Bitcoin Forum
October 11, 2026, 11:37:35 PM *
News: Serious possible issue involving Ledger hardware wallets and CryptoBilis
 
   Home   Help Search Login Register More  
Pages: « 1 [2] 3 4 5 6 7 »  All
  Print  
Author Topic: Reports about wallet-draining by Ledger users. Total losses $86M+  (Read 1823 times)
LuckyCrypto777 (OP)
Member
**
Offline

Activity: 80
Merit: 181

-


View Profile
October 09, 2026, 03:51:57 PM
Last edit: October 09, 2026, 04:15:52 PM by LuckyCrypto777
 #21

Ledger should never be an option, their customers have suffered a lot of losses over the years.

As my personal irony, just yesterday I shared in topic of  the hardware wallets that I have a Ledger

A few years ago, my friend gave me this Ledger. ...

promise444c5
Legendary
*
Offline

Activity: 1162
Merit: 1232


All things are numbers


View Profile WWW
October 09, 2026, 04:40:40 PM
Last edit: October 09, 2026, 06:10:20 PM by promise444c5
Merited by theymos (5), pooya87 (5), ABCbits (3), Foxpup (2), vapourminer (1)
 #22

I know some folks would still ignore this as if CryptoBillis CryptoBilis isn’t an authorized reseller.

Infact, Ledger force people to buy from their local resellers like CryptoBillis CryptoBilis if ledger can’t ship directly to their location, which is more like saying “we have a store closer to you , go grab your Ledger wallet there”. Yet , when addressing the issue they never mentioned “our authorized reseller CryptoBillis” all they mentioned was “a reseller named CryptoBillis”  Tongue.


AHOYBRAUSE
Legendary
*
Offline

Activity: 1470
Merit: 2110


よろしく


View Profile WWW
October 09, 2026, 05:02:30 PM
 #23


Damn, I saw that on reddit as well today and just thought it was an isolated case. Some replies even accused the person of making this story up, guess it wasn't so wide spread yet at that time.
Has it been announced which reseller it was? I mean I scrolled through this thread and maybe I have overlooked it since I couldn't find this information. Haven't used my ledger in ages but reading stuff like this really makes up my mind I won't use it again anytime soon. The amount lost really is huge, quite scary when you can't even have you funds stored safely in this kind of "secure" wallet.


LuckyCrypto777 (OP)
Member
**
Offline

Activity: 80
Merit: 181

-


View Profile
October 09, 2026, 05:05:51 PM
Last edit: October 09, 2026, 05:26:19 PM by LuckyCrypto777
Merited by Pmalek (3), vapourminer (1), ABCbits (1), DireWolfM14 (1), AHOYBRAUSE (1)
 #24

I know some folks would still ignore this as if CryptoBillis isn’t an authorized reseller.

Infact, Ledger force people to buy from their local resellers like CryptoBillis if ledger can’t ship directly to their location, which is more like saying “we have a store closer to you , go grab your Ledger wallet there”. Yet , when addressing the issue they never mentioned “our authorized reseller CryptoBillis” all they mentioned was “a reseller named CryptoBillis”  Tongue.



The theory that their owner changed on August 3 is currently being investigated, but this information has not yet been fully confirmed.

Quote
CryptoBilis changed ownership, with an individual identified as Jiaming, whose registered address is in China’s Heilongjiang province, listed as holding 100% of the company’s shares


https://x.com/BitcoinNewsCom/status/2108600302177763516


Damn, I saw that on reddit as well today and just thought it was an isolated case. Some replies even accused the person of making this story up, guess it wasn't so wide spread yet at that time.
Has it been announced which reseller it was? I mean I scrolled through this thread and maybe I have overlooked it since I couldn't find this information. Haven't used my ledger in ages but reading stuff like this really makes up my mind I won't use it again anytime soon. The amount lost really is huge, quite scary when you can't even have you funds stored safely in this kind of "secure" wallet.


CryptoBilis

https://www.cryptobilis.com/
Ambatman
Legendary
*
Offline

Activity: 1148
Merit: 1469


Don't tell anyone


View Profile WWW
October 09, 2026, 05:32:08 PM
Merited by vapourminer (1)
 #25

They were among the first to come out and state they were safe after the coldcard vulnerabilities
I guess vulnerabilities can come in different stage.
The more stages we rely on others in our Bitcoin the higher the risk of vulnerabilities.
Almost similar to what happened here done by a user in the forum then.

