In an Oct. 9 statement, the crypto hardware wallet maker said it was probing claims that customers suffered losses after buying devices from the distributor, which appears in Ledger's official reseller directory for Malaysia, Indonesia and the Philippines. Ledger asked CryptoBilis to immediately pause sales and shipments while the investigation continues.
The company advised anyone who purchased a device from CryptoBilis in the past 90 days not to initialise it if setup is incomplete, and urged customers who have already configured their wallets to consider transferring cryptocurrency to a new Ledger device created with a fresh recovery phrase.
Binance founder Changpeng Zhao warned users to be cautious. "Based on information so far, it seems to be localized to a supply chain attack with one vendor," he wrote on X, while calling for industry-wide cooperation to trace and recover stolen assets. "I expect and know all BNB ecosystem players (and all industry) to help trace and recover the funds."
Former Mt. Gox CEO Mark Karpelès has asked CryptoBilis to open some of its unsold Ledger wallets so their circuit boards can be inspected for possible spying implants or other unauthorised modifications. His concern highlights a recognised gap in Ledger's security: the company's own documentation notes that its Genuine Check system verifies a device's Secure Element but cannot necessarily identify physical modifications elsewhere in the hardware if the original security chip remains intact.