Buy now

Developing story, last reviewed 10 October 2026. Affected-device scope, loss estimates and the cause may all change. Ryder makes a competing hardware wallet, so weigh this accordingly. This is general security information, and it cannot diagnose your device, trace your funds or promise recovery.

The Ledger wallet drain: what to do about it starts with your own receipt rather than the headlines, because the warning Ledger issued covers a specific group of buyers. If you bought from the reseller CryptoBilis in the last 90 days, there are steps to take today. If you bought directly from Ledger, Ledger has said there are no reports involving devices bought through its own store, which is worth knowing before you move anything in a hurry.

1. With a Ledger wallet drain, what to do depends on where you bought it

Ledger's notice on 9 October, reported by The Block, told CryptoBilis buyers from the preceding 90 days not to begin setup if they had not already, and to move their assets to a new signer with a newly generated seed if they had. Ledger also asked the reseller to pause sales and shipments.

Pull up the receipt and check three things: who you bought from, when it arrived, and which model it is. That window is the scope of what has been reported, and a purchase outside it has not been cleared so much as left unmentioned. Current instructions are on Ledger's own site, and that is the version to trust over any summary, including this one.

2. Keep your recovery phrase out of the investigation

Anyone who can help you works from transaction hashes, public addresses, purchase records and a description of what happened. None of that requires your recovery phrase, and nobody legitimate will ask for it in a chat window, a form or an email.

Ledger states that one of its devices never arrives with a recovery phrase or a PIN already configured. If yours came with words printed on a card, shown in the instructions, or presented to you at any point before you finished setup yourself, treat that phrase as the attacker's and do not move anything into the accounts it generates.

3. Work out which kind of compromise you are dealing with

An unwanted token approval and an exposed recovery phrase are different problems with different fixes, and conflating them wastes the hours that matter. Ledger's own explanation of how crypto gets stolen is a reasonable primer: an approval lets a contract move the assets you permitted, while someone holding your keys can move everything.

Revoking an approval closes that permission and does nothing about a phrase somebody else has written down. Disconnecting a site in your wallet app is not the same as revoking what you granted it on chain. If the evidence points to your keys being known, loading the same words into a different device carries the exposure across with them.

4. Do not improvise the rescue

Where a theft is still running, automated sweepers watch the account and take what arrives, including the gas you send to pay for a rescue transaction. Ledger's incident guidance warns that topping up a draining account can add to the loss rather than enable an escape. People lose a second time this way.

If you suspect the device itself was altered, generating a fresh phrase on that same device does not give you a trustworthy destination. A new destination means different hardware, a phrase you watched being created, and a receiving address you checked on its screen. The right sequence depends on the network, the assets and what signing access you still have, so get help before you start sending.

5. Preserve the evidence without creating new problems

Keep the receipt, the seller correspondence, the packaging, the transaction hashes and a dated note of what happened and when, separating what you saw yourself from what you were told. Leave the device alone: opening, resetting or updating it can destroy the thing an examiner would need.

Bitquery's on-chain analysis of the incident lists the addresses the funds moved to, which is worth checking against your own outgoing transactions. If you were drained, the crypto security response group SEAL 911 and Ledger's official support are the two places to start. Anyone who contacts you first, promising to recover your coins for a fee, is the next attack rather than the solution.

Where a new wallet fits, and where it does not

Buying hardware is not an incident response plan, and we would rather say that plainly than sell into someone's worst week. If your phrase has been exposed, importing it into a Ryder One leaves it exposed, because the words are the access and changing the box around them changes nothing.

Once the immediate situation is under control, the question worth sitting with is what kind of backup you can keep working for years. A written phrase concentrates everything into one object that has to survive every house move and every flood. Our recovery documentation explains how we split a backup across separate pieces instead, so that losing any single one is survivable. That is a decision for a calm week, not this one.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More