My Cold Keys Just Got Swiped! All Cold Kuntz!!

julerz12
Legendary
*
Offline

Activity: 3206
Merit: 1743


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
October 09, 2026, 05:34:15 PM
Last edit: October 09, 2026, 06:30:03 PM by julerz12
Merited by Pmalek (3), ABCbits (2), vapourminer (1), nc50lc (1)
 #26

And...that reseller also sells lots of other hardware wallets.  Roll Eyes SecuX, Trezor, and SafePal.
If they really did tamper with the devices they've been selling, more hardware wallets are probably gonna get drained in the next couple of hours.


It's important to mention that the seed phrase of the affected wallets has most likely been compromised, and anyone using a Ledger wallet should create a new seed phrase on another device, and move their funds to those fresh addresses.  Please place this warning in the OP.

Regardless of the source of the hack, weather it was caused by tampering by the reseller or a resulting from a malicious firmware update, it's safe to assume the seed phrase is compromised.
I bought my Ledger nano years ago from that same authorized reseller. Roll Eyes From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies Cheesy )
If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is.


[EDIT] Vague memory..I think those papers were blank. Yeah, just something to write on. I just found my copy of my old seed phrase, and it's written by me. lol Cheesy

promise444c5
Legendary
*
Offline

Activity: 1162
Merit: 1232


All things are numbers


View Profile WWW
October 09, 2026, 05:55:17 PM
Last edit: October 09, 2026, 06:15:37 PM by promise444c5
 #27

I guess CryptoBillis ws a typo from Ledger then.

I bought my Ledger nano years ago from that same authorized reseller. Roll Eyes From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies Cheesy )
If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is.
Is that how it supposed to be ?  I mean does every ledger wallet comes with a pre-generated seed phrase copy? Or it’s just CryptoBillis thing? Either ways, both doesn’t make any sense to me.

There’s no point in using “if” the seed phrase is compromised, someone put it there either it was Ledger or CryptoBillis.

Adding passphrase can only work if it’s a strong one.. The only safe option is to generate another one but that doesn’t eliminate the question why it comes with a copy of seedphrase.

[Edit]
Cleared..
Sorry, my memory is getting vague these days. I just found that copy of my old seed phrase, and it was written by me, so that paper came in blank- just something to write on.

libert19
Legendary
*
Offline

Activity: 3374
Merit: 1204


★Bitvest.io★ Play Plinko or Invest!


View Profile WWW
October 09, 2026, 05:56:06 PM
 #28

It's important to mention that the seed phrase of the affected wallets has most likely been compromised, and anyone using a Ledger wallet should create a new seed phrase on another device, and move their funds to those fresh addresses.  Please place this warning in the OP.

Regardless of the source of the hack, weather it was caused by tampering by the reseller or a resulting from a malicious firmware update, it's safe to assume the seed phrase is compromised.
I bought my Ledger nano years ago from that same authorized reseller. Roll Eyes From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies Cheesy )

O_o I would instantly doubt the seller if I am given my wallet's seed phrase.

Quote
If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is.

If? That seed phrase was already compromised and using that 'ready-made wallet' was akin to throwing the funds in the drain.

After hearing this, now I feel pretty much confirmed that this drain has to do with reseller.

I bought my Ledger nano years ago from that same authorized reseller. Roll Eyes From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies Cheesy )
If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is.
Is that how it supposed to be ?  I mean does every ledger wallet comes with a pre-generated seed phrase copy? Or it’s just CryptoBillis thing? Either ways, both doesn’t make any sense to me.

You receive a blank paper to write your seed phrase on it, not already written pre-generated seed.

Edit: ^ Irrelevant after the edit.

