Saturday, October 10, 2026Live markets
BBTC$82,767.78 +0.19%EETH$2,493.40 -0.41%BBNB$749.64 +0.91%XXRP$1.41 +0.22%SSOL$109.86 -0.42%TTRX$0.3308 -0.41%HHYPE$84.36 -1.75%ZZEC$1,225.00 -0.13%DDOGE$0.0862 +1.17%XXMR$525.80 -4.02%LLINK$12.96 +0.61%AADA$0.2561 +6.73%XXLM$0.1971 +1.16%NNEAR$5.22 +8.00%
Security

Tether Freezes $90M in USDT Tied to Ledger Buyer Thefts

CDBy · · 4 min read
Tether Freezes $90M in USDT Tied to Ledger Buyer Thefts
In this article5 sections
  1. 01Key facts
  2. 02A supply chain question, not a vault problem
  3. 03Why the freeze is only partial
  4. 04Why it matters
  5. 05What to watch

Tether has frozen close to $90 million in USDT connected to thefts from Ledger hardware wallet buyers, Cryptobriefing reported. The freeze stops the stolen stablecoins from moving but does not return any money to the people who lost it.

The incident surfaced on October 9, 2026 and centers on Ledger devices bought from CryptoBilis, an authorized distributor operating in Southeast Asia. Coincentral reported that researchers estimate losses between $72 million and $86 million, while Ledger itself has not confirmed either figure.

Key facts

  • Estimated losses from the thefts exceed $86 million, with some tracking services putting the figure near $90 million, per Cryptobriefing.
  • Researcher Specter said on X that more than $86 million may have been stolen from hundreds of wallets, while researcher tanuki42 identified eight wallet addresses linked to over $72 million in losses, Coincentral reported.
  • The stolen assets were spread mostly across the Bitcoin, Ethereum and Tron networks.
  • Ledger has asked CryptoBilis to pause all sales and shipments of Ledger devices during the investigation.
  • Binance co-founder Changpeng Zhao said he expects all BNB ecosystem players and the wider industry to help trace and recover the funds, according to Coincentral.

A supply chain question, not a vault problem

The cause of the thefts has not been confirmed. Early speculation points to possible tampering somewhere in the supply chain rather than a flaw in Ledger’s core hardware or systems, and there has been no confirmation of a broader hardware compromise at Ledger. Ledger said in a statement to Cointelegraph that the issue appears limited to the reseller and the markets it serves, and that it has received no reports involving devices bought directly from Ledger. The company said its infrastructure, systems and services were not compromised.

Coincentral reported that one explanation researchers have floated is a supply chain attack, in which a device is tampered with before it reaches the buyer and an attacker preloads a wallet with a recovery phrase they already know. Ledger has not confirmed that this is what happened.

CryptoBilis sells Ledger devices in Indonesia, Malaysia and the Philippines. Ledger, founded in 2014, has sold more than 7 million devices worldwide, according to Coincentral.

Why the freeze is only partial

USDT is not like Bitcoin. Tether issues the token and keeps the ability to blacklist addresses, stopping them from sending USDT anywhere, and it has used that power over the years to lock funds tied to thefts and fraud adding up to billions. In this case the freeze applies only to the USDT portion of the stolen assets. Bitcoin moving on its own network has no central issuer that can step in, which makes the Tether action helpful but incomplete, as Cryptobriefing noted.

For victims, a freeze is the start of a process rather than the end of one. Frozen funds generally need a further step, such as legal action or a coordinated return, before they reach rightful owners.

Ledger advised customers who bought a device from CryptoBilis in the last 90 days not to initialize new hardware and to be careful moving assets. Customers who already activated their wallets were told to consider shifting funds to a new Ledger device with a freshly generated recovery phrase.

The security group Security Alliance shared tanuki42’s findings on X and urged anyone who sent funds to the flagged addresses to contact its incident response team. It did not give its own loss estimate or confirm a cause. Separately, the onchain analytics account Onchain Lens reported that wallets linked to the suspected thefts moved about $270,000 in USDT and TRX to Binance, most of which then went to a Binance hot wallet, according to Coincentral.

The case adds to a heavy year for crypto security. Other large exploits in 2026 include a Bitget hack worth more than $350 million, a Liquid Network loss near $320 million, a Drift exploit at $295 million and a Kelp loss of $293 million, based on DefiLlama data cited by Coincentral.

Why it matters

Hardware wallets are marketed on the premise that a compromised exchange or software wallet cannot reach the user’s keys; this episode shifts the concern to the point of purchase, where a device can pass through a third party’s hands before it reaches a buyer. That matters for anyone who has bought a Ledger through a reseller rather than directly. It also shows the limits of issuer intervention: Tether can lock USDT, but it cannot touch Bitcoin moved on its own chain, so recovery will depend on cooperation across chains, exchanges and investigators.

What to watch

Ledger has said it will keep updating the public as its investigation progresses, so the key questions still open are how the devices were compromised, whether other distributors are affected, and whether the frozen USDT can be routed back to victims.

Disclaimer: This article is for information only and is not investment, financial or trading advice. Cryptocurrency prices are highly volatile. Always do your own research.

Sources: Crypto Briefing, Coincentral

CD

The CryptoNewsroom editorial desk covers Bitcoin, Ethereum, altcoins, DeFi, regulation and crypto markets. Editorial policy

Related stories