A proposed class action lawsuit filed in the U.S. District Court for the Southern District of New York has thrust hardware wallet manufacturer Ledger into a new round of security controversies. The plaintiffs allege that Ledger’s access controls and subsequent disclosures surrounding its December 2023 security incident were inadequate, enabling malicious actors to exploit customer information and further enable crypto scams impersonating customer support.
The lawsuit targets the December 2023 events.
The lawsuit was filed on August 27. Plaintiff Douglas Kim filed the suit individually and on behalf of a proposed nationwide class, seeking at least $500 million in damages. The complaint alleges that Ledger failed to adequately protect customers' personal identifying information and data related to the security of crypto assets.
The core of the dispute centers on the Ledger Connect Kit, a software library used to connect hardware wallets to websites and decentralized applications. The complaint alleges that attackers gained access to an ex-employee’s NPMJS account through phishing, and that Ledger failed to promptly revoke access rights after the employee’s departure.
The attacker then uploaded a malicious version of the Connect Kit, tricking users into signing malicious transactions that transferred funds to addresses under their control. Ledger acknowledged at the time that the malicious code could have induced users to sign transactions, resulting in the transfer of wallet assets.
The plaintiff claims that nearly $1.95 million in assets were stolen.
The complaint states that the losses from the case extend beyond the direct impacts at the time of the Connect Kit incident. The plaintiffs argue that the attackers later used customer information—such as names, email addresses, and phone numbers—to impersonate Ledger or its affiliated personnel and carry out secondary scams, and that the company failed to provide adequate warnings to its customers.
Douglas Kim said he received a phone call in February 2025 from individuals impersonating Coincover and Ledger staff, claiming that his account information had been used in the Netherlands to register for Ledger Recover and that his assets were at risk. He then received an email seemingly from Ledger and was directed to a fraudulent website, where he was prompted to enter his recovery phrase to “reset the device.”
According to the complaint, two days later, Kim discovered that $1,948,074 in crypto assets had been stolen and have not been recovered. The plaintiffs allege that the attackers identified Kim’s Ledger account and triggered the relevant email using contact information exposed in the December 2023 incident.
The complaint also mentions the 2020 data breach.
The complaint also cites Ledger’s past security record, stating that the company experienced a large-scale data breach as early as 2020, affecting over 270,000 customers and exposing information including names, addresses, and phone numbers. The compromised data later surfaced on the dark web, and this incident previously led to a separate lawsuit.
The plaintiff alleges that Ledger failed to adequately enhance its security measures following prior incidents and downplayed the severity of the 2020 data breach and the December 2023 security incident. The complaint also lists seven causes of action, including violations of New York State business law, negligence, misrepresentation, and breach of fiduciary duty.
The proposed class action targets users in the United States who suffered financial losses, unauthorized transactions, or identity theft-related expenses due to the related data breach. The complaint states that the potential number of plaintiffs could reach thousands.
Additional information: Following the 2023 incident, Ledger stated that it would compensate affected users and work to disable the blind signing feature in Ethereum Virtual Machine applications. In February of this year, counterfeit letters and phishing websites impersonating Ledger continued to appear in the market.
