LuckyCrypto777 (OP)
Member

Online
Activity: 80
Merit: 171
-
|
 |
October 09, 2026, 03:51:57 PM Last edit: October 09, 2026, 04:15:52 PM by LuckyCrypto777 |
|
Ledger should never be an option, their customers have suffered a lot of losses over the years.
As my personal irony, just yesterday I shared in topic of the hardware wallets that I have a Ledger A few years ago, my friend gave me this Ledger. ... 
|
|
|
|
|
promise444c5
Legendary

Activity: 1162
Merit: 1232
All things are numbers
|
I know some folks would still ignore this as if CryptoBillis CryptoBilis isn’t an authorized reseller. Infact, Ledger force people to buy from their local resellers like CryptoBillis CryptoBilis if ledger can’t ship directly to their location, which is more like saying “we have a store closer to you , go grab your Ledger wallet there”. Yet , when addressing the issue they never mentioned “our authorized reseller CryptoBillis” all they mentioned was “a reseller named CryptoBillis”  .
|
|
|
|
AHOYBRAUSE
Legendary

Activity: 1470
Merit: 2110
よろしく
|
 |
October 09, 2026, 05:02:30 PM |
|
Damn, I saw that on reddit as well today and just thought it was an isolated case. Some replies even accused the person of making this story up, guess it wasn't so wide spread yet at that time. Has it been announced which reseller it was? I mean I scrolled through this thread and maybe I have overlooked it since I couldn't find this information. Haven't used my ledger in ages but reading stuff like this really makes up my mind I won't use it again anytime soon. The amount lost really is huge, quite scary when you can't even have you funds stored safely in this kind of "secure" wallet.
|
| | Sportsbet.io | │ |
| │ |
| │ | ████████████████████████ ██ ██████
██ ████████████████
MORE THAN A BET!
██ ████████████████
██ █████████████████████ ██ ████████ |
|
|
|
LuckyCrypto777 (OP)
Member

Online
Activity: 80
Merit: 171
-
|
 |
October 09, 2026, 05:05:51 PM Last edit: October 09, 2026, 05:26:19 PM by LuckyCrypto777 |
|
I know some folks would still ignore this as if CryptoBillis isn’t an authorized reseller. Infact, Ledger force people to buy from their local resellers like CryptoBillis if ledger can’t ship directly to their location, which is more like saying “we have a store closer to you , go grab your Ledger wallet there”. Yet , when addressing the issue they never mentioned “our authorized reseller CryptoBillis” all they mentioned was “a reseller named CryptoBillis”  . The theory that their owner changed on August 3 is currently being investigated, but this information has not yet been fully confirmed. CryptoBilis changed ownership, with an individual identified as Jiaming, whose registered address is in China’s Heilongjiang province, listed as holding 100% of the company’s shares https://x.com/BitcoinNewsCom/status/2108600302177763516 Damn, I saw that on reddit as well today and just thought it was an isolated case. Some replies even accused the person of making this story up, guess it wasn't so wide spread yet at that time. Has it been announced which reseller it was? I mean I scrolled through this thread and maybe I have overlooked it since I couldn't find this information. Haven't used my ledger in ages but reading stuff like this really makes up my mind I won't use it again anytime soon. The amount lost really is huge, quite scary when you can't even have you funds stored safely in this kind of "secure" wallet.
CryptoBilis https://www.cryptobilis.com/
|
|
|
|
|
Ambatman
Legendary

Activity: 1148
Merit: 1469
Don't tell anyone
|
 |
October 09, 2026, 05:32:08 PM Merited by vapourminer (1) |
|
They were among the first to come out and state they were safe after the coldcard vulnerabilities I guess vulnerabilities can come in different stage. The more stages we rely on others in our Bitcoin the higher the risk of vulnerabilities. Almost similar to what happened here done by a user in the forum then. My Cold Keys Just Got Swiped! All Cold Kuntz!!
|
|
|
|
julerz12
Legendary

Activity: 3206
Merit: 1736
A swap that needs a hand? zeto.cash@proton.me
|
And...that reseller also sells lots of other hardware wallets.  SecuX, Trezor, and SafePal. If they really did tamper with the devices they've been selling, more hardware wallets are probably gonna get drained in the next couple of hours.    It's important to mention that the seed phrase of the affected wallets has most likely been compromised, and anyone using a Ledger wallet should create a new seed phrase on another device, and move their funds to those fresh addresses. Please place this warning in the OP.
Regardless of the source of the hack, weather it was caused by tampering by the reseller or a resulting from a malicious firmware update, it's safe to assume the seed phrase is compromised.
I bought my Ledger nano years ago from that same authorized reseller. From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies ) If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is.[EDIT] Vague memory..I think those papers were blank. Yeah, just something to write on. I just found my copy of my old seed phrase, and it's written by me. lol 
|
|
|
|
promise444c5
Legendary

