Ledger users reportedly drained of over $86 million in suspected exploit

1 hour ago 7

Hardware wallets exist for one reason: to keep your crypto safe when everything else goes wrong. On October 9, 2026, that promise reportedly took a serious hit.

On-chain analyst Specter (@SpecterAnalyst) flagged what appears to be a coordinated drain of funds from Ledger hardware wallet users. Cumulative losses are estimated at over $86 million, and some reports suggest the final figure could approach $100 million.

The cause has not been confirmed. Ledger has not said anything publicly.

What the on-chain trail shows

According to Specter’s analysis, the theft spans three major networks: Ethereum, TRON and Bitcoin. The analyst traced several theft addresses that received inflows from hundreds of victim wallets, pointing toward a coordinated campaign rather than a handful of unlucky individuals.

One Bitcoin address linked to the theft stands out: bc1qjqgwejnp8dc0x2938x9n9954hj97t82unx49dl. It has reportedly received over 211 BTC, and as of the report, those coins had not moved.

The big unanswered question: how

Right now, nobody outside the attacker knows exactly how the funds were taken. Discussion on X and Reddit has filled the vacuum with several theories.

The leading possibilities floated by the community include:

Device flaws: a vulnerability in Ledger’s hardware or firmware itself.

Seed phrase compromises: the seed phrase is the list of words that can recreate a wallet anywhere. If attackers obtained those words, the device itself becomes irrelevant.

Phishing: tricking users into signing malicious transactions or handing over their recovery words through fake apps or websites.

Ledger has not confirmed any vulnerability related to its devices or firmware and had stayed silent publicly as of the report date.

A rough year for hardware wallet security

Earlier this year, a fake Ledger Live app appeared on the Apple App Store. It drained approximately $9.5 million from more than 50 users before the scheme came to light.

Separately, a flaw in the Zilliqa Ledger app led to considerable losses for users holding ZIL.

In August 2026, a reported seed-generation flaw in Coldcard hardware wallets resulted in losses exceeding $88 million in Bitcoin. The reported Ledger losses of over $86 million sit in the same range as the Coldcard incident from just two months earlier.

What this means for users

Until the attack vector is confirmed, every user has to assume some level of risk. If the root cause turns out to be phishing or a compromised third-party app, the fix is behavioral: verify software sources, never type a seed phrase into a computer or phone, and scrutinize every transaction before signing. If it turns out to be a device or firmware problem, the response becomes far more complicated, potentially involving firmware updates or migrating funds to new wallets entirely.

Several things are worth watching from here. First, whether Ledger issues an official statement identifying the cause. Second, whether the attacker begins moving the 211 BTC sitting in the flagged Bitcoin address. Third, whether the loss estimate settles closer to $86 million or climbs toward the $100 million mark as more victims are identified.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article