Ledger Faces $500M Class Action Over Alleged Security Failures and Crypto Theft
Ledger, the hardware wallet manufacturer, is facing a proposed class action lawsuit seeking at least $500 million in damages over alleged security and disclosure failures tied to a December 2023 breach. The complaint, filed on August 27 in the U.S. District Court for the Southern District of New York by plaintiff Douglas Kim, accuses Ledger of negligence, deceptive practices, and failing to protect customer data leading to nearly $1.95 million in stolen cryptocurrency from Kim alone.
The lawsuit centers on a December 2023 incident involving Ledger’s Connect Kit, a software library used to link hardware wallets with decentralized applications. Attackers compromised a former employee’s NPMJS account via phishing, exploiting Ledger’s failure to revoke access post-employment. The hackers then deployed a malicious version of the Connect Kit, tricking users into approving transactions that drained their wallets. While Ledger initially estimated losses at $480,000–$600,000, the company later committed to reimbursing affected users and announced plans to phase out blind signing for Ethereum-based dApps.
Kim’s complaint alleges that the breach exposed customer personally identifiable information (PII), including names, emails, and phone numbers, which scammers later used to impersonate Ledger representatives. In February 2025, Kim received a fraudulent call from individuals posing as Ledger’s Coincover department, warning of a security threat and directing him to a phishing site. After entering his passphrase, Kim lost $1.95 million in cryptoassets none of which have been recovered.
The lawsuit also highlights Ledger’s 2020 data breach, which exposed over 270,000 customers’ PII, as evidence of a pattern of inadequate security. Kim argues that Ledger’s public claims about encryption, employee training, and monitoring were misleading, given its failure to address foreseeable risks. The complaint includes seven causes of action, including violations of New York’s SHIELD Act and General Business Law, negligence, and breach of good faith.
The proposed nationwide class covers U.S. customers whose PII or cryptoassets were compromised, with a subclass for New York-based victims. Kim estimates collective damages could exceed $500 million, potentially reaching billions, depending on the number of affected users. The lawsuit seeks actual, compensatory, statutory, treble, and punitive damages, along with attorneys’ fees and a jury trial.
Source: https://crypto.news/ledger-sued-for-500m-over-alleged-data-breach-and-crypto-theft/
Ledger cybersecurity rating report: https://www.rankiteo.com/company/ledgerhq
"id": "LED1788441237",
"linkid": "ledgerhq",
"type": "Breach",
"date": "2/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'U.S. customers (proposed '
'nationwide class), New '
'York-based subclass, 270,000+ '
'(from 2020 breach)',
'industry': 'Cryptocurrency, Cybersecurity, FinTech',
'location': 'France (global operations)',
'name': 'Ledger',
'size': 'Large (specific revenue/size not provided)',
'type': 'Hardware Wallet Manufacturer'}],
'attack_vector': 'Phishing (compromised NPMJS account), Malicious Software '
'Update (Connect Kit)',
'customer_advisories': 'Warnings about phishing risks following the breach; '
'Instructions to verify communications from Ledger.',
'data_breach': {'data_exfiltration': 'Yes (used for follow-up phishing '
'attacks)',
'number_of_records_exposed': '270,000+ (from 2020 breach), '
'Unknown (2023 breach)',
'personally_identifiable_information': ['Names',
'Emails',
'Phone numbers'],
'sensitivity_of_data': 'High (PII, financial/crypto '
'credentials)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Crypto wallet credentials']},
'date_detected': '2023-12',
'date_publicly_disclosed': '2023-12',
'description': 'Ledger, the hardware wallet manufacturer, is facing a '
'proposed class action lawsuit seeking at least $500 million '
'in damages over alleged security and disclosure failures tied '
'to a December 2023 breach. The complaint accuses Ledger of '
'negligence, deceptive practices, and failing to protect '