Activity: 1162
Merit: 1232
All things are numbers
|
 |
October 09, 2026, 05:55:17 PM Last edit: October 09, 2026, 06:15:37 PM by promise444c5 |
|
I guess CryptoBil lis ws a typo from Ledger then. I bought my Ledger nano years ago from that same authorized reseller.  From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies  ) If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is. Is that how it supposed to be ? I mean does every ledger wallet comes with a pre-generated seed phrase copy? Or it’s just CryptoBillis thing? Either ways, both doesn’t make any sense to me. There’s no point in using “if” the seed phrase is compromised, someone put it there either it was Ledger or CryptoBillis. Adding passphrase can only work if it’s a strong one.. The only safe option is to generate another one but that doesn’t eliminate the question why it comes with a copy of seedphrase. [Edit] Cleared.. Sorry, my memory is getting vague these days. I just found that copy of my old seed phrase, and it was written by me, so that paper came in blank- just something to write on.
|
|
|
|
libert19
Legendary

Activity: 3374
Merit: 1204
★Bitvest.io★ Play Plinko or Invest!
|
 |
October 09, 2026, 05:56:06 PM |
|
It's important to mention that the seed phrase of the affected wallets has most likely been compromised, and anyone using a Ledger wallet should create a new seed phrase on another device, and move their funds to those fresh addresses. Please place this warning in the OP.
Regardless of the source of the hack, weather it was caused by tampering by the reseller or a resulting from a malicious firmware update, it's safe to assume the seed phrase is compromised.
I bought my Ledger nano years ago from that same authorized reseller.  From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies  ) O_o I would instantly doubt the seller if I am given my wallet's seed phrase. If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is.
If? That seed phrase was already compromised and using that 'ready-made wallet' was akin to throwing the funds in the drain. After hearing this, now I feel pretty much confirmed that this drain has to do with reseller. I bought my Ledger nano years ago from that same authorized reseller.  From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies  ) If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is. Is that how it supposed to be ? I mean does every ledger wallet comes with a pre-generated seed phrase copy? Or it’s just CryptoBillis thing? Either ways, both doesn’t make any sense to me. You receive a blank paper to write your seed phrase on it, not already written pre-generated seed. Edit: ^ Irrelevant after the edit.
|
|
|
|
logfiles
Copper Member
Legendary

Activity: 2856
Merit: 2424
|
 |
October 09, 2026, 05:58:24 PM |
|
Man crypto is so crazy lately. Your offline for day and then you try to log into the forum and boom! Another hack, million's lost  For years hardware wallet were thought to be one of the safest out there but I guess that narrative already changed. Also people have always resounded the warning of never trying to buy hardware wallets from third parties/resellers. This will be an expensive lesson.
|
| | Sportsbet.io | │ |
| │ |
| │ | ████████████████████████ ██ ██████
██ ████████████████
MORE THAN A BET!
██ ████████████████
██ █████████████████████ ██ ████████ |
|
|
|
julerz12
Legendary

Activity: 3206
Merit: 1736
A swap that needs a hand? zeto.cash@proton.me
|
 |
October 09, 2026, 06:02:06 PM |
|
Is that how it supposed to be ? I mean does every ledger wallet comes with a pre-generated seed phrase copy? Or it’s just CryptoBillis thing? Either ways, both doesn’t make any sense to me.
O_o I would instantly doubt the seller if I am given my wallet's seed phrase.
Sorry, my memory is getting vague these days. I just found that copy of my old seed phrase, and it was written by me, so that paper came in blank- just something to write on.
|
|
|
|
OmegaStarScream
Staff
Legendary

