Millions in Stolen Crypto Routed to Binance Amid Ledger Breach Fallout
Blockchain security firm PeckShield has identified approximately $3.89 million in cryptocurrency, drained from compromised Ledger hardware wallets, being funneled into Binance deposit addresses on the Tron network.
PeckShield flagged these transfers on October 11, 2026, noting that the movements occurred over a two-day period. The stolen assets included an estimated 3.685 million USDT and 615,000 TRX, both of which were moved on the Tron network before reaching Binance-linked deposit addresses.
A complicating factor in the investigation is that some of the stolen funds reportedly passed through intermediary wallets that also handle funds belonging to other clients. This is not the first instance of funds from this incident being directed to Binance; earlier on October 11, approximately $10 million in USDT had already been sent to Binance deposit addresses, according to research findings.
The $3.89 million represents a portion of a much larger draining campaign, with total estimated losses ranging between $86 million and $94.5 million. More than 300 wallets across multiple blockchains, including Bitcoin and Ethereum, were affected. However, the majority of the damage was inflicted through USDT on the Tron network.
The illicit drains commenced on October 9, 2026, and progressed rapidly. A common link among the most significant losses appears to be devices purchased from CryptoBilis, a Southeast Asian reseller of Ledger hardware.
Ledger Responds to Security Incident
In response to the breach, Ledger has suspended sales through CryptoBilis. The company has also confirmed unauthorized hardware modifications in at least one of the compromised devices and has advised affected users to implement new security measures.
Meanwhile, Tether has moved to freeze addresses associated with the attack, totaling approximately $10 million in USDT. However, the attacker appears to have anticipated this move, with some funds being swapped into USDD, a different stablecoin, in an apparent attempt to circumvent Tether’s freeze capabilities. The use of mixers, services that blend funds from multiple users to obscure their origin, has also been observed.
Implications for Recovery and Investigation
For victims, the routing of funds to Binance deposits offers a glimmer of hope. Centralized exchanges like Binance can, in principle, link deposit addresses to account holders, providing law enforcement and investigators with a clear path forward.
The presence of intermediary wallets, however, presents a significant challenge. If these addresses serve multiple customers, any freeze or account action risks impacting uninvolved users. Furthermore, any claim that a specific account belongs to the attacker will require rigorous proof.
Tether’s partial freeze of approximately $10 million highlights the effectiveness of centralized controls in recovering stolen assets. Conversely, the attacker’s pivot to USDD demonstrates the limitations of such measures, as freezes are only effective on tokens controlled by the issuer.
Key developments to monitor include potential actions by Binance or authorities regarding the flagged deposit addresses, the feasibility of tracing or freezing a substantial portion of the estimated $86 million to $94.5 million in losses, and further disclosures from Ledger regarding the extent of tampering with CryptoBilis devices.



