The most instructive hack of 2026 isn’t a smart contract bug. It’s a story about buying a company.
On October 9, Ledger users in Southeast Asia woke up to empty wallets. By the end of the day, investigators had traced an estimated $72M–$90M to roughly 98 collection addresses across Bitcoin, Ethereum, and Tron; Tether had frozen what it could; and the attacker was already pushing funds through Tornado Cash. The devices at the center of it all came from one place: CryptoBilis, an authorized Ledger reseller.
Then came the detail that reframed everything. Per Bitcoin News, citing Malaysian corporate records: as of August 3, 2026, CryptoBilis was 100% owned by a Chinese national named Jiaming, registered at an address in Heilongjiang province. The company’s former co-founder confirmed the sale closed in March — and that the original team had exited everything, kept from speaking by a confidentiality agreement.
A trusted distribution channel changed hands in secret. Seven months later, its customers’ wallets drained in a day. That sequence — not any single vulnerability — is what makes this case a textbook study in how supply-chain attacks actually work.
The full timeline
| Date | Event |
|---|---|
| Dec 2020 | CryptoBilis founded in Malaysia by Arravind Prabu, Vimal Selvamany, and Dhivager Rathakrishnan under parent Fetch International (Vulcan Post) |
| Through 2025 | Builds regional reputation: authorized Ledger reseller for Malaysia, Indonesia, Philippines; hosts Bitcoin Pizza Day events; CEO is president of Malaysia’s ACCESS Blockchain Association |
| Mar 2026 | Company acquired; original founders exit all operations, management, and administration — confirmed by former co-founder |
| Aug 3, 2026 | SSM records show Jiaming (Heilongjiang, China) holds 100% of shares |
| Oct 8 | Mark Karpelès warns on X that tampered Ledgers with hidden implants are circulating; one device he examined came from Malaysia, in intact shrink wrap; the warning draws ~90K views |
| Oct 9, ~06:00 UTC | Collection addresses begin receiving large USDT transfers |
| Oct 9, 12:24 | Specter publishes ten collection addresses across BTC/ETH/Tron; $86M+ estimate |
| Oct 9, 13:32 | Ledger confirms investigation, orders CryptoBilis to halt all sales and shipments |
| Oct 9, 14:01 | CZ calls it a supply-chain attack via a single vendor |
| Oct 9, afternoon | MistTrack nears $90M; Tether freezes linked USDT |
| Oct 9, 16:30 | 430.2 ETH moves through Tornado Cash; USDT swapped to USDD via Sun.io and PSM |
| Oct 9, 16:48 | SSM ownership findings published; former co-founder confirms March acquisition |
The minute-level flow on October 9 is documented by The Block, CoinDesk, and CryptoTicker.
The shell that got bought
CryptoBilis was, by every public signal, a legitimate operation. Founded in late 2020 by a team that also ran a crypto payments company, it grew into what its own marketing called Southeast Asia’s leading crypto commerce platform — selling Ledger, Trezor, OneKey, Tangem, and SafePal devices across Malaysia, Indonesia, and the Philippines. Its co-founder sat at the top of Malaysia’s blockchain industry association. It organized the region’s Bitcoin Pizza Day events. Its name, a play on ikan bilis (Malay for anchovies — the little fish next to crypto whales), was a local in-joke people trusted.
That is precisely what made it worth buying.
For an attacker, acquiring a five-year-old authorized reseller is cheaper and more reliable than counterfeiting one from scratch. The “authorized reseller” badge transfers with the company. The customer base transfers. The logistics chain — warehouses, packaging, shipping — transfers. Nothing about the storefront needs to change, and per the former co-founder’s account, nothing did: the company kept selling, kept running events, kept its public face while the people who built it walked out of operations entirely in March.
Whether Jiaming or the acquiring entity directed the device tampering is not established. What the record shows is narrower and still damning as a pattern: the devices that drained wallets came from a channel whose ownership quietly changed hands months earlier, and nobody — not Ledger, not the customers — was any the wiser. A distribution channel is a trust product, and this one was sold without the trust being re-underwritten.
The implant: hardware that passes the genuine check
The mechanism, per Mark Karpelès — who says he was investigating a related issue before the incident and asked victims to send him circuit-board photos — is physical, not cryptographic:
- A hidden implant sits under the screen, intercepting the data sent to the display.
- When the user sets up the wallet, the recovery phrase shown on screen is captured and transmitted.
- The original secure element remains intact, so Ledger’s genuine-device verification passes — the check confirms Ledger’s chip is genuine, not that nothing else was added.
- The tampered device arrives in intact shrink wrap, defeating the standard “check the seals” advice.
This explains the theft pattern better than phishing would. Lookonchain traced one victim who bought 80 BTC at ~$65,000 four months earlier, deposited all of it into a Ledger bought from CryptoBilis a week before the incident — gone. Another address, tagged TY24Ya, bought a device three weeks prior, loaded 7 million USDT, and lost the entire amount in a single sweep: likely the largest single loss in the case. Across Specter’s Arkham data, the drains averaged roughly $890,000 per address — versus about $21,000 per victim in the Coldcard incident two months earlier. (Our companion piece traces the ten flagged theft addresses transaction by transaction; the verifiable-loss floor there is ~$27M, well below the $86M headline estimate.) An attacker holding harvested seed phrases can simply wait, watch balances accumulate, and take only the wallets worth taking.
