A hardware wallet maker built its entire brand promise on keeping crypto safe from hackers. Now Ledger is defending that promise in federal court. A newly filed Ledger data breach lawsuit accuses the company of failing to protect customer data after a December 2023 security incident, then failing to warn users before scammers allegedly drained nearly $2 million from one customer’s wallet. The proposed class action, filed in the Southern District of New York, seeks at least $500 million in damages on behalf of what could be thousands of affected customers nationwide.
Key takeaways
- Douglas Kim filed the proposed class action against Ledger on Aug. 27 in the U.S. District Court for the Southern District of New York, seeking at least $500 million.
- The complaint centers on a December 2023 breach involving malicious code hidden inside Ledger Connect Kit, a software library linking hardware wallets to decentralized apps.
- Kim claims scammers used stolen contact data to impersonate Ledger representatives and steal cryptoassets worth $1,948,074 from him in February 2025.
- The lawsuit also points to Ledger’s 2020 data breach, which exposed information belonging to more than 270,000 customers, as proof of a pattern of weak safeguards.
- The complaint brings seven causes of action, including violations of New York General Business Law Sections 349 and 350, negligence and misrepresentation.
Ledger Faces $500 Million Class Action Over December 2023 Breach
Ledger is facing a proposed class action that claims security and disclosure failures tied to the December 2023 incident left customers exposed to cryptocurrency theft and other financial harm. Douglas Kim filed the case individually and on behalf of a nationwide class, arguing that the hardware wallet maker did not adequately protect personally identifiable information or cryptocurrency security data belonging to its customers.
According to the filing, Kim alleges that Ledger failed to properly notify customers after the breach and never fully disclosed how far it reached. That failure, the lawsuit claims, allowed hackers to later exploit stolen contact details to pose as Ledger staff and gain access to victims’ wallets and private keys.
Scope of the Nationwide Class and Estimated Damages
The complaint proposes a nationwide class covering U.S. residents whose personal data, cryptoassets or crypto credentials were compromised because of the alleged breach and who suffered financial losses, unauthorized transactions or identity theft costs as a result. A separate New York subclass would cover customers whose purchases or account activity with Ledger took place in that state.
Kim’s own damages are estimated at roughly $2 million, while the filing projects collective class damages could reach at least $500 million and potentially climb into the billions depending on how many customers were affected and how large individual losses turn out to be. Those figures remain estimates put forward by the plaintiff and have not been verified or established by any court.
How the December 2023 Security Incident Unfolded
The breach at the heart of this Ledger data breach lawsuit traces back to Ledger Connect Kit, a software library that lets hardware wallets interact with websites and decentralized applications. Attackers allegedly obtained unauthorized entry into the NPMJS account belonging to a previous Ledger staff member via a phishing attack, then used that access to slip malicious code into the software.
Once inside the compromised library, the attackers uploaded a tainted version of Connect Kit capable of redirecting transactions to wallets they controlled by tricking users into approving fraudulent signing requests. Ledger publicly confirmed at the time that the malicious code could induce users to sign transactions that drained their funds. crypto.news previously reported on the phishing attack that gave hackers access to the former employee’s account. Ledger CEO Pascal Gauthier said at the time that the incident was confined to third-party applications and that Ledger’s own hardware wallets were unaffected. Estimated losses from the Connect Kit exploit at the time ranged between roughly $480,000 and $600,000, and Ledger later pledged to reimburse affected users while phasing out blind signing for Ethereum-based decentralized apps.
Ledger’s Access Control Failure and Malicious Code
Central to the lawsuit is an admission Ledger itself made after the incident: the company had failed to properly revoke the former employee’s NPMJS access once their employment ended. That access-control lapse, the complaint argues, is what allowed the attackers to slip malicious software into a widely used tool without detection. The new complaint goes further than the losses reported right after the Connect Kit compromise, alleging that hackers also accessed and later exploited customer personal data — including names, email addresses and phone numbers — without Ledger giving customers sufficient warning.
Plaintiff Alleges Nearly $1.95 Million Stolen Through Impersonation Scam
Kim, who bought his first Ledger device around 2017 and picked up a Nano X in New York City in 2021, says he became the target of an elaborate impersonation scheme more than a year after the original breach. On Feb. 18, 2025, he received a call from someone claiming to represent Coincover, described to him as a department within Ledger. The caller warned him that someone in the Netherlands had tried to register for Ledger Recover using his information and that his cryptoassets were at risk.