║
★
║
.
.BIG WINNER!.
[15.00000000 BTC]
║
★
║
▄████████████████████▄
██████████████████████
██████████▀▀██████████
█████████░░░░█████████
██████████▄▄██████████
███████▀▀████▀▀███████
██████░░░░██░░░░██████
███████▄▄████▄▄███████
████▀▀████▀▀████▀▀████
███░░░░██░░░░██░░░░███
████▄▄████▄▄████▄▄████
██████████████████████

▀████████████████████▀
▄████████████████████▄
██████████████████████
█████▀▀█▀▀▀▀▀▀██▀▀████
█████░░░░░░░░░░░░░████
█████░░░░░░░░░░░░▄████
█████░░▄███▄░░░░██████
█████▄▄███▀░░░░▄██████
█████████░░░░░░███████
████████░░░░░░░███████
███████░░░░░░░░███████
███████▄▄▄▄▄▄▄▄███████

██████████████████████
▀████████████████████▀
▄████████████████████▄
███████████████▀▀▀▀▀▀▀
███████████▀▀▄▄█░░░░░█
█████████▀░░█████░░░░█
███████▀░░░░░████▀░░░▀
██████░░░░░░░░▀▄▄█████
█████░▄░░░░░▄██████▀▀█
████░████▄░███████░░░░
███░█████░█████████░░█
███░░░▀█░██████████░░█
███░░░░░░████▀▀██▀░░░░
███░░░░░░███░░░░░░░░░░

▀██░▄▄▄▄░████▄▄██▄░░░░
▄████████████▀▀▀▀▀▀▀██▄
█████████████░█▀▀▀█░███
██████████▀▀░█▀░░░▀█░▀▀
███████▀░▄▄█░█░░░░░█░█▄
████▀░▄▄████░▀█░░░█▀░██
███░▄████▀▀░▄░▀█░█▀░▄░▀
█▀░███▀▀▀░░███░▀█▀░███░
▀░███▀░░░░░████▄░▄████░
░███▀░░░░░░░█████████░░
░███░░░░░░░░░███████░░░
███▀░██░░░░░░▀░▄▄▄░▀░░░
███░██████▄▄░▄█████▄░▄▄

▀██░████████░███████░█▀
▄████████████████████▄
████████▀▀░░░▀▀███████
███▀▀░░░░░▄▄▄░░░░▀▀▀██
██░▀▀▄▄░░░▀▀▀░░░▄▄▀▀██
██░▄▄░░▀▀▄▄░▄▄▀▀░░░░██
██░▀▀░░░░░░█░░░░░██░██
██░░░▄▄░░░░█░██░░░░░██
██░░░▀▀░░░░█░░░░░░░░██
██░░░░░▄▄░░█░░░░░██░██
██▄░░░░▀▀░░█░██░░░░░██
█████▄▄░░░░█░░░░▄▄████
█████████▄▄█▄▄████████

▀████████████████████▀
║
★
║
║
★
║
✔ Rainbot
✔ Daily Quests
✔ Faucet
logfiles
Copper Member
Legendary
*
Offline

Activity: 2856
Merit: 2425



View Profile WWW
October 09, 2026, 05:58:24 PM
 #29

Man crypto is so crazy lately. Your offline for day and then you try to log into the forum and boom! Another hack, million's lost  Cry

For years hardware wallet were thought to be one of the safest out there but I guess that narrative already changed. Also  people have always resounded the warning of never trying to buy hardware wallets from third parties/resellers. This will be an expensive lesson.

julerz12
Legendary
*
Offline

Activity: 3206
Merit: 1743


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
October 09, 2026, 06:02:06 PM
 #30

Is that how it supposed to be ?  I mean does every ledger wallet comes with a pre-generated seed phrase copy? Or it’s just CryptoBillis thing? Either ways, both doesn’t make any sense to me.

O_o I would instantly doubt the seller if I am given my wallet's seed phrase.
Sorry, my memory is getting vague these days. I just found that copy of my old seed phrase, and it was written by me, so that paper came in blank- just something to write on.

OmegaStarScream
Staff
Legendary
*
Offline

Activity: 4354
Merit: 7754



View Profile
October 09, 2026, 06:02:22 PM
Last edit: October 09, 2026, 06:28:32 PM by OmegaStarScream
Merited by vapourminer (1), julerz12 (1)
 #31

-snip-

Someone who appears to be the Founder of CryptoBilis just made an official statement on Linkedin:

OFFICIAL STATEMENT REGARDING CRYPTOBILIS

In light of recent public discussions and media reports concerning CryptoBilis and Ledger, Vimalatheethan and I (Arravind Prabu) wish to provide full clarity regarding our position and involvement.

1. Operational Handover & Conclusion of Role:
Earlier this year, CryptoBilis was acquired by new ownership. As part of this transition, Vimal and I officially stepped down and completed a full handover of all operational, managerial, and administrative responsibilities in March 2026.

