Ledger Suspends CryptoBilis Sales Amid Investigation Into Estimated $90 Million Loss
The suspected incident would surpass losses from a fake Ledger Live app and the 2023 Connect Kit attack if confirmed.

Ledger is investigating a suspected supply-chain incident tied to Southeast Asian authorized distributor CryptoBilis after an Oct. 9 event that may have caused nearly $90 million in losses, which would make it the largest loss among the company’s major security incidents described here.
Ledger has suspended sales and shipments through CryptoBilis while it investigates. Users who bought devices through the channel during the past 90 days were urged to exercise caution and move their assets. The cause has not been finalized, but the incident is suspected to involve device tampering or another supply-chain risk.
The estimated loss exceeds the company’s previous major security incidents. In April, a fake Ledger Live app remained available for about a week and persuaded more than 50 victims to enter their recovery phrases, causing roughly $9.5 million in losses across multiple blockchains.
A December 2023 attack on Ledger’s Connect Kit software affected decentralized applications that used the library and caused an estimated $480,000 to $600,000 in losses. Ledger’s 2020 customer-data breach exposed more than 1 million email addresses and hundreds of thousands of detailed customer records, but did not compromise hardware or private keys.