Activity: 4354
Merit: 7754
|
 |
October 09, 2026, 06:02:22 PM Last edit: October 09, 2026, 06:28:32 PM by OmegaStarScream Merited by vapourminer (1), julerz12 (1) |
|
-snip-
Someone who appears to be the Founder of CryptoBilis just made an official statement on Linkedin: OFFICIAL STATEMENT REGARDING CRYPTOBILIS In light of recent public discussions and media reports concerning CryptoBilis and Ledger, Vimalatheethan and I (Arravind Prabu) wish to provide full clarity regarding our position and involvement. 1. Operational Handover & Conclusion of Role: Earlier this year, CryptoBilis was acquired by new ownership. As part of this transition, Vimal and I officially stepped down and completed a full handover of all operational, managerial, and administrative responsibilities in March 2026. 2. System & Database Access: Since the completion of the handover, we have held zero access, credentials, visibility, or administrative control over CryptoBilis backend systems, customer databases, order histories, or corporate communication channels. 3. Post-Acquisition Support: While we assisted the incoming management team in an advisory and coordination capacity during key industry events earlier this year (including Bitcoin Pizza Day, MyBW, and PBW) to ensure a smooth transition, we have had no business or operational visibility into the company's day-to-day management or IT infrastructure. 4. Confidentiality & Public Announcements: Under the formal acquisition agreements, all parties were contractually bound to hold off on issuing a joint public announcement until mid-October 2026. All suppliers were previously notified of the corporate acquisition and new management structure. 5. Commitment to Security: Having built CryptoBilis over many years with absolute integrity and dedication to the community, we deeply value user security and our long-standing relationships in the Web3 ecosystem. While we have no active operational standing, we remain open to providing any historical context to Ledger’s team should it assist their review. For all active operational matters, technical inquiries, or official statements regarding CryptoBilis, please contact the current lead Person in Charge: Nicholas Chang Email: nicholas@cryptobilis.comThank you to our partners, clients, and community members who have reached out to support us during this time. Arravind Prabu & Vimalatheethan Former Co-Founders, CryptoBilis I guess things are starting to add up. Although, and as sophisticated the attack is, I'm not sure what made the person buying the company think this would go unnoticed... could North Korea be behind this? I'm also curious to know whether at least Ledger was notified of CryptoBilis changing hands
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | ..BTC......XMR... ..USDT.....LTC... ....Fees 0.8%..... |
|
|
|
stompix
Legendary

Activity: 3766
Merit: 7443
|
 |
October 09, 2026, 06:02:41 PM Merited by vapourminer (1) |
|
I bought my Ledger nano years ago from that same authorized reseller.  From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies  ) If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is. If you still have it you could test it on a wallet by sending a few satoshis and see if they get swiped by some bot. If they do then there is no longer anything mysterious about this drain. LE: nevermind, saw your edit. And...that reseller also sells lots of other hardware wallets.  SecuX, Trezor, and SafePal.  So, probably toss coin time now: - do they drain those too and try to flee as it's obvious they are to blame? - they don't as they want cast a shadow of doubt on this take, but they regret not doing as they anyhow land in prison with less loot? So, nothing happening doesn't make them innocent, but one coin moving does.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | ..BTC......XMR... ..USDT.....LTC... ....Fees 0.8%..... |
|
|
|
|
Meuserna
|
 |
October 09, 2026, 06:06:42 PM Merited by vapourminer (1) |
|
I guess CryptoBil lis ws a typo from Ledger then. I bought my Ledger nano years ago from that same authorized reseller.  From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies  ) If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is. Is that how it supposed to be ? I mean does every ledger wallet comes with a pre-generated seed phrase copy? Or it’s just CryptoBillis thing? Either ways, both doesn’t make any sense to me. No, no... definitely no. Ledger's don't come with a pre-generated seed. They come with blank cards to write the random seed in. And I always tell people to wipe out the wallet after it gives you a seed and force it to give you another one, just to prove it's giving you random seeds. That being said... I stopped letting hardware wallets generate seeds for me a few years ago, because I realized I couldn't prove the seed was truly random. ColdCard seeds weren't truly random, and people got burned. And how can anybody prove the seeds aren't being generated by BIP85, all from a master seed? I assume those attacks will happen at some point. A year ago, I thought I was going overboard by manually generating my own seeds to prove they were truly random (I printed the entire BIP39 wordlist and chopped it up so each little slip of paper had one word. Then I dumped the words in a popcorn bowl & scrambled 'em up). Now, I don't think my method was overboard at all. The real lesson for this Ledger attack is, don't buy hardware wallets from a third party, ever. That's a painful truth. I've been recommending people buy hardware wallets at physical stores instead of by mail. Now, I don't think I can recommend that at all.
|
|
|
|
greysonz
Member


Activity: 98
Merit: 108
GZ
|
He must be right, because social media users are posting screenshots like these. Devices are different.  Simcard 2x2 mm is found inside of Ledger device. This is starting to look like a spy movie.  This thing probably listened to what phrase the user would make and sent it over the Internet. .. could North Korea be behind this?
The chances are not zero.
|
"I know that I know nothing" - Socrates
|
|
|
stompix
Legendary

