bc1qjq…49dl
Bitcoin drain address (public)bc1qqn…jtm9
Bitcoin address in one public list, likely a separate operationbc1qgq…d26n
Run it yourself

Follow the stolen money in plain English

Every transfer, approval and balance in this story comes from Bitquery's data for the five chains involved. The Bitquery MCP server puts that data behind an AI assistant, so you can ask where a wallet's money went or what labels an address carries, without writing the query yourself. The full histories are also sold as files on the Bitquery Data Store, for TRON, Bitcoin, Ethereum, BNB Chain and Polygon.

Watch the wallets holding 14,810 ETH and 203.8 BTCTrace where any wallet's money came from and wentCheck an address against Bitquery's labelsRun your own SQL over TRON, Bitcoin and EVM transfers
Explore Bitquery MCP →Figures measured on 9 October 2026 across all five chains. Balances read at 16:45 UTC on 9 October.

FAQ

Was Ledger hacked?

Nothing public so far shows a break-in at Ledger itself. Wallets of people who bought Ledger devices from the reseller CryptoBilis were drained by someone who held their keys. Ledger is investigating how those keys leaked and has paused sales through that reseller.

What is CryptoBilis?

CryptoBilis, also spelled CryptoBillis, is a crypto hardware shop that sells Ledger devices in Indonesia, Malaysia and the Philippines. News reports describe it as an official Ledger reseller. On 9 October 2026 Ledger asked it to stop all sales and shipments of Ledger devices while it investigates.

How much was stolen in the Ledger CryptoBilis hack?

We count $92.9M taken from 311 wallets on TRON, Bitcoin, Ethereum, BNB Chain and Polygon. Most of it was USDT on TRON. Early counts of about $86 million covered only the ten public addresses.

Can a Ledger be hacked?

The device is built so the recovery phrase never leaves it. If someone else gets that phrase, they control the wallet without the device. That can happen through a tampered device, a pre-printed recovery card, a fake app or a phishing site. In this case the thief clearly held the keys. How they got them is not yet known.

Is my Ledger safe if I bought it from a reseller?

If you bought from CryptoBilis, follow Ledger's advice: don't set up an unused device, and move your coins to a new device with a new recovery phrase. Many victim wallets were first funded in June 2026, before Ledger's 90-day window, so earlier buyers should take the same step.

Can the stolen crypto be recovered?

About $10 million in USDT is frozen by Tether, which can later reissue frozen coins. The Bitcoin has not moved, and most of the ETH still sits in known wallets. Money that went through Tornado Cash or into USDD is harder to recover.

Is this the same as the 2023 Ledger hack?

No. In December 2023 a fake version of Ledger's Connect Kit code library drained people who used certain crypto websites for a few hours. In 2020 a breach exposed customer emails and home addresses. This case is different: the thief held the recovery keys of hundreds of wallets and emptied them directly.

Legal disclaimer

This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, and nothing in it is a recommendation to buy, sell, or hold any token or asset.

The findings describe transfers, approvals and balances observed on TRON, Bitcoin, Ethereum, BNB Chain and Polygon between 24 September and 9 October 2026. Attributions come from Bitquery's address labels and from on-chain behaviour; they may be incomplete or incorrect and may be revised as more data becomes available.

References to Ledger, CryptoBilis, Tether, Bybit, Binance, Gate.io, Aeroswap or any other named company, service or protocol describe what the record shows about addresses and transactions linked to them. They are not statements about any party's security practices, compliance or conduct, and nothing here asserts that any named party acted unlawfully or negligently. The wallets that received the drained funds are described by their behaviour and attributed to nobody.

Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.

Reported by Gaurav Agarwal for Bitquery Research, with AI tools; every figure was checked against the raw data.