The headline number in the Ledger reseller case is somewhere between $86 million and $93 million, depending on which on-chain tracker you read. The more telling number is smaller: about $10 million, the portion that Tether was able to freeze, according to blockchain analytics firm Bitquery. Roughly three quarters of the stolen value moved as USDT on Tron, and part of it was swapped within hours into a stablecoin that Tether cannot freeze.

The case centres on CryptoBilis, a Malaysia-based reseller that The Block reports was listed as an official Ledger reseller for Indonesia, Malaysia and the Philippines; it has suspended sales in all three, according to Chinese outlet MarsBit. On 10 October 2026 Ledger said that one affected user's device contained an unauthorized hardware implant.

It is part of the backdrop for Web3 Week Asia in Jakarta on 11-12 November 2026, where custody and regulation sit alongside markets.

What happened. Wallets of buyers of CryptoBilis-sold Ledger devices were drained on 9 October 2026. Bitquery puts the drain window at about 05:07 to 16:37 UTC, or 12:07 to 23:37 WIB.

How much. Estimates range from more than $72 million (researcher tanuki42, early count) to $86 million (investigator Specter, using Arkham data) to $92.9 million across 311 wallets (Bitquery) and $93.4 million across 471 addresses (Yfarmx). Ledger has confirmed none.

What Ledger confirmed. An unauthorized hardware implant in one affected device, and no sign that its own infrastructure, systems or services were compromised, according to its statements reported by CoinDesk, Bitcoin.com News and CoinEdition.

What Ledger advised. Buyers from CryptoBilis in the past 90 days should not set up a new device; those who already did should consider moving assets to a new device with a newly generated recovery phrase.

Reseller status. CryptoBilis suspended sales and shipping of all hardware wallet brands in Malaysia, the Philippines and Indonesia and closed its physical stores, according to MarsBit reports republished by KuCoin.

How a sealed device can still leak a seed phrase

The working theory comes from former Mt. Gox chief executive Mark Karpelès, who published teardown photos of a Ledger Nano X that he says arrived in flawless shrink wrap. According to reporting by BeInCrypto and BigGo Finance, the device held a hidden circuit board behind the screen with a mobile data module and an eSIM. The board reportedly read what the screen displayed during setup, including the 24-word recovery phrase, and could send it out over a mobile connection.

Why it matters: the attack, if confirmed, did not need to break the secure element that holds the keys. Ledger's own documentation acknowledges that its Genuine Check, which verifies that chip, may not detect physical modifications around it when the original secure element is intact. A device can pass the authenticity check and still be compromised.

Karpelès has said his device came from a Malaysian seller other than CryptoBilis, according to BeInCrypto, and investigators have not shown that every drained wallet involved the same hardware.

The stablecoin freeze gap

Bitquery's breakdown, valued at 9 October prices, shows where the money sat: about $70.5 million on Tron, almost all of it USDT, against $16.8 million in bitcoin, $3.7 million on Ethereum, $1.45 million on BNB Chain and $0.58 million on Polygon. Tron alone is about 76% of Bitquery's $92.9 million total.

That matters because USDT is the one asset in the pile that its issuer can freeze. Tether did act: blockchain security firm MistTrack, as relayed by BlockBeats, reported freezes on multiple addresses on 9 October, and Bitquery puts the frozen amount at about $10.0 million across 20 wallets. That is roughly 11% of Bitquery's total.

The rest moved fast. Bitquery traced about 20 million USDT bridged from Tron to Ethereum and about 14.9 million USDT swapped into USDD, a Tron-based stablecoin that Tether cannot freeze. As of 16:45 UTC on 9 October, Bitquery counted about $79 million still sitting on-chain, including the frozen funds and $16.8 million in bitcoin that had not moved.

A centralized freeze is a race measured in hours, and this attacker planned for it. Bitquery dates the first funding of the attacker's control addresses to 25 September 2026, 14 days before the drain, with test transactions running until 7 October.

A reseller ownership question

The second thread is who owned CryptoBilis. Company records cited by MarsBit show an individual named Jiaming, with a registered address in Heilongjiang, China, holding 100% of the shares since 3 August. A former co-founder, Arravind Prabu, says the company was sold in March 2026 and that the founding team no longer had access to operations. The two dates conflict, and no public evidence links the new shareholder to the compromised devices.

Why it matters: an "authorized" badge does not show a change of control. CryptoBilis has promised an independent review of its processes.

