Ledger reseller hacker sends $1.3M to Tornado Cash and Binance

In this article5 sections
A suspected attacker linked to the Ledger CryptoBilis reseller incident has moved 430.2 ETH, worth about $1.07 million, into Tornado Cash and deposited a further $270,280 at Binance, according to Cryptopolitan, citing the on-chain analytics account Onchain Lens in a report dated October 9, 2026.
The Ethereum was routed through four separate wallets before reaching the mixer, while the exchange deposits consisted of $256,567 in USDT and roughly $13,710 in TRX, Onchain Lens said. A further $22,390 in USDT formed part of the total. The funds were placed in a hot wallet at Binance, where they can still be frozen by the exchange even if recovery is a separate problem.
Key facts
- Onchain Lens reported 430.2 ETH, approximately $1.07 million, sent to Tornado Cash via four wallets, plus $270,280 deposited at Binance.
- Tether froze some of the USDT tied to the suspected theft, after which other funds were converted to USDD through the SUN.io platform and its Peg Stability Module.
- Loss estimates for the CryptoBilis incident range from $72 million to $86 million, per analysis by tanuki42 and Specter cited by U.today and The Block, while Binance News put the figure at $90 million. None has been confirmed.
- Ledger said on October 9 that it was investigating claims involving CryptoBilis customers in Southeast Asia and asked the vendor to halt device distribution.
- Those estimates appeared alongside a report from U.today, which described an incident in Southeast Asia in which users lost more than $86 million, and noted Ledger’s statement that its factory production, firmware, and the Ledger Live application were untouched by the attack.
Funds routed from wallets into an exchange hot wallet
Tornado Cash makes it harder to trace a deposit back to a specific withdrawal, but it does not remove every route for investigators. Blockchain analysts were able to observe the transfers as they happened; observing a flow of funds is not the same as halting it.
USDD, a decentralized stablecoin, falls outside the issuer-level freeze controls that the Financial Action Task Force urged stablecoin issuers to adopt in a March 2026 report. Frozen USDT, by contrast, could not be swapped for anything. The conversion shows that a stablecoin swap can move value beyond the reach of those controls, though it does nothing to hide the original on-chain trail.
U.today reported that the attackers physically opened packages at a reseller’s intermediate warehouses and replaced the original instructions with pre-generated seed phrases. That account lines up with the supply-chain framing, but no device-tampering claim has been verified.
Ledger’s investigation and the unconfirmed loss figures
Ledger’s public guidance on October 9 covered two groups. Buyers who purchased devices within the previous 90 days were told not to set up or use the new devices, and that they should consider moving assets to a new Ledger signer with a fresh seed phrase. The company also asked CryptoBilis to stop all sales and shipments.
Cryptopolitan reported that a TokenPost estimate valued the suspected hacker’s assets at roughly $70.60 million across ETH, BTC, USDD and USDT, based on wallets monitored by Arkham, while noting that this figure is not the same as the amount actually lost. Binance co-founder Changpeng Zhao has floated the idea of a vendor-specific supply-chain attack, and former Mt. Gox chief executive Mark Karpelès has discussed the possibility of device tampering. Neither theory has been validated.
Why it matters
The case shifts attention from software exploits to the physical journey a hardware wallet takes before it reaches a buyer. U.today noted that Coldcard maker Coinkite reported a compromise of its third-party distributor systems in August and that Trezor disclosed a data breach affecting 80,000 US customers after its logistics contractor ShipMonk was hacked in September — pointing to delivery, not firmware, as the recurring weak link.
For anyone holding assets in self-custody, the practical effect is that buying through a local distributor or marketplace is now treated as risky. Zhao has recommended leaving a newly purchased wallet unused for at least a couple of weeks while watching the news, a window that gives on-chain analysts time to spot a bad batch and warn other buyers. U.today credited that quarantine guidance to Zhao.
The figures in circulation still diverge, and none of them has been confirmed. Cryptopolitan reported estimates of $72 million to $86 million from tanuki42 and Specter and $90 million from Binance News; U.today described more than $86 million in tracked outflows across the Bitcoin, Ethereum and Tron networks. The reports do not agree, and some figures may cover different wallet sets.
What to watch
Ledger’s investigation into the CryptoBilis claims, Binance’s handling of the deposits sitting in its hot wallet, and any further movement of the mixed ETH will shape how much of the total can be traced or recovered. Consumers who bought devices in the past 90 days still face the decision Ledger flagged: skip activation and migrate to a new signer with a fresh seed phrase.
This article is not financial advice, and crypto markets and on-chain recovery outcomes are volatile and uncertain.
Disclaimer: This article is for information only and is not investment, financial or trading advice. Cryptocurrency prices are highly volatile. Always do your own research.
Sources: Cryptopolitan, U.today