Activity: 3766
Merit: 7443
|
 |
October 09, 2026, 06:17:05 PM Merited by vapourminer (1) |
|
Someone who appears to be the Founder of CryptoBilis just made an official statement on Linkedin: OFFICIAL STATEMENT REGARDING CRYPTOBILIS
In light of recent public discussions and media reports concerning CryptoBilis and Ledger, Vimalatheethan and I (Arravind Prabu) wish to provide full clarity regarding our position and involvement.
1. Operational Handover & Conclusion of Role: Earlier this year, CryptoBilis was acquired by new ownership. As part of this transition, Vimal and I officially stepped down and completed a full handover of all operational, managerial, and administrative responsibilities in March 2026.
I guess things are starting to add up. Although, and as sophisticated the attack is, I'm not sure what made the person buying the company think this would go unnoticed... Yeah...not really... One of the drain wallets was funded in May 1st: https://mempool.space/address/bc1qt2e2a5l66x8s5ahe7339mqvukmzhmrxe27603zThis wallet was funded in January: https://mempool.space/address/bc1qpxq4p55xg7exdnzrjg8x652gnceyjmh45sg6ceAnd this is just me browsing around Also, how about the other scenario.. They loaded their inventory at the moment of the sale with malware and made sure they would reach future clients on orders placed after they sold and had nothing to do with the company.. Doesn't that also make a lot of sense? Like the perfect exit point?
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | ..BTC......XMR... ..USDT.....LTC... ....Fees 0.8%..... |
|
|
|
libert19
Legendary

Activity: 3374
Merit: 1204
★Bitvest.io★ Play Plinko or Invest!
|
 |
October 09, 2026, 06:25:04 PM |
|
Also people have always resounded the warning of never trying to buy hardware wallets from third parties/resellers. This will be an expensive lesson. The real lesson for this Ledger attack is, don't buy hardware wallets from a third party, ever. That's a painful truth. I've been recommending people buy hardware wallets at physical stores instead of by mail. Now, I don't think I can recommend that at all.
I have never trusted random third party resellers but this incident has taught me to not even trust official resellers. Guess, brands should be shipping globally, so less supply-chain attacks possibility. By the way, Ledger has been getting burned and burned been a while, has it's reputation already burnt to ashes or any remaining?
|
|
|
|
|
oll
|
The attack's victims extend beyond the 90-day window mentioned by Ledger. This directly points to devices purchased previously or existing seed phrases restored on newer devices. X of AMLBot: If you bought from this reseller this year, or entered an existing seed into one of its devices, don’t rely on the 90-day cutoff. Move your funds to a new seed generated on a device bought directly from the manufacturer https://x.com/AMLBotHQ/status/2108625722210435143
|
|
|
|
|
YellowSwap
|
 |
October 09, 2026, 06:54:57 PM Merited by vapourminer (1) |
|
The Cryptobilis team needs to be arrested asap,  They must have worked physically on the hardware wallets and sold it to the public, this is a big crime that needs action immediately, they need to crucified those guys. I feel for this fella, who just not too long bought 10BTC and lost it because he got Ledger from same Cryptobilis. https://x.com/lookonchain/status/2108585005635301427
|
|
|
|
|
julerz12
Legendary

Activity: 3206
Merit: 1736
A swap that needs a hand? zeto.cash@proton.me
|
 |
October 09, 2026, 06:58:53 PM Merited by vapourminer (1) |
|
The stolen funds have begun to move; some went to a Binance deposit address (TMxnc434PYthRnaBxEA494xrk7iyufrAZP). Unfortunately, funds are still coming in, especially in BTC - the latest inflow was 6 minutes ago. https://arkm.com/explorer/entity/cryptobillis-ledger-drainer (current balance: $72m)
|
|
|
|
LuckyCrypto777 (OP)
Member

Online
Activity: 80
Merit: 171
-
|
I'm also curious to know whether at least Ledger was notified of CryptoBilis changing hands
There is no exact answer yet, but: The ownership change turned out to be true. An official statement from CryptoBilis co-founders Arravinda Prabu and Vimalathithan regarding their current status and relationship with Ledger: In March, the full ownership was transferred to the new owner, the deal included a non-disclosure agreement until October. The new CEO: Nicholas Chang, available for communication at nicholas@cryptobilis.com
|
|
|
|
|
|