On October 9, 2026, on-chain analyst Specter (@SpecterAnalyst) flagged a coordinated drain of Ledger user wallets spanning Ethereum, TRON, and Bitcoin. Headlines quickly settled on “$86M+ stolen from Ledger users,” with some reports suggesting the final figure could approach $100 million. Crypto Briefing and others framed the cause as a mystery — a possible device flaw, a seed compromise, or phishing, with Ledger staying silent.

We pulled the full transaction history of all ten flagged theft addresses and traced the money ourselves. Our initial read — published hours after the news broke — saw an address-poisoning pattern in the zero-value transfers around the victim wallets. Hours later, Ledger’s official response and CZ’s comments pointed somewhere more specific: a supply-chain compromise through Malaysian reseller CryptoBilis, with devices that may have been tampered with or counterfeit before sale. That explanation fits the on-chain evidence at least as well — and it keeps the core conclusion intact: the firmware and genuine devices were not breached. The channel was.

BLUF:

  • The ten published addresses took in ~$91.6M gross at press-time prices: 65,245,481 USDT on TRON (137 external transfers, 136 senders — 96 of them moved ≥$100K each, median transfer ~$150K, largest $7M), 211.2 BTC ≈ $17.5M, 3,337 ETH ≈ $8.3M, plus ~$0.6M USDT on Ethereum. The TRON USDT has since been fully swept out of the four addresses; the BTC and the ETH still sit there.
  • Specter’s full tally — $86.96M across 98 addresses, with tanuki42 independently estimating $72M+ — is a holdings snapshot at posting time, not cumulative inflow (its 211.199 BTC matches our three Bitcoin addresses). The two figures are different lenses on one operation, and Ledger has not endorsed either.
  • The ETH transfers we sampled are plain sends — no approve(), no blind signing, no drainer contract. (USDT transfers are contract calls by nature, and one matched TRON victim did leave an Approve — but the dominant shape is plain sends, consistent with a compromised seed rather than a signing exploit.)
  • Victim wallets were bracketed by zero-value transactions from lookalike vanity addresses (0x69c8… / 0x83ae… clusters). We first read those as poisoning bait; on closer timeline review most land after the big sends, which reads more like the attacker’s own operational addresses than bait.
  • Wu Blockchain reports Ledger is investigating Southeast Asian buyers who purchased through distributor CryptoBilis; CZ called it a likely single-vendor supply-chain attack.

What the ten addresses actually received

Using Etherscan V2, Tronscan, and blockchain.info, we paginated through every inbound transfer to the ten addresses Specter published (address-by-address, full history, not first-page samples):

ChainAmount≈ USD (press time)Distinct senders
Ethereum (ETH)3,337.35 ETH$8.29M~40
Ethereum (USDT, ERC-20)~605,845 USDT$0.61M—
Bitcoin211.20 BTC$17.47M260 inbound txs
TRON (USDT)65,245,481 USDT$65.2M136 senders, 137 external txs
Total gross inflow≈ $91.6M

The TRON side is not a retail-longtail pattern: 96 of the 136 senders moved ≥$100K each (together $63.9M), transfers under $10K number just 15 (~$16K combined), the median transfer is ~$150K, and the single largest is $7M. On Ethereum, inflows were similarly concentrated: ~40 senders averaging ~80 ETH each, led by a single 298.23 ETH transfer. This is wholesale wallet-sweeping, not nickel-and-dime collection.

One correction to the coverage: Crypto Briefing wrote that Bitcoin address bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl “has reportedly received over 211 BTC.” It received 92.5 BTC. The 211 BTC figure is the sum of all three flagged Bitcoin addresses (92.5 + 111.3 + 7.4). Small error, but it shows how quickly unverified numbers harden into “facts” during a breaking event.

A larger correction to our own earlier framing, courtesy of a full TRON-grid pull that superseded our first TRON numbers (our initial TRC-20 statistics via the Tronscan web API missed the large transfers — an object lesson in why explorer convenience endpoints are not archives). The 10 public addresses alone grossed ~$91.6M — more than Specter’s $86.96M figure, which is a holdings snapshot at posting time rather than cumulative inflow. There is no missing “$59M on unpublished addresses” from our earlier decomposition; the TRON USDT ($65.2M) simply flowed through these four addresses and out again. What remains on the 10 addresses today is the BTC ($17.5M) and the ETH ($8.3M) — the part the thief hasn’t laundered yet, and the part everyone can watch.

The zero-value fingerprints

Here is where it gets interesting. We pulled the full transaction history of the first large Ethereum victim — the address that sent 298.23 ETH to thief address 0x69c8f401… at 05:09 UTC on October 9.

