Crypto Scams North Korean Hackers Infect 30,000 Devices, Target 7,000 Crypto Wallets

Ledger investigates crypto wallet theft reports linked to Southeast Asian reseller CryptoBilis, as an onchain investigator estimates losses exceed $86 million.
Ledger is investigating reports of stolen cryptocurrency involving customers who purchased hardware wallets from Southeast Asian reseller CryptoBilis. Meanwhile, Specter, an onchain investigator, estimates that the suspicious addresses received over $86 million on Bitcoin, Ethereum, and TRON networks.
The company has asked CryptoBilis to stop selling and shipping Ledger devices during the investigation. Furthermore, Ledger has alerted its customers who bought the devices from this reseller in the last 90 days not to set them up.
Those who have already activated their devices were urged to transfer their assets to a new Ledger signer, according to Ledger. The company also suggested the generation of a new recovery phrase for the replacement setup.
Related reading: KelpDAO Files Lawsuit Against LayerZero Over $292M Bridge Exploit | Live Bitcoin News
A recovery phrase is a set of words that can be used to regain access to a cryptocurrency wallet. It is therefore important that users never share this phrase with anyone or enter it into untrusted websites.
But Ledger has not specified what is the reason behind the reported thefts. The company also has not verified the total financial losses or the number of affected customers.
Meanwhile, Specter said he was able to follow up on suspicious wallet addresses where money was deposited by hundreds of victims. The investigation included Bitcoin, Ethereum, and TRON, but there is no confirmation of the link between all of the reported cases.
The flagged addresses had almost $87 million in the supplied. This comprised around $42 million in Ethereum, $17.6 million in Bitcoin, and $16.5 million in USDT.
These numbers are reported holdings at suspicious addresses and not a final loss figure, verified independently. As a result, the total dollar loss is still not known as investigators investigate the transactions.
Ledger has also said that there is no evidence of a direct attack on their hardware wallets or underlying infrastructure. However, the investigation needs to determine how the impacted customers lost access to their money.
So far, according to Binance founder Changpeng Zhao, or CZ, the incident “seemed to be isolated. He proposed that the reports could be the result of a supply chain attack by a single reseller.
⚠️ Beware if you use a Ledger hardware wallet, especially if you bought one recently.
Based on information so far, it seems to be localized to a supply chain attack with one vendor. A small number of people probably bought fake (or tampered) Ledgers.
Ledger is one of the most… https://t.co/zW8wkvdZNf
— CZ 🔶 BNB (@cz_binance) October 9, 2026
In this attack, the criminals disrupt the products before they get to the customers. For instance, someone might modify a device or create it with a recovery phrase that they know.
Former Mt. Gox CEO Mark Karpelès also expressed worries about potential interference in the supply chain. Investigators have not yet confirmed, however, if devices were altered, replaced or provided with compromised recovery phrases.
Thus, it is important for customers to not assume that all Ledger devices and resellers are the same. The information available indicates that there may be an issue with a particular seller, but the investigation is continuing.
Participants from the BNB ecosystem and the broader cryptocurrency community would also assist in tracking the stolen funds, CZ added. But tracking transactions does not ensure that investigators will be able to get the assets back.
Ledger is currently warning customers who bought its devices from CryptoBilis in the last 90 days. Users who have been impacted should adhere to official company updates and reach out to Ledger via official channels.
Last but not least, the incident underscores the need to purchase hardware wallets from trusted sources. A recovery phrase provided by a seller or anyone else should not be used by customers.
Explore more