2. System & Database Access:
Since the completion of the handover, we have held zero access, credentials, visibility, or administrative control over CryptoBilis backend systems, customer databases, order histories, or corporate communication channels.

3. Post-Acquisition Support:
While we assisted the incoming management team in an advisory and coordination capacity during key industry events earlier this year (including Bitcoin Pizza Day, MyBW, and PBW) to ensure a smooth transition, we have had no business or operational visibility into the company's day-to-day management or IT infrastructure.

4. Confidentiality & Public Announcements:
Under the formal acquisition agreements, all parties were contractually bound to hold off on issuing a joint public announcement until mid-October 2026. All suppliers were previously notified of the corporate acquisition and new management structure.

5. Commitment to Security:
Having built CryptoBilis over many years with absolute integrity and dedication to the community, we deeply value user security and our long-standing relationships in the Web3 ecosystem. While we have no active operational standing, we remain open to providing any historical context to Ledger’s team should it assist their review.

For all active operational matters, technical inquiries, or official statements regarding CryptoBilis, please contact the current lead Person in Charge:

Nicholas Chang
Email: nicholas@cryptobilis.com

Thank you to our partners, clients, and community members who have reached out to support us during this time.

Arravind Prabu & Vimalatheethan
Former Co-Founders, CryptoBilis

I guess things are starting to add up. Although, and as sophisticated the attack is, I'm not sure what made the person buying the company think this would go unnoticed... could North Korea be behind this?

I'm also curious to know whether at least Ledger was notified of CryptoBilis changing hands

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
stompix
Legendary
*
Offline

Activity: 3766
Merit: 7445



View Profile WWW
October 09, 2026, 06:02:41 PM
Merited by vapourminer (1)
 #32

I bought my Ledger nano years ago from that same authorized reseller. Roll Eyes From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies Cheesy )
If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is.

If you still have it you could test it on a wallet by sending a few satoshis and see if they get swiped by some bot.
If they do then there is no longer anything mysterious about this drain.

LE: nevermind, saw your edit.

And...that reseller also sells lots of other hardware wallets.  Roll Eyes SecuX, Trezor, and SafePal.



So, probably toss coin time now:
- do they drain those too and try to flee as it's obvious they are to blame?
- they don't as they want cast a shadow of doubt on this take, but they regret not doing as they anyhow land in prison with less loot?

So, nothing happening doesn't make them innocent, but one coin moving does.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Meuserna
Sr. Member
****
Offline

Activity: 402
Merit: 750


View Profile WWW
October 09, 2026, 06:06:42 PM
Merited by vapourminer (1)
 #33

I guess CryptoBillis ws a typo from Ledger then.

I bought my Ledger nano years ago from that same authorized reseller. Roll Eyes From what I remember, the Ledger device I bought came with a 24-word seed phrase on a piece of paper (they were generous enough to send two copies Cheesy )
If that seed phrase is already compromised, is it possible those users who got their wallets drained never added a passphrase to their devices or created a new set of seed phrases after they bought them? Probably used it as is.
Is that how it supposed to be ?  I mean does every ledger wallet comes with a pre-generated seed phrase copy? Or it’s just CryptoBillis thing? Either ways, both doesn’t make any sense to me.

No, no... definitely no. Ledger's don't come with a pre-generated seed. They come with blank cards to write the random seed in. And I always tell people to wipe out the wallet after it gives you a seed and force it to give you another one, just to prove it's giving you random seeds.

That being said... I stopped letting hardware wallets generate seeds for me a few years ago, because I realized I couldn't prove the seed was truly random. ColdCard seeds weren't truly random, and people got burned. And how can anybody prove the seeds aren't being generated by BIP85, all from a master seed? I assume those attacks will happen at some point.

A year ago, I thought I was going overboard by manually generating my own seeds to prove they were truly random (I printed the entire BIP39 wordlist and chopped it up so each little slip of paper had one word. Then I dumped the words in a popcorn bowl & scrambled 'em up). Now, I don't think my method was overboard at all.

The real lesson for this Ledger attack is, don't buy hardware wallets from a third party, ever. That's a painful truth. I've been recommending people buy hardware wallets at physical stores instead of by mail. Now, I don't think I can recommend that at all.

greysonz
Member
**
Offline

Activity: 98
Merit: 108

GZ


View Profile WWW
October 09, 2026, 06:14:33 PM
Merited by theymos (5), LoyceV (4), Pmalek (3), vapourminer (1)
 #34

Quote

He must be right, because social media users are posting screenshots like these. Devices are different.