The minutes around the transfer look like this:

  • 05:09 — victim sends 298.23 ETH to 0x69c8f401… (plain transfer, empty input data)
  • 05:11–05:12 — victim sends 14.91 ETH and 0.75 ETH to a second thief address, 0x83aeac16…
  • 05:12–05:49 — the victim’s address receives a string of 0-value transactions from senders including 0x69c8c5f6…, 0x69c888f9…, 0x69c8b3e9…, 0x83ae9f19…, and 0x83ae51cd…

Look at the prefixes. The zero-value senders share their first four hex characters with the two thief addresses: 0x69c8… and 0x83ae…. Four matching hex characters occur naturally in roughly 1 in 65,536 random addresses. Finding five lookalike addresses clustered around two thief addresses is not a coincidence — those are deliberately generated vanity addresses.

This is the address-family fingerprint of a prepared operation. When we first published, we read this cluster as the bait layer of an address poisoning campaign — the same play we broke down in Address Poisoning Attacks Explained and a close cousin of dusting attacks. On closer review of the timestamps, however, most of the zero-value transfers land after the big sends, not before. Poisoning bait has to precede the victim’s mistake to work; trailing zero-value traffic reads more like the attacker’s own operational footprint — gas top-ups, tagging, or consolidation among addresses they generate with matching prefixes for bookkeeping.

Either way, the cluster proves one operator ran this at scale, with tooling, across three chains.

The supply-chain explanation that fits everything

Hours after our first publish, two things landed. Wu Blockchain reported that Ledger is investigating Southeast Asian users who bought devices through distributor CryptoBilis — a Malaysian shop founded in 2020 that also operates in Indonesia and the Philippines. Ledger Support asked CryptoBilis to pause all sales and shipments, told buyers from the past 90 days not to initialize their devices, and told anyone who already had to move funds to a new device with a new seed phrase. CZ separately called it a likely single-vendor supply-chain attack, with some users possibly holding tampered or counterfeit units.

A tampered or fake device explains every on-chain observation — including the ones that made us hesitate:

Almost no signature-trick footprint. The ETH transfers we sampled carry empty input data — plain sends, no approve(), no blind signing, no drainer contract like the ones in wallet drainer campaigns. Two honest qualifications: any USDT transfer is a contract call (that’s how ERC-20/TRC-20 works), and at least one victim matched to TRON address TK6DWN… did leave an Approve on-chain. Still, the dominant shape is plain sends — and a holder of the seed can sign both kinds equally, so this fits key compromise rather than a signing-flow exploit.

Multi-chain consistency. BTC, ETH, and TRON moved in the same window from plausibly the same owners (one Ledger seed derives addresses on all three). A key holder sweeps everything they can at market-rate gas — which is the shape we see: plain sends across all three networks, the TRON USDT consolidated out within hours, the ETH later swapped and moved as well. (To be precise about “still sitting there”: the ether balance of the three EVM addresses is unchanged, but their USDT has been forwarded and some swaps occurred.)

Victims who “never exposed their seed.” Multiple Reddit victims insisted they never typed their 24 words anywhere and barely interacted with dapps. With a tampered device, they’re right — they never leaked it. It was never exclusively theirs to begin with: a fake or altered unit can ship with a preloaded seed, or with firmware that exfiltrates it during setup. (A researcher documented exactly this on counterfeit Ledger units sold through a Chinese marketplace in April 2026.)

The week-long gap. The first TRON collection address went live October 2; the mass drain hit October 9. A supply-chain attacker with preloaded seeds doesn’t strike immediately — they let balances accumulate, then sweep in one coordinated window.

What this is not, on current evidence: a firmware vulnerability in genuine devices, or a failure of the Ledger security model itself. The device did its job; the box it shipped in had already been compromised. And note Ledger has not confirmed the $86M figure nor explained the mechanism — the supply-chain framing is the strongest current hypothesis, not a settled fact.

Timeline of the operation

  • Oct 2, 15:20 UTC — first flagged TRON collection address is created and begins receiving test payments. A week of quiet setup.
  • Oct 9, 05:09–05:55 UTC — the three Ethereum thief addresses activate within 46 minutes of each other; three more TRON addresses come online in the same window. The main drain begins.
  • Oct 9, 10:26 UTC — a seventh collection address appears. The operation is still scaling.
  • Oct 9, ~12:36 UTC — Wu Blockchain reports Ledger is investigating CryptoBilis-sourced devices in Southeast Asia; Ledger asks the reseller to halt sales.
  • Oct 9, ~13:47 UTC — Coinpedia publishes Specter’s fuller tally: $86.96M across 98 addresses; tanuki42’s independent estimate of $72M+ corroborates the scale. CoinDesk notes the tracked addresses hold only ~$25M at last check — most of the non-published money has already moved.
  • Oct 9, 13:31 UTC — most recent inbound TRON transfer at time of writing. Still live.
  • Laundering status — all 211.2 BTC ($17.5M) and 3,337 ETH ($8.3M) sit unmoved in the flagged addresses (independently confirmed against mempool data by BeInCrypto at 13:44 UTC). Every cent of TRON USDT has already been swept out and consolidated. Watching those addresses is now trivially easy for exchanges and chain-analytics teams, which is likely why the big bags haven’t moved — recall from the After a Wallet Drainer, What Now playbook that thieves typically age funds or fragment through mixers before cashing out.

