On-chain analyst Specter has traced what appears to be a coordinated drain of Ledger hardware wallets that reportedly cost users over $86 million across Ethereum, TRON and Bitcoin. The cause remains unconfirmed, and Ledger has not issued a public statement.
On-chain analyst Specter has flagged what appears to be a coordinated drain of funds from Ledger hardware wallet users, with cumulative losses estimated at over $86 million and some reports suggesting the figure could approach $100 million. Ledger has not said anything publicly, and the cause has not been confirmed.
Theft traced across three networks
Specter's analysis shows the theft spans three major networks: Ethereum, TRON and Bitcoin, with several theft addresses receiving inflows from hundreds of victim wallets. That pattern points toward a coordinated campaign rather than a handful of unlucky individuals.
One Bitcoin address linked to the theft has reportedly received over 211 BTC, and as of the report, those coins had not moved.
How the funds were taken remains unclear
Nobody outside the attacker knows exactly how the funds were taken, and discussion on X and Reddit has filled the vacuum with theories. The leading possibilities include a vulnerability in Ledger's hardware or firmware, a compromised seed phrase that lets an attacker recreate a wallet elsewhere, or phishing that tricks users into signing malicious transactions or handing over recovery words through fake apps or websites. Ledger has not confirmed any vulnerability tied to its devices or firmware.
Part of a rough year for wallet security
Earlier this year, a fake Ledger Live app on the Apple App Store drained approximately $9.5 million from more than 50 users before the scheme came to light. Separately, a flaw in the Zilliqa Ledger app led to considerable losses for ZIL holders. In August 2026, a reported seed-generation flaw in Coldcard hardware wallets resulted in losses exceeding $88 million in Bitcoin, putting the Ledger incident in the same range as that episode from two months earlier.
Until the attack vector is confirmed, users have to assume some level of risk. If phishing or a compromised third-party app turns out to be the cause, the fix is behavioral: verify software sources, never type a seed phrase into a computer or phone, and scrutinize every transaction before signing. A device or firmware problem would be harder to resolve, potentially requiring firmware updates or migrating funds to new wallets entirely.
Three things are worth watching from here: whether Ledger issues an official statement on the cause, whether the attacker moves the 211 BTC sitting in the flagged address, and whether the loss estimate settles near $86 million or climbs toward $100 million as more victims are identified.
Source: Crypto Briefing
Trading involves risk.