What is reported to have happened?
On Oct. 9, Specter (@SpecterAnalyst) said on X that a trace of theft addresses showed losses of more than $86 million from reported wallet drains of Ledger users. Specter said the addresses took in funds from hundreds of victims’ wallets on multiple major chains, among them Ethereum, TRON and Bitcoin.
The tracker cited user reports on X and Reddit and listed 10 addresses. As of last check, those addresses held only over $25 million, suggesting the majority of the funds had been moved.
For newcomers, a “theft address” is a public wallet address that appears in an on-chain trace as a destination for stolen funds. The address itself does not tell the whole story; trackers follow how funds move after they leave the original wallets.
Why do another tracker’s numbers look different?
A post from tanuki42 published at 12:00 UTC asked anyone drained to contact SEAL 911 as soon as possible. That post said, “Total loss is >$72M+ and increasing.” It listed eight addresses, all of which also appear in Specter’s list of 10.
Specter’s list adds two more bitcoin addresses and was posted at 12:24 UTC.
The difference matters for readers because these figures are public snapshots of on-chain activity, not necessarily final damage totals. A wallet address may show a smaller balance than the reported loss if the funds were moved to other addresses, spent, bridged, or otherwise dispersed after the drain.
What did the Security Alliance do?
The Security Alliance (SEAL) quote-posted tanuki42’s list at 12:29 UTC. It asked anyone whose funds were drained to those addresses to get in contact with the group as soon as possible through the SEAL 911 Telegram bot.
This kind of coordinated reporting can help security groups and investigators connect separate losses into a larger picture. It can also help identify patterns across chains, addresses, and transaction flows.
What did Ledger say, and what did it not say?
Ledger (@Ledger_Support) said at 13:32 UTC that it is investigating reports of lost funds from users in South East Asia who bought products from a reseller named CryptoBillis. Pending the results, Ledger said it asked the reseller to pause all sales and shipments of Ledger devices.
Ledger recommended that users who bought from the reseller in the last 90 days not start setup if they have not done so. It said users who have already set up a device should “consider moving assets to a new Ledger signer (with new seed)” and that it will keep informing customers as the investigation progresses.
Ledger’s post does not mention the $86 million tally or the addresses in the other posts, and does not say how many users or how much money is involved.
What should a user take from this?
If you bought a Ledger device from CryptoBillis in the last 90 days and have not started setup, Ledger’s guidance is to pause before setting up. If you already set up that device and hold assets on it, Ledger said you should consider moving assets to a new Ledger signer with a new seed.
If you did not buy from that reseller, the public posts and Ledger’s statement do not say your device is affected. But the broader lesson for newcomers is that a hardware wallet helps protect private keys, while the recovery seed and the purchase or setup process still need care. Users should never share their seed phrase, should verify devices and instructions before use, and should check addresses carefully before sending funds.
Why is this important beyond one brand?
The reported drains touched Ethereum, TRON and Bitcoin, showing that a wallet or seed-related issue can cross major ecosystems. The story is also a reminder that self-custody security has more than one weak point: malware, phishing, supply-chain problems, reseller risk, and setup mistakes can all lead to drained funds.
Hardware wallets are often described as offline protection for private keys, but they do not make a user immune to bad purchases, bad instructions, or compromised setup steps. The practical takeaway is that security depends on the whole chain: where the device comes from, how it is initialized, how the seed is stored, and how addresses are verified.
What is still unknown?
Ledger did not say how many users are involved or how much money is tied to its investigation. Specter and tanuki42 showed traced addresses and reported totals, but the cause has not been fully detailed in the public posts.
The underlying report, originally published by Unchained, said this is still a developing story that will be updated. The original coverage also referenced a related listen, “Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money.”

Comments 0