{"id":37444,"date":"2026-09-03T08:22:08","date_gmt":"2026-09-03T08:22:08","guid":{"rendered":"https:\/\/bitunikey.com\/news\/ledger-sued-for-500m-over-alleged-data-breach-and-crypto-theft\/"},"modified":"2026-09-03T08:22:34","modified_gmt":"2026-09-03T08:22:34","slug":"ledger-sued-for-500m-over-alleged-data-breach-and-crypto-theft","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/ledger-sued-for-500m-over-alleged-data-breach-and-crypto-theft\/","title":{"rendered":"Ledger sued for $500M over alleged data breach and crypto theft"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Ledger has been hit with a proposed class action seeking at least $500 million over allegations that poor security and disclosure failures tied to a December 2023 incident exposed customers to cryptocurrency theft and other financial losses.<\/p>\n<div id=\"cn-block-summary-block_559e0902ccaed358784395acd944ee37\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Ledger faces a proposed class action seeking at least $500 million over alleged security and disclosure failures tied to a December 2023 incident.<\/li>\n<li>Plaintiff Douglas Kim alleges scammers used compromised customer information to impersonate Ledger representatives before stealing nearly $1.95 million in crypto.<\/li>\n<li>The complaint cites Ledger\u2019s 2020 breach affecting more than 270,000 customers as part of an alleged pattern of inadequate data safeguards.<\/li>\n<li>The lawsuit brings seven causes of action and seeks actual, compensatory, statutory, treble and punitive damages.\u00a0<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>The complaint, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/storage.courtlistener.com\/recap\/gov.uscourts.nysd.671431\/gov.uscourts.nysd.671431.1.0.pdf\" target=\"_blank\" rel=\"nofollow\">filed<\/a> by Douglas Kim in the U.S. District Court for the Southern District of New York on Aug. 27, accuses the hardware wallet maker of failing to adequately protect customer personally identifiable information and cryptocurrency security data. Kim brought the case individually and on behalf of a proposed nationwide class.<\/p>\n<p>Kim alleges that Ledger failed to properly notify customers after the December 2023 security incident and did not fully disclose its scope. The lawsuit claims hackers later used customer contact information to impersonate Ledger representatives and gain access to customers\u2019 cryptocurrency wallets and private keys.<\/p>\n<p>The complaint brings seven causes of action, including claims under New York General Business Law Sections 349 and 350, negligence, negligent misrepresentation, promissory estoppel and breach of the implied covenant of good faith and fair dealing.<\/p>\n<h2 class=\"wp-block-heading\">Ledger lawsuit centers on December 2023 security incident<\/h2>\n<p>The December 2023 incident involved Ledger Connect Kit, a software library used to connect hardware wallets with websites and decentralized applications.<\/p>\n<p>The complaint says attackers gained access to the NPMJS account of a former Ledger employee through a phishing attack. Ledger had failed to properly revoke the former employee\u2019s access after their employment ended, according to the filing.<\/p>\n<p>Ledger acknowledged the access control failure at the time, stating that the former employee\u2019s NPMJS access had not been properly revoked.<\/p>\n<p>Once inside the account, the attackers uploaded a malicious version of Ledger Connect Kit that could redirect transactions to addresses they controlled by inducing users to approve malicious transactions. Ledger publicly acknowledged that the malicious software could trick users into signing transactions that drained their wallets.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>crypto.news previously reported that a former Ledger employee was phished before an attacker used the compromised access to publish malicious code. Ledger CEO Pascal Gauthier said at the time that the incident was isolated to third party applications and that Ledger hardware wallets remained unaffected.<\/p>\n<p>Estimates at the time put losses from the Connect Kit exploit between roughly $480,000 and $600,000. Ledger later said it would reimburse affected users and announced plans to phase out blind signing for Ethereum virtual machine decentralized applications.<\/p>\n<p>The new lawsuit goes beyond losses reported immediately after the Connect Kit compromise. Kim alleges that hackers accessed and used Ledger customer PII, including names, email addresses and phone numbers, and that Ledger failed to provide customers with sufficient warning about the incident.<\/p>\n<h2 class=\"wp-block-heading\">Plaintiff says scammers stole nearly $1.95 million in crypto<\/h2>\n<p>Kim, who first bought a Ledger hardware wallet around 2017 and purchased a Nano X in New York City in 2021, says he later became the victim of a Ledger impersonation scheme.<\/p>\n<p>On Feb. 18, 2025, Kim received a call from someone claiming to represent Coincover, which the caller presented as a department within Ledger, according to the complaint. The caller allegedly told Kim that someone in the Netherlands had attempted to register for Ledger Recover using his information and that his cryptoassets could be at risk.<\/p>\n<p>A second person then contacted Kim while posing as another Ledger representative and asked him to check his email as proof that the caller was legitimate.<\/p>\n<p>Kim received what appeared to be an email from Ledger, the filing says. The complaint alleges, on information and belief, that the attackers used customer contact information originating from the December 2023 incident to identify him as a Ledger customer and trigger the email. Kim reserved the right to amend that allegation after obtaining Ledger\u2019s breach forensics and incident response records through discovery.