A second caller then contacted Kim posing as another Ledger representative and told him to check his email to verify the first caller’s legitimacy. Kim says he received an email that appeared to come from Ledger. The complaint alleges, on information and belief, that the attackers pulled his contact details from data exposed in the December 2023 incident to identify him as a Ledger customer and trigger that email — an allegation Kim has reserved the right to amend once he obtains Ledger’s breach forensics through discovery.
The fake representative then directed Kim to a website designed to mimic Ledger’s own services and instructed him to enter his confidential recovery passphrase to “reset” his device. Kim complied and received what he believed was a replacement passphrase. Two days later, he checked his holdings and found that cryptoassets worth $1,948,074 had vanished. He has not recovered any of it.
Kim’s case is not an isolated data point. Ledger customers have continued to face impersonation attempts well after his loss — in February 2026, scammers sent fake Ledger letters directing recipients to phishing sites built to harvest wallet recovery phrases. Similar mail-based scams surfaced in April 2025, reportedly relying on data leaked in Ledger’s earlier 2020 breach to send branded letters with QR codes leading to phishing pages.
Lawsuit Cites 2020 Breach and Lists Seven Legal Claims
To back its claims of chronic security shortcomings, the complaint leans heavily on Ledger’s history. A 2020 breach exposed information belonging to more than 270,000 customers, including names, physical addresses and phone numbers — data that later surfaced on black-market channels online. That earlier incident is the subject of separate litigation in the Northern District of California.
Kim’s filing argues Ledger never sufficiently tightened its security practices after that 2020 episode and accuses the company of downplaying the severity of both breaches. The complaint notes that Ledger requires customers to hand over names, email addresses, delivery addresses, phone numbers, payment details and order information just to buy its products — making the company’s advertised security promises, including encryption, employee training, role-based authentication, two-factor authentication, continuous monitoring and independent security testing, central to the case. Those representations, the lawsuit contends, were misleading because Ledger allegedly failed to implement adequate protections and did not address foreseeable risks that followed its earlier incidents.
This isn’t the only security question Ledger has fielded recently. In August, the company said an Ethereum signing flaw had already been patched before another security firm publicly disclosed it, with Ledger’s chief technology officer, Charles Guillemet, saying users on updated firmware and apps were protected and noting no independently verified thefts tied to that specific bug. Days later, Ledger pushed back against claims it had been hacked after OneKey’s security team reproduced a transaction-substitution flaw — but using an outdated version of Ledger’s Ethereum application that the company said had already been fixed in newer releases.
Damages and Relief Sought
The complaint brings seven causes of action altogether, including violations of New York General Business Law Sections 349 and 350, negligence, negligent misrepresentation, promissory estoppel and breach of the implied covenant of good faith and fair dealing. Kim’s filing also seeks a court declaration that Ledger violated New York’s SHIELD Act. The requested relief spans actual, compensatory, statutory, treble and punitive damages, plus attorneys’ fees and costs. Kim has demanded a jury trial.
Why this matters beyond one plaintiff’s losses: the case tests how far a hardware wallet company’s duty to warn customers extends once stolen data starts circulating among scammers, and it puts a dollar figure — potentially reaching into the billions if the class grows large enough — on what happens when a crypto security brand’s own infrastructure becomes the point of failure.
FAQ
What triggered the class action lawsuit against Ledger?
The lawsuit stems from a December 2023 data breach involving malicious code in Ledger Connect Kit, unauthorized access via a former employee’s compromised account, and subsequent crypto theft.
How much is the plaintiff seeking in damages?
The plaintiff, Douglas Kim, and the proposed class seek at least $500 million in total damages for security failures, financial losses, and related claims.
What security failures does the lawsuit allege?
The lawsuit alleges Ledger failed to revoke access for a former employee, did not properly notify customers after the breach, and had inadequate safeguards following previous breaches.
What kind of attacks were customers subject to after the breach?
Customers faced phishing, impersonation scams using stolen contact data, and loss of crypto through fraudulent schemes impersonating Ledger representatives.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.





Be the first to comment