If you hold crypto, do these things now

First, the channel check (official Ledger guidance): if you bought a Ledger from CryptoBilis in the past 90 days — do not initialize it. If you already set it up, move your funds to a new device with a new seed phrase, bought directly from Ledger’s official store. Never buy hardware wallets from third-party marketplaces; the April 2026 counterfeit-Ledger findings showed fake units shipping with seed-exfiltrating firmware.

Then, hygiene that protects you regardless of the vector:

  1. Never copy addresses from your transaction history. That’s the surface attackers poison. Pull addresses only from your verified source — the exchange’s deposit page, the recipient’s official site.
  2. Check first and last 6+ characters. Vanity mimicking usually copies only the edges; the middle diverges. Six characters each side catches most lookalikes.
  3. Use an allowlist for repeat payments. Most wallets support saved/verified contacts. Pay saved addresses, not pasted ones.
  4. Send a test transaction first. For anything above rounding error, move $20 before you move $20,000.

And if you were affected by this specific incident: the BTC and ETH remain in unmoved, publicly flagged addresses — report to the receiving-chain explorers’ fraud tags and to your local cybercrime unit while the trail is still this fresh. For the broader playbook, see How to Avoid Crypto Phishing Scams and How to Audit Your Own Wallet Activity.

Update log: initial version (Oct 9, ~14:20 UTC) attributed the pattern to address poisoning based on the zero-value vanity cluster. Ledger’s CryptoBilis response and CZ’s supply-chain comments, surfaced in Chinese-language media from ~12:36 UTC, were incorporated later the same day, along with a timestamp re-check that moved most zero-value transfers to after the main sends. Core verified findings — $27.1M traceable, zero contract calls, 211 BTC unmoved — are unchanged. Evening update: the $86M was reconciled — Specter’s full tally is $86.96M across 98 addresses (Coinpedia), with our $27.1M being the verified, still-unmoved portion on the 10 published addresses. Second evening correction: a full TRON-grid pull of TRC-20 records superseded our initial TRON statistics — the Tronscan convenience API had missed the large transfers, understating TRON inflow ~90x. Corrected figures: 65,245,481 USDT across 137 external transfers (median ~$150K, max $7M); 10-address gross inflow ≈ $91.6M; Specter’s $86.96M is a holdings snapshot, not cumulative inflow. Timeline corrected (first TRON address created Oct 2 09:20:54 UTC; last external USDT inflow Oct 9 11:41:36 UTC). ‘Zero contract calls’ qualified — USDT transfers are by nature contract calls, and one matched TRON victim left an Approve. The URL slug retains the initial ‘address-poisoning’ framing for link stability; the article’s conclusion supersedes it. We will keep updating as the addresses move or Ledger publishes findings.

Frequently Asked Questions

Were Ledger devices actually hacked?

Not the firmware. Ledger's own response points to a supply-chain compromise: devices bought from Malaysian reseller CryptoBilis may have been tampered with or counterfeit. A tampered device can ship with a preloaded seed the attacker already knows — which explains why the dominant transfer shape is plain sends, and why victims insist they never exposed their seed. If you bought from CryptoBilis in the past 90 days, follow Ledger's guidance: do not initialize the device, or move funds to a fresh device with a new seed.

Is the loss really $86 million?

Specter's $86.96M (98 addresses, per Coinpedia) is a holdings snapshot at posting time, not cumulative inflow — and tanuki42 independently estimated $72M+. Gross inflow to the 10 published addresses alone was ~$91.6M at press-time prices: $65.2M in TRON USDT, $17.5M in BTC, $8.3M in ETH, plus ~$0.6M in Ethereum USDT. Ledger has not endorsed any figure.

Why did the media report 211 BTC in a single address?

Cryptobriefing wrote that address bc1qjqgwejnp… received over 211 BTC. Our tracing shows that address received 92.5 BTC; the 211 BTC total is the sum of all three flagged Bitcoin addresses combined. The figure was attributed to the wrong address in translation.

How do I protect myself from this kind of attack?

For this incident there is exactly one real defense: if you bought a Ledger from CryptoBilis in the past 90 days, do not initialize it — if already set up, move funds to a new device with a new seed, bought from the official store. If the device shipped with a preloaded seed, address-checking habits will not save you. Those habits (never copy from history, verify first/last 6+ chars, allowlists, test sends) protect against other vectors — poisoning, drainers — not against this supply-chain problem.

Is the supply-chain explanation confirmed?

No. Ledger named CryptoBilis and asked it to halt sales, and CZ called it a likely single-vendor supply-chain attack, but the company has not explained the mechanism or confirmed any loss figure. 'Tampered devices with preloaded seeds' is the leading hypothesis that best fits the on-chain evidence — not established fact.

Where are the stolen funds now?

The $65.2M of TRON USDT was fully swept out of the four TRON addresses; the EVM addresses' USDT has been forwarded and partly swapped. Still sitting in the flagged addresses as of October 9 evening: 211.2 BTC (~$17.5M) and 3,337 ETH (~$8.3M) — the live, watchable trail.