In October 2025, hardware wallet manufacturer Ledger faced an unprecedented crisis of confidence. More than 300 users reported stolen assets, with independent investigators estimating losses of between $86 million and $92.9 million. As the investigation deepened, a Southeast Asian distributor called CryptoBilis came into the public eye—and numerous questions surrounding changes in its ownership cast an even more complex shadow over the supply chain attack.
The heart of the incident: confirmation of a supply chain attack
In early October, Ledger officially confirmed that some users’ devices had been maliciously tampered with before initialization. By physically implanting or preloading seed phrases, the attackers caused users to transfer their assets, unknowingly, to wallets controlled by hackers. Ledger acted quickly, asking CryptoBilis to suspend sales and advising users who had purchased devices through the distributor in the past 90 days to stop using the associated wallets immediately and transfer their assets to new, secure addresses.
What makes this incident unusual is that it was not a traditional software vulnerability or phishing attack, but a precise infiltration targeting the physical supply chain of hardware devices. Security researchers point out that such attacks require access close to the device production or distribution process, making distributor networks a key investigative direction.
CryptoBilis: From Regional Distributor to the Center of the Storm
CryptoBilis is an important authorized distributor for Ledger in Southeast Asian markets such as Malaysia and Indonesia. It was through this channel that a large number of affected users purchased tampered devices. However, as the investigation progressed, a more sensitive fact emerged: the company underwent an ownership change in 2025.
According to publicly available company registration information, CryptoBilis completed the acquisition transaction in March 2025, and the former shareholder fully withdrew from the company’s operations, management, and administrative roles. However, the formal change in equity registration was not completed until August 3, when the newly registered shareholder was listed as a person named Jiaming, with a registered address in Heilongjiang Province, China.
This time gap has raised many questions. How long did the former shareholder retain actual control after the transaction was completed? Why was there a nearly five-month delay between the completion of the acquisition and the change in equity registration? More importantly, is this change in ownership structure linked to the subsequent supply chain attack?
Key Questions and Information Gaps
At present, investigators have not found direct evidence linking the equity change to the theft of cryptocurrencies. However, several facts cannot be ignored:
First, the precision of the attack suggests that the hackers had a clear understanding of the target user base. Most affected users purchased devices through the CryptoBilis channel, implying that the attackers may have obtained the distributor’s sales data and customer information.
Second, after the incident was exposed, the former shareholder disclosed that they were bound by a non-disclosure agreement and could not publicly discuss the transaction details before October 19. This time restriction happened to cover the critical investigation period after the exposure, objectively delaying the transparent release of information.
Moreover, delayed registration of equity changes is not uncommon in Southeast Asian business practice, but in the context of a security incident, such delays make it harder to trace the actual controller.
Regulatory Involvement and Industry Impact
Financial regulators in Malaysia and Indonesia have launched investigations, focusing on CryptoBilis’s ownership structure and compliance records. Ledger, for its part, said it is cooperating with law enforcement agencies to conduct a comprehensive audit of the supply chain.
This incident sounded an alarm for the entire hardware wallet industry. For a long time, hardware wallets have been regarded as the "gold standard" for cryptocurrency storage, with their security built on the assumptions of physical isolation and a trusted supply chain. However, the CryptoBilis incident shows that even if the device itself has no design flaws, vulnerabilities in the distribution process can still lead to catastrophic consequences.
Unsolved Mysteries
As the investigation deepens, more questions emerge: Is Jiaming the ultimate beneficial owner? Was the control vacuum between March and August exploited by attackers? Is this incident an independent criminal act, or part of a larger-scale supply chain infiltration?
After the non-disclosure agreement expires on October 19, the former shareholder may disclose more transaction details. The investigation results from regulators may also reveal a more complex truth behind this incident. For cryptocurrency users, this incident serves as a reminder: in the world of digital assets, trust requires technology to be built, but it can be shattered by a tampered hardware wallet.#Tether冻结Ledger盗窃案相关USDT
