Ledger faced a $500 million class action lawsuit over the 2023 security incident.

icon币界网
Share
AI summary iconSummary
A class-action lawsuit seeking $500 million in damages has been filed against Ledger in the U.S. District Court for the Southern District of New York, citing a 2023 security incident tied to CFT regulations. Led by Douglas Kim, the lawsuit alleges that Ledger’s failure to secure customer data enabled phishing attacks, resulting in Kim losing $1.95 million. The breach occurred via malicious code uploaded through a former employee’s NPMJS account. Risk-on assets experienced volatility as the lawsuit underscored persistent security concerns. A separate data leak in 2020 affected over 270,000 users.
CoinDesk reports:

A proposed class action lawsuit filed in the U.S. District Court for the Southern District of New York has thrust hardware wallet manufacturer Ledger into a new round of security controversies. The plaintiffs allege that Ledger’s access controls and subsequent disclosures surrounding its December 2023 security incident were inadequate, enabling malicious actors to exploit customer information and further enable crypto scams impersonating customer support.

The lawsuit targets the December 2023 events.

The lawsuit was filed on August 27. Plaintiff Douglas Kim filed the suit individually and on behalf of a proposed nationwide class, seeking at least $500 million in damages. The complaint alleges that Ledger failed to adequately protect customers' personal identifying information and data related to the security of crypto assets.

The core of the dispute centers on the Ledger Connect Kit, a software library used to connect hardware wallets to websites and decentralized applications. The complaint alleges that attackers gained access to an ex-employee’s NPMJS account through phishing, and that Ledger failed to promptly revoke access rights after the employee’s departure.

The attacker then uploaded a malicious version of the Connect Kit, tricking users into signing malicious transactions that transferred funds to addresses under their control. Ledger acknowledged at the time that the malicious code could have induced users to sign transactions, resulting in the transfer of wallet assets.

The plaintiff claims that nearly $1.95 million in assets were stolen.

The complaint states that the losses from the case extend beyond the direct impacts at the time of the Connect Kit incident. The plaintiffs argue that the attackers later used customer information—such as names, email addresses, and phone numbers—to impersonate Ledger or its affiliated personnel and carry out secondary scams, and that the company failed to provide adequate warnings to its customers.

Douglas Kim said he received a phone call in February 2025 from individuals impersonating Coincover and Ledger staff, claiming that his account information had been used in the Netherlands to register for Ledger Recover and that his assets were at risk. He then received an email seemingly from Ledger and was directed to a fraudulent website, where he was prompted to enter his recovery phrase to “reset the device.”

According to the complaint, two days later, Kim discovered that $1,948,074 in crypto assets had been stolen and have not been recovered. The plaintiffs allege that the attackers identified Kim’s Ledger account and triggered the relevant email using contact information exposed in the December 2023 incident.

The complaint also mentions the 2020 data breach.

The complaint also cites Ledger’s past security record, stating that the company experienced a large-scale data breach as early as 2020, affecting over 270,000 customers and exposing information including names, addresses, and phone numbers. The compromised data later surfaced on the dark web, and this incident previously led to a separate lawsuit.

The plaintiff alleges that Ledger failed to adequately enhance its security measures following prior incidents and downplayed the severity of the 2020 data breach and the December 2023 security incident. The complaint also lists seven causes of action, including violations of New York State business law, negligence, misrepresentation, and breach of fiduciary duty.

The proposed class action targets users in the United States who suffered financial losses, unauthorized transactions, or identity theft-related expenses due to the related data breach. The complaint states that the potential number of plaintiffs could reach thousands.

Additional information: Following the 2023 incident, Ledger stated that it would compensate affected users and work to disable the blind signing feature in Ethereum Virtual Machine applications. In February of this year, counterfeit letters and phishing websites impersonating Ledger continued to appear in the market.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.