
Ledger Links All Confirmed Fund Drainings to CryptoBilis-Sold Devices
Ledger said Tuesday that all confirmed cases of user funds being drained from hardware wallets involved devices sold through CryptoBilis, a reseller, rather than through Ledger's direct channels. The company reiterated its policy against restocking returned products, highlighting supply-chain vulnerabilities.
Written by CoinArticle’s AI Newsroom · from 2 cited sources. How we work
The Scope of the Problem
Ledger said in a statement that every confirmed instance of unauthorized fund draining from its hardware wallets traces back to devices purchased through CryptoBilis, a third-party reseller, according to reporting from The Defiant and Crypto Briefing. The company emphasized that its own direct sales channels have not been implicated in any of the incidents so far.
Ledger's Response and Supply-Chain Concerns
Ledger reminded resellers and users that returned products should never be restocked or resold, a core policy aimed at preventing compromised devices from re-entering the market. The incident underscores a broader vulnerability: hardware wallet security depends not only on the manufacturer's controls but also on every intermediary in the distribution chain. Without strict verification and inventory controls at reseller level, devices can potentially be tampered with, intercepted, or counterfeited before reaching end users.
Implications for Buyers
The pattern suggests that purchasing directly from a manufacturer's official website or authorized retailers may reduce exposure to supply-chain compromise. However, the full scope of affected devices and the mechanism of compromise remain unclear from Ledger's public disclosures to date. Users who purchased Ledger hardware through CryptoBilis or other third-party channels in recent months may wish to verify the authenticity of their devices and consider migrating funds if concerns persist.
Why It Matters
For Traders
If you hold crypto on a Ledger, verify your purchase source; devices from unauthorized resellers pose material risk of fund loss.
For Investors
Supply-chain attacks on hardware wallet makers erode consumer confidence and reveal a structural weakness in custody infrastructure that regulators may eventually address.
For Builders
Hardware wallet manufacturers and DeFi protocols should consider adding on-chain device attestation or tx-signing fingerprints to detect compromised signing environments.
This article is for information only and is not financial advice. Read the full disclaimer.