The honest counterweight

The loss total is not confirmed. Every figure above comes from independent on-chain trackers using different address sets. Ledger has not confirmed a total, a victim count or the attack vector.

The implant is not proven to be the cause. Ledger confirmed one implant in one device. Whether all drained wallets trace back to tampered hardware from one channel is still under investigation.

No Indonesian victim count exists. The reseller sold into Indonesia, but no source has published how many affected buyers are in Indonesia, Malaysia or the Philippines.

What this means for Indonesia crypto users

OJK reported 23.21 million consumer accounts as of August 2026 and transaction value of Rp23.16 trillion for that month, figures announced on 5 October 2026 and reported by Investortrust, Akurat and Kompas. Those numbers count accounts at licensed platforms. They say nothing about how many Indonesians move coins into hardware wallets, which is exactly the population this case touches.

As of 07:30 WIB on 11 October 2026, no public statement from OJK on the CryptoBilis case could be found in searches of Indonesian media.

Ledger said it had received no reports involving devices bought directly from Ledger. Ledger also states it will never ask for a 24-word recovery phrase.

Web3 Week Asia 2026: blockchain event in Jakarta, 11-12 November

Web3 Week Asia takes place on 11-12 November 2026 at the Grand Ballroom, Kuningan City, Jakarta. The programme runs across four tracks: Investor Meetups, Alpha Callers, Web3 Entrepreneur and Indonesia Crypto Outlook 2026.

The same reseller channel sold into three Southeast Asian countries, which makes supply-chain security a regional question. The 2025 edition drew more than 5,000 participants, over 100 speakers and more than 200 companies from more than 10 countries, according to the organisers. The 2026 speaker line-up is to be announced.

Frequently asked questions

When and where is Web3 Week Asia 2026?

Web3 Week Asia 2026 takes place on 11-12 November 2026 in Jakarta, Indonesia. It is a two-day crypto and blockchain event covering markets, regulation, infrastructure and venture investment across Southeast Asia.

Was Ledger itself hacked?

Ledger says it has no indication its systems were compromised. The losses are linked to devices sold through one reseller, CryptoBilis, and Ledger confirmed an unauthorized implant in one affected device.

How much was stolen in the CryptoBilis case?

Independent trackers estimate between $86 million and $93.4 million, with an early count above $72 million. Ledger has not confirmed any total.

Did the reseller sell devices in Indonesia?

Yes. The Block reports it was listed as an official Ledger reseller for Indonesia, Malaysia and the Philippines, and MarsBit reports it suspended sales in all three. No Indonesian victim count has been published.

What should buyers of these devices do?

Ledger advises buyers from CryptoBilis in the past 90 days not to set up the device, and those who already did to consider moving assets to a new device with a newly generated recovery phrase.

Sources

Bitquery investigation of the Ledger CryptoBilis drain: https://www.bitquery.io/investigations/ledger-cryptobilis-hack

CoinDesk report on Ledger's investigation: https://www.coindesk.com/business/2026/10/09/ledger-investigates-potential-wallet-tampering-after-reports-of-usd86-million-in-crypto-stolen

Loss estimates come from Bitquery (9 October 2026), Specter via CoinDesk, Decrypt and The Block (9 October), tanuki42 via The Block (9 October) and Yfarmx via Bitcoin.com News (10 October). Ledger's statements were reported by CoinDesk and Decrypt (9 October) and by Bitcoin.com News, CoinEdition and Telset (10-11 October). The Indonesia, Malaysia and Philippines reseller listing and sales suspension come from The Block and from MarsBit reports republished by KuCoin (10 October). Tether's freeze was reported by MistTrack via BlockBeats (9 October), with the amount from Bitquery. Teardown details come from BeInCrypto and BigGo Finance (10 October). Ownership records and the co-founder's account come from MarsBit and BigGo Finance. OJK market figures come from Investortrust, Akurat and Kompas (5 October 2026).

Methodology: Tron's share (about 76%) and the frozen share (about 11%) were computed by dividing Bitquery's $70.5 million and $10.0 million by its $92.9 million total; they apply only to Bitquery's address set. Loss estimates were not summed or averaged because the trackers use different and overlapping address lists. Bitcoin losses also differ by source: Bitquery counts 203.8 BTC while Galaxy's Alex Thorn, as reported by BigGo Finance, counts 213.42 BTC. The frozen amount rests on Bitquery and could not be independently matched to a Tether statement. The ownership dates (March versus 3 August 2026) conflict and are reported as such. UTC times were converted to WIB by adding seven hours.

This article is for information only and is not investment advice.