Simcard 2x2 mm is found inside of Ledger device. This is starting to look like a spy movie.



This thing probably listened to what phrase the user would make and sent it over the Internet.

.. could North Korea be behind this?

The chances are not zero.

"I know that I know nothing" -  Socrates
stompix
Legendary
*
Offline

Activity: 3766
Merit: 7445



View Profile WWW
October 09, 2026, 06:17:05 PM
Merited by vapourminer (1)
 #35

Someone who appears to be the Founder of CryptoBilis just made an official statement on Linkedin:

OFFICIAL STATEMENT REGARDING CRYPTOBILIS

In light of recent public discussions and media reports concerning CryptoBilis and Ledger, Vimalatheethan and I (Arravind Prabu) wish to provide full clarity regarding our position and involvement.

1. Operational Handover & Conclusion of Role:
Earlier this year, CryptoBilis was acquired by new ownership. As part of this transition, Vimal and I officially stepped down and completed a full handover of all operational, managerial, and administrative responsibilities in March 2026.
I guess things are starting to add up. Although, and as sophisticated the attack is, I'm not sure what made the person buying the company think this would go unnoticed...

Yeah...not really...

One of the drain wallets was funded in May 1st:
https://mempool.space/address/bc1qt2e2a5l66x8s5ahe7339mqvukmzhmrxe27603z
This wallet was funded in January:
https://mempool.space/address/bc1qpxq4p55xg7exdnzrjg8x652gnceyjmh45sg6ce
And this is just me browsing around

Also, how about the other scenario..
They loaded their inventory at the moment of the sale with malware and made sure they would reach future clients on orders placed after they sold and had nothing to do with the company..
Doesn't that also make a lot of sense? Like the perfect exit point?

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
libert19
Legendary
*
Offline

Activity: 3374
Merit: 1204


★Bitvest.io★ Play Plinko or Invest!


View Profile WWW
October 09, 2026, 06:25:04 PM
 #36

Also  people have always resounded the warning of never trying to buy hardware wallets from third parties/resellers. This will be an expensive lesson.
The real lesson for this Ledger attack is, don't buy hardware wallets from a third party, ever. That's a painful truth. I've been recommending people buy hardware wallets at physical stores instead of by mail. Now, I don't think I can recommend that at all.

I have never trusted random third party resellers but this incident has taught me to not even trust official resellers. Guess, brands should be shipping globally, so less supply-chain attacks possibility.

By the way, Ledger has been getting burned and burned been a while, has it's reputation already burnt to ashes or any remaining?

║
★
║
.
.BIG WINNER!.
[15.00000000 BTC]
║
★
║
▄████████████████████▄
██████████████████████
██████████▀▀██████████
█████████░░░░█████████
██████████▄▄██████████
███████▀▀████▀▀███████
██████░░░░██░░░░██████
███████▄▄████▄▄███████
████▀▀████▀▀████▀▀████
███░░░░██░░░░██░░░░███
████▄▄████▄▄████▄▄████
██████████████████████

▀████████████████████▀
▄████████████████████▄
██████████████████████
█████▀▀█▀▀▀▀▀▀██▀▀████
█████░░░░░░░░░░░░░████
█████░░░░░░░░░░░░▄████
█████░░▄███▄░░░░██████
█████▄▄███▀░░░░▄██████
█████████░░░░░░███████
████████░░░░░░░███████
███████░░░░░░░░███████
███████▄▄▄▄▄▄▄▄███████

██████████████████████
▀████████████████████▀
▄████████████████████▄
███████████████▀▀▀▀▀▀▀
███████████▀▀▄▄█░░░░░█
█████████▀░░█████░░░░█
███████▀░░░░░████▀░░░▀
██████░░░░░░░░▀▄▄█████
█████░▄░░░░░▄██████▀▀█
████░████▄░███████░░░░
███░█████░█████████░░█
███░░░▀█░██████████░░█
███░░░░░░████▀▀██▀░░░░
███░░░░░░███░░░░░░░░░░