'customer data, leading to nearly $1.95 million in stolen '
'cryptocurrency from the plaintiff alone. The breach involved '
'a compromised Connect Kit software library, which attackers '
'used to deploy malicious code and drain user wallets. The '
'lawsuit also highlights a 2020 data breach as evidence of a '
'pattern of inadequate security.',
'impact': {'brand_reputation_impact': 'Significant (allegations of '
'negligence, deceptive practices, and '
'repeated security failures)',
'customer_complaints': 'Fraudulent calls impersonating Ledger '
'representatives, Phishing attacks '
'targeting customers',
'data_compromised': 'Personally Identifiable Information (PII) '
'including names, emails, phone numbers, and '
'crypto wallet credentials',
'financial_loss': '$1.95M (plaintiff alone), $480K–$600K (initial '
'Ledger estimate), $500M+ (proposed class action '
'damages)',
'identity_theft_risk': 'High (PII exposed, used for phishing and '
'fraud)',
'legal_liabilities': 'Class action lawsuit ($500M+ sought), '
'Violations of New York SHIELD Act and '
'General Business Law, Potential regulatory '
'fines',
'operational_impact': 'Loss of customer trust, Reimbursement '
'commitments, Phasing out of blind signing '
'for Ethereum-based dApps',
'payment_information_risk': 'High (crypto wallet credentials '
'compromised, direct theft of assets)',
'systems_affected': 'Ledger Connect Kit (software library), User '
'wallets linked to decentralized applications'},
'initial_access_broker': {'entry_point': 'Compromised NPMJS account (former '
'employee)',
'high_value_targets': 'Ledger Connect Kit users, '
'Crypto wallet holders'},
'investigation_status': 'Ongoing (lawsuit filed, no resolution yet)',
'lessons_learned': 'Failure to revoke former employee access can lead to '
'supply chain attacks; Inadequate monitoring of software '
'updates can enable malicious deployments; Exposed PII can '
'be weaponized for follow-up phishing attacks; Public '
'claims about security must align with actual practices to '
'avoid legal liability.',
'motivation': 'Financial gain',
'post_incident_analysis': {'corrective_actions': ['Reimbursement for affected '
'users',
'Phasing out blind signing '
'for Ethereum-based dApps',
'Investigation into breach '
'(specific measures not '
'detailed)'],
'root_causes': ['Failure to revoke former employee '
'access',
'Inadequate monitoring of software '
'updates',
'Lack of blind signing protections',
'Repeated security failures (2020 '
'breach)']},
'recommendations': 'Implement strict access revocation policies for former '
'employees; Enhance monitoring of third-party software '
'libraries and dependencies; Adopt blind signing '
'protections for decentralized applications; Improve '
'customer education on phishing risks; Conduct regular '
'security audits to prevent repeated breaches.',
'references': [{'date_accessed': '2025-08-27',
'source': 'Class Action Complaint (Douglas Kim v. Ledger)'},
{'source': 'Ledger Public Statements'}],
'regulatory_compliance': {'legal_actions': 'Class action lawsuit ($500M+ '
'sought), Seven causes of action '
'(negligence, breach of good '
'faith, etc.)',
'regulations_violated': ['New York SHIELD Act',
'New York General Business '
'Law']},
'response': {'communication_strategy': 'Public disclosure of breach, Customer '
'advisories (though plaintiff alleges '
'inadequate protection against '
'follow-up phishing)',
'containment_measures': 'Removal of malicious Connect Kit '
'version, Investigation into breach',
'incident_response_plan_activated': 'Yes (reimbursement '
'commitments, investigation)',
'remediation_measures': 'Reimbursement for affected users, '
'Phasing out blind signing for '
'Ethereum-based dApps'},
'stakeholder_advisories': 'Ledger committed to reimbursing affected users; '
'Phasing out blind signing for Ethereum-based '
'dApps.',
'threat_actor': 'Unknown (likely financially motivated cybercriminals)',
'title': 'Ledger Faces $500M Class Action Over Alleged Security Failures and '
'Crypto Theft',
'type': 'Data Breach, Phishing, Supply Chain Attack, Fraud',
'vulnerability_exploited': 'Failure to revoke former employee access, Lack of '
'blind signing protection, Inadequate monitoring '
'of software updates'}