Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
Ledger Users Drained of an Estimated $86M to $93M. Tether Froze $10M, and the Thief Moved Stablecoins Into USDD

On Friday, Oct. 9, Ledger owners in Indonesia, Malaysia and the Philippines opened their wallet apps and found zero balances. They had sent nothing. Roughly a day later, the size of the loss is still being counted, and the cause is still unexplained.
What Ledger has said
In an Oct. 9 statement, Ledger said it was investigating reports of customer losses tied to devices bought from CryptoBilis, an authorized reseller. CryptoBilis is listed in Ledger's reseller directory for Malaysia, Indonesia and the Philippines.
Ledger asked the reseller to pause all sales and shipments. It told customers who bought from CryptoBilis in the past 90 days not to initialize their devices if setup was not finished. Those who had already set up were told to consider moving their assets to a new Ledger signer with a fresh recovery phrase.
Ledger has not disclosed how many devices were affected. It has not said whether the cause was counterfeit hardware, physical tampering or something else.
How big the theft is
The totals depend on who is counting. The on-chain researcher Specter published ten collection addresses on Oct. 9 with losses above $86 million. Blockchain data firm Bitquery then traced $92.9 million from 311 wallets across five chains: Tron, Bitcoin, Ethereum, BNB Chain and Polygon. Bitquery says the gap comes from BNB Chain and Polygon wallets and five Tron addresses that no public list included.
Galaxy head of research Alex Thorn called a $91 million tally a "floor," since activity on BNB Chain, Base, Avalanche and other networks had not been fully traced. A fuller audit from Ledger is expected in the coming days.
By one breakdown, Tron took the heaviest losses, about $64.5 million across 276 victim addresses. Bitcoin addresses lost about $17.7 million. Ethereum-side losses were about $8.8 million. Bitquery's chain-by-chain split differs in its counts, which is typical this early in a trace.
Tether freezes, and the USDD workaround
Tether blacklisted more than 20 addresses linked to the stolen assets and froze about $10 million in USDT. That is a fraction of the haul.
The thief responded the same day. Tron records show USDT being converted into USDD, a stablecoin that sits outside Tether's freeze powers. Reports differ on the size: one tally has roughly 14.7 million USDT swapped for about 14.6 million USDD through SUN.io, while The Defiant cites a 2 million USDT conversion through USDD's stability module. Bitquery counts 15.1 million USDD in the thief's wallets.
On the numbers that hold across tallies, USDD that Tether cannot touch now exceeds the USDT it froze.
On Ethereum, funds went through Tornado Cash. Bitquery counts 1,254 ETH sent into the mixer and then traced out through Zcash to three new wallets holding 384 ETH and 2.1 million USDC. Another tally puts the Tornado Cash amount at about 430 ETH. Some funds reportedly reached Binance hot wallets, and security analysts are pressing the exchange to freeze them.
By two tallies, between $70.6 million and $73 million still sits in wallets the thief controls across Bitcoin, Ethereum and Tron.
A planned operation
Bitquery's trace points to a single actor holding the keys to every drained wallet. The firm says that actor ran 21 small test loops on Tron and 20 on Ethereum over about two weeks before the drain. On Tron, 30 wallets handed control to the thief's key, and 25 more signed the same approval three seconds apart eight minutes later.
Bitquery also found that six in 10 victim wallets were first funded inside Ledger's 90-day window, and more than eight in 10 were funded from June. The firm notes the chain cannot show where the keys leaked from.
The hardware question
One report, unverified, alleges that Ledger Nano X and Nano S Plus units sold by CryptoBilis carried spyware components that could read and transmit seed phrases. No confirmed evidence shows that implants caused the thefts.
Former Mt. Gox CEO Mark Karpelès has asked CryptoBilis to open some of its unsold Ledger units so their circuit boards can be inspected for implants. Ledger's own security documentation says its Genuine Check verifies a device's Secure Element but cannot necessarily detect physical modifications elsewhere in the hardware. A physically altered unit with an intact chip could therefore pass the check.
CryptoBilis also faces questions about ownership. Arravind Prabu, identified as the company's CEO, told users he is no longer part of CryptoBilis. He said he had signed a non-disclosure agreement with a Chinese buyer, which is why he had not disclosed the sale. His account has not been independently confirmed.
Two readings of what this means
Binance founder Changpeng Zhao wrote on X that, "Based on information so far, it seems to be localized to a supply chain attack with one vendor." He stressed Ledger's longstanding security reputation. Binance CEO Richard Teng said the exchange "stands ready to support the industry's collective efforts" to trace and recover the funds.
Lorenzo Valente, Ark Invest's head of crypto research, drew a harsher conclusion: "Never buy from a reseller, even if official. Self-custody will die very quickly if nothing is done." He called the story "pretty wild" if confirmed.
The theft follows a Coldcard hardware wallet exploit earlier this year that drained more than $100 million.
What comes next
Ledger's full audit of affected devices is expected in the coming days, and Thorn expects the total to rise. Whether Binance freezes the funds that reached its hot wallets, and whether Karpelès gets to inspect CryptoBilis's unsold inventory, will show how much of the money can be pulled back and how the keys were captured.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.