▀██░▄▄▄▄░████▄▄██▄░░░░
▄████████████▀▀▀▀▀▀▀██▄
█████████████░█▀▀▀█░███
██████████▀▀░█▀░░░▀█░▀▀
███████▀░▄▄█░█░░░░░█░█▄
████▀░▄▄████░▀█░░░█▀░██
███░▄████▀▀░▄░▀█░█▀░▄░▀
█▀░███▀▀▀░░███░▀█▀░███░
▀░███▀░░░░░████▄░▄████░
░███▀░░░░░░░█████████░░
░███░░░░░░░░░███████░░░
███▀░██░░░░░░▀░▄▄▄░▀░░░
███░██████▄▄░▄█████▄░▄▄

▀██░████████░███████░█▀
▄████████████████████▄
████████▀▀░░░▀▀███████
███▀▀░░░░░▄▄▄░░░░▀▀▀██
██░▀▀▄▄░░░▀▀▀░░░▄▄▀▀██
██░▄▄░░▀▀▄▄░▄▄▀▀░░░░██
██░▀▀░░░░░░█░░░░░██░██
██░░░▄▄░░░░█░██░░░░░██
██░░░▀▀░░░░█░░░░░░░░██
██░░░░░▄▄░░█░░░░░██░██
██▄░░░░▀▀░░█░██░░░░░██
█████▄▄░░░░█░░░░▄▄████
█████████▄▄█▄▄████████

▀████████████████████▀
║
★
║
║
★
║
✔ Rainbot
✔ Daily Quests
✔ Faucet
oll
Full Member
***
Offline

Activity: 534
Merit: 200



View Profile
October 09, 2026, 06:36:03 PM
Merited by Pmalek (3), vapourminer (1)
 #37

One of the drain wallets was funded in May 1st:
https://mempool.space/address/bc1qt2e2a5l66x8s5ahe7339mqvukmzhmrxe27603z
This wallet was funded in January:
https://mempool.space/address/bc1qpxq4p55xg7exdnzrjg8x652gnceyjmh45sg6ce
And this is just me browsing around

Also, how about the other scenario..
They loaded their inventory at the moment of the sale with malware and made sure they would reach future clients on orders placed after they sold and had nothing to do with the company..
Doesn't that also make a lot of sense? Like the perfect exit point?

The attack's victims extend beyond the 90-day window mentioned by Ledger. This directly points to devices purchased previously or existing seed phrases restored on newer devices.

X of AMLBot:
Quote
If you bought from this reseller this year, or entered an existing seed into one of its devices, don’t rely on the 90-day cutoff. Move your funds to a new seed generated on a device bought directly from the manufacturer

https://x.com/AMLBotHQ/status/2108625722210435143


YellowSwap
Sr. Member
****
Offline

Activity: 700
Merit: 251


View Profile
October 09, 2026, 06:54:57 PM
Merited by vapourminer (1)
 #38

The Cryptobilis team needs to be arrested asap,  Angry Angry

They must have worked physically on the hardware wallets and sold it to the public, this is a big crime that needs action immediately, they need to crucified those guys.

I feel for this fella, who just not too long bought 10BTC and lost it because he got Ledger from same Cryptobilis.




https://x.com/lookonchain/status/2108585005635301427
julerz12
Legendary
*
Offline

Activity: 3206
Merit: 1743


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
October 09, 2026, 06:58:53 PM
Merited by vapourminer (1)
 #39

The stolen funds have begun to move; some went to a Binance deposit address (TMxnc434PYthRnaBxEA494xrk7iyufrAZP).
Unfortunately, funds are still coming in, especially in BTC - the latest inflow was 6 minutes ago.
https://arkm.com/explorer/entity/cryptobillis-ledger-drainer (current balance: $72m)

LuckyCrypto777 (OP)
Member
**
Offline

Activity: 80
Merit: 181

-


View Profile
October 09, 2026, 07:36:57 PM
Merited by Pmalek (3), ABCbits (2), vapourminer (1)
 #40


I'm also curious to know whether at least Ledger was notified of CryptoBilis changing hands

There is no exact answer yet, but:

The ownership change turned out to be true.
An official statement from CryptoBilis co-founders Arravinda Prabu and Vimalathithan regarding their current status and relationship with Ledger:
In March, the full ownership was transferred to the new owner, the deal included a non-disclosure agreement until October.
The new CEO: Nicholas Chang, available for communication at nicholas@cryptobilis.com

Pages: « 1 [2] 3 4 5 6 7 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!