And there is a chilling wrinkle in the timing. Karpelès posted his warning about implant-carrying devices on October 8 — the day before the coordinated sweep. The warning drew around 90,000 views. The emerging speculation, explicitly flagged as unconfirmed, is that the attacker saw the warning, realized exposure was imminent, and triggered the mass drain overnight. If true, the community’s own early warning system rang the bell that started the slaughter.
The laundering: freezes, swaps, and the mixer
The hours after the drain turned into a live demonstration of stablecoin attack surface:
- Tether froze first. MistTrack confirmed large USDT freezes at linked addresses — freezing in place a chunk of the ~$16.5M in USDT that Specter’s Arkham snapshot showed.
- The attacker swapped to USDD. Following the freezes, funds moved through Sun.io and the USDD Peg Stability Module into USDD — a Tron-based stablecoin Tether cannot freeze — with some routed onward to Binance hot wallets, as Onchain Lens data showed. Onchain Lens publicly called on Binance to freeze linked accounts.
- ETH went through Tornado Cash. 430.2 ETH (~$1.07M) across four wallets entered the Tornado Cash mixer, breaking deterministic traceability — see our mixer explainer for why this works.
- The bulk is still visible. Arkham-tagged addresses held ~$70.6M at last count: 11,406 ETH, 213.37 BTC, 13.65M USDD, and 10.91M USDT. Every hour it sits there is a window for freezes; every swap shrinks it.
What this case teaches
For users: the seller is part of the threat model. The rule that survived this incident: buy hardware wallets from the manufacturer directly, generate your own seed phrase on-device, and treat a new device as unproven for its first weeks — CZ’s advice to leave a fresh device unused for a while before funding it would have saved several victims here. Our earlier piece on hardware wallet scams covers the pre-filled-seed variant of the same attack; this case adds the scarier upgrade, an implant that survives the genuine-device check. If you drained funds, the first-24-hours checklist still applies — fast reporting is what makes interception possible.
For vendors: reseller badges are liabilities if unmonitored. Ledger authorized this reseller, and the authorization outlived the company’s original owners. A vendor that doesn’t track ownership changes in its distribution chain is underwriting trust for whoever buys the shell. After this, expect “authorized reseller” programs to come with ownership-change disclosure clauses — and expect buyers to ask.
For the industry: reputation is transferable, and that’s the vulnerability. Five years of community events, an industry-association president as founder, official badges — all of it was packaged into an entity that could be bought silently. The security of a hardware wallet channel isn’t cryptographic; it’s corporate. This is the same lesson as the supply-chain attack class we’ve seen hit npm packages — trust artifacts (a badge, a publisher, a package name) get harvested instead of broken. For a transaction-by-transaction read of the theft addresses themselves, see our companion tracing piece.
What to watch
Three things will harden this from narrative into verdict: (1) Ledger’s post-mortem confirming the implant mechanism and whether tampering maps to the March ownership change; (2) whether anyone establishes who Jiaming and the acquiring company are, and whether funds connect them to the drain addresses; (3) whether Binance freezes the accounts that received laundered flows. Until then, treat this as the confirmed parts — secret acquisition, device tampering, coordinated drain — plus the strong inference connecting them. We will update as findings land.
Frequently Asked Questions
Was CryptoBilis really sold to a Chinese buyer?
Malaysian corporate records (SSM) show that as of August 3, 2026, a person named Jiaming, with a registered address in China's Heilongjiang province, held 100% of CryptoBilis shares. The company's former co-founder confirmed the acquisition was completed in March 2026 and that the original owners exited all operational, management, and administrative roles. Per reporting of the original post, the ex-owner was placed under a confidentiality agreement preventing public disclosure of the sale.
Does the ownership change prove the new owner is the hacker?
No. No evidence yet connects Jiaming or the acquiring company to the theft addresses. The acquisition is a fact from corporate records; the causal link between the ownership change and the wallet drains remains unconfirmed. What is established is the timing: devices sold after the March takeover are the ones linked to the losses.
How did tampered devices pass Ledger's genuine-device check?
According to Mark Karpelès, the implants sit under the screen and intercept the data sent to it — capturing the recovery phrase displayed during setup — while the original secure element remains intact. Ledger's genuine-device check verifies the secure element, so an unauthorized physical modification goes undetected. He examined one affected device from Malaysia that arrived in intact shrink wrap.
How much was stolen and where is the money now?
Estimates range from $72M+ (tanuki42) to $86M+ (Specter, across ~98 collection addresses) to nearly $90M (MistTrack); Ledger has confirmed no figure. The attacker moved 430.2 ETH (~$1.07M) through Tornado Cash and, after Tether froze linked USDT, began swapping USDT for USDD — a Tron stablecoin Tether cannot freeze. Arkham-tagged addresses still held about $70.6M at last count.
I bought a Ledger from CryptoBilis. What should I do?
Follow Ledger's guidance: if the device is not set up, do not start setup. If it is set up, move assets to a new Ledger device with a freshly generated seed phrase. Do not reuse any recovery phrase that shipped with the device, and be alert for phishing — fake 'Ledger security check' pages target users exactly when they panic.