<\/p>\n<p>The purported representative directed Kim to a website designed to resemble Ledger\u2019s services and instructed him to enter his confidential passphrase to reset the device, according to the lawsuit. Kim complied and was given what he believed was a replacement passphrase.<\/p>\n<p>Two days later, Kim checked his holdings and discovered that cryptoassets valued at $1,948,074 had been stolen, the complaint alleges. He has not recovered any of those assets.<\/p>\n<p>Ledger customers have continued to face impersonation attempts. In February 2026, scammers sent fake Ledger letters directing recipients to phishing websites designed to collect wallet recovery phrases.<\/p>\n<p>Similar physical mail attacks were reported in April 2025, when scammers reportedly used data leaked in 2020 to send Ledger branded letters containing QR codes that directed customers to websites seeking their recovery phrases.<\/p>\n<h2 class=\"wp-block-heading\">Complaint points to Ledger\u2019s 2020 data breach<\/h2>\n<p>Kim\u2019s lawsuit uses Ledger\u2019s earlier security history to support its allegations of inadequate safeguards.<\/p>\n<p>A 2020 breach affected more than 270,000 Ledger customers, according to the complaint, exposing information that included names, physical addresses and phone numbers. The data later became available on black market channels online. Litigation over that breach was separately brought in the Northern District of California.<\/p>\n<p>The new complaint alleges Ledger failed to sufficiently improve its security practices following that incident and accuses the company of downplaying both the earlier breach and the December 2023 incident.<\/p>\n<p>Kim argues that Ledger\u2019s security representations were particularly important because the company requires customers to provide information when buying its products. The complaint lists names, email addresses, delivery addresses, phone numbers, payment details, product information and order amounts among the customer data collected by Ledger.<\/p>\n<p>Ledger has advertised security measures including encryption, employee training, role based authentication, two factor authentication, continuous system monitoring and independent security testing, according to statements reproduced in the complaint.<\/p>\n<p>The lawsuit alleges those representations were deceptive because Ledger failed to implement adequate measures to protect customer information and did not sufficiently address foreseeable risks after earlier cybersecurity incidents.<\/p>\n<p>Security questions around Ledger resurfaced in August when the company said an Ethereum signing flaw was fixed before another security company publicly disclosed the issue. Ledger CTO Charles Guillemet said users running updated firmware and applications were protected, while no independently verified thefts linked to that specific vulnerability had been reported at the time.<\/p>\n<p>Days later, Ledger rejected claims it was hacked after OneKey\u2019s security team reproduced a transaction substitution flaw using an outdated version of Ledger\u2019s Ethereum application. Ledger said protections had already been added in a newer application version.<\/p>\n<h2 class=\"wp-block-heading\">Class action seeks at least $500 million<\/h2>\n<p>Kim proposes a nationwide class covering U.S. individuals whose PII, cryptoassets, cryptocurrencies or crypto credentials were compromised as a result of the alleged data breach and who suffered financial losses, unauthorized transactions or identity theft mitigation costs. The complaint says the proposed class could number in the thousands.<\/p>\n<p>A separate New York subclass would cover qualifying customers whose transactions with Ledger, including product or service purchases or the creation of Ledger accounts, occurred in New York.<\/p>\n<p>The complaint estimates Kim\u2019s damages at approximately $2 million and claims collective class damages could reach at least $500 million, potentially running into billions of dollars depending on the number of customers affected and the size of individual losses. Those figures are estimates advanced by the plaintiff and have not been established by the court.<\/p>\n<p>Kim\u2019s filing seeks declarations that Ledger violated New York\u2019s SHIELD Act and General Business Law Sections 349 and 350, along with findings of negligence and negligent misrepresentation. The requested relief includes actual, compensatory, statutory, treble and punitive damages, as well as attorneys\u2019 fees and costs.<\/p>\n<p>The plaintiff has demanded a jury trial.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Ledger has been hit with a proposed class action seeking at least $500 million over allegations that poor security and disclosure failures tied to a December 2023 incident exposed customers&hellip;<\/p>\n","protected":false},"author":1,"featured_media":37445,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-37444","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=37444"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37444\/revisions"}],"predecessor-version":[{"id":37446,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37444\/revisions\/37446"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/37445"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=37444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=37444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=37444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}