How PeckShield Followed $3.89 Million Stolen from Ledger Wallet Straight into Binance’s Vaults—A Crypto Whodunit Unfolds
Ever wonder how nearly $4 million can quietly slip through the cracks of some of the most secure hardware wallets and suddenly pop up in Binance accounts on the Tron network? Sounds like the plot of a high-stakes thriller, right? Well, that’s exactly what blockchain watchdog PeckShield uncovered recently — a slick maneuver where $3.89 million drained from compromised Ledger devices made its way, traced step-by-step, into Binance deposit addresses. But hold on, this isn’t just a neat little heist; it’s only a slice of a mammoth $86 million-plus theft storm sweeping across hundreds of wallets and multiple blockchains, shaking up the crypto scene from Bitcoin to Ethereum and beyond. What makes this even more tangled is the middlemen wallets acting like traffic controllers, handling other users’ funds and muddying the waters for anyone trying to pin down the thief. Throw in Ledger’s halted sales via a shady reseller and Tether’s reactive freezes, and you’ve got a complex dance of theft, adaptation, and chase that could redefine what we think about crypto security. Curious about the full saga? Dive deeper and follow the trail yourself. LEARN MORE

Blockchain security firm PeckShield says roughly $3.89 million drained from compromised Ledger hardware wallets has been routed into Binance deposit addresses on the Tron network.
Following the money to Binance
PeckShield flagged the transfers on October 11, 2026. The movements happened over a two-day window.
The haul included approximately 3.685 million USDT and 615,000 TRX. Both moved on Tron before landing in deposit addresses linked to Binance.
There is a catch. Some of the stolen funds reportedly passed through intermediary wallets that also handle money belonging to other clients.
This also isn’t the first Binance-bound flow tied to the incident. Earlier on October 11, approximately $10 million in USDT had already been sent to Binance deposit addresses, according to the research findings.
A much bigger theft behind the headline number
The $3.89 million is a slice of a far larger draining campaign. Total losses are estimated between $86 million and $94.5 million.
More than 300 wallets were hit across several blockchains, including Bitcoin and Ethereum. Most of the damage, though, came in USDT on Tron.
The drains started on October 9, 2026, and moved quickly. The common thread among the biggest losses: devices purchased from CryptoBilis, a Southeast Asian reseller of Ledger hardware.
Ledger has paused sales through CryptoBilis. The company also confirmed unauthorized hardware modifications in at least one of the compromised devices.
Ledger has also advised affected users to adopt new security measures.
Tether freezes, and the attacker adapts
Tether moved to freeze addresses tied to the attack. The frozen funds total approximately $10 million in USDT.
The attacker appears to have anticipated that move. Some funds were swapped into USDD, a different stablecoin, in an apparent effort to dodge Tether’s freeze powers.
Mixers also entered the picture. These services blend funds from many users so outside observers struggle to tell which coins came from where.
What this means
For victims, the Binance deposits are the most hopeful development so far. A centralized exchange can, in principle, connect deposit addresses to account holders, which gives law enforcement and investigators a concrete next step.
The intermediary wallets are the obvious complication. If those addresses serve other customers too, any freeze or account action risks catching uninvolved users, and any claim that a specific account belongs to the attacker needs careful proof.
Tether’s roughly $10 million freeze shows how centralized controls can claw back part of a theft quickly. The attacker’s pivot to USDD shows the limit: a freeze only works on the token an issuer controls.
The key things to watch now: whether Binance or authorities act on the flagged deposit addresses, how much of the estimated $86 million to $94.5 million in losses can realistically be traced or frozen, and whether Ledger shares more about how many CryptoBilis devices were tampered with.




Post Comment