Ledger faces a class action lawsuit of at least $500 million alleging inadequate security measures and disclosure violations.
Ledger is facing a proposed class action lawsuit claiming at least $500 million. The lawsuit alleges that the company had serious security flaws and failed information disclosure in a security incident that occurred in December 2023, causing customers to suffer theft of cryptocurrency and other financial losses.
Plaintiff Allegations: Scammers used leaked information to pretend to be officials to steal assets
Plaintiff Douglas Kim alleges that fraudsters used stolen customer information to pretend to be Ledger representatives and subsequently stole nearly $1.95 million in cryptocurrency. The indictment cited Ledger's data breach in 2020 that affected more than 270,000 customers as evidence of the company's long-term poor data protection.
The lawsuit filed seven claims, including actual damages, compensatory damages, statutory damages, triple damages, and punitive damages.
On August 27, Douglas King filed the case in the U.S. District Court for the Southern District of New York, prosecuting separately and on behalf of a proposed national-wide collective. The indictment alleges that the hardware wallet maker failed to adequately protect customers 'personally identifiable information (PII) and cryptocurrency security data. Jin filed the lawsuit personally and on behalf of the proposed class action.
King alleges that Ledger failed to properly notify customers after the December 2023 security incident and failed to fully disclose the severity of the incident. The lawsuit alleges that the hackers then used the customer's contact information to impersonate a Ledger representative and gained access to the customer's cryptocurrency wallet and private key.
The seven claims listed in the indictment include claims under sections 349 and 350 of the New York State General Commerce Code, as well as charges of negligence, negligent misrepresentation, estoppel and breach of implied good faith and fair dealing obligations.
Core of the lawsuit: Focus on the December 2023 security incident
The December 2023 incident involved the "Ledger Connect Kit", a software library used to connect hardware wallets to websites and decentralized applications.
The indictment states that the attacker obtained access to the NPMJS account of a former Ledger employee through a phishing attack. Documents show that Ledger failed to correctly revoke the employee's access rights after he left the company. At the time, Ledger admitted the access control failure, saying that the former employee's access to NPMJS had indeed not been properly revoked.
Once in the account, the attacker uploaded a malicious version of the Ledger Connect Kit that redirected transactions to addresses controlled by the attacker by inducing users to approve malicious transactions. Ledger has publicly admitted that the malware could trick users into signing transactions that result in their wallets being emptied.
There were previous reports that a former Ledger employee was attacked by phishing, and the attacker then used the stolen permissions to release malicious code. At the time, Ledger CEO Pascal Gauthier said the incident was limited to third-party applications and the Ledger hardware wallet itself was not affected. Estimated losses at the time ranged from $480,000 to $600,000. Subsequently, Ledger said it would refund affected users and announced plans to phase out blind sign-off functionality for Ethereum Virtual Machine (EVM) decentralized applications.
The new lawsuit goes beyond the direct damage caused by the Connect Kit vulnerability. King alleges that the hackers accessed and used Ledger customers 'personally identifiable information, including names, email addresses and phone numbers, and Ledger failed to provide customers with sufficient warnings about the incident.
Plaintiff details: Almost $1.95 million in cryptocurrency was stolen
Jin first purchased a Ledger hardware wallet around 2017 and purchased a Nano X model in New York City in 2021. He claims he later became the target of a fake Ledger scam.
According to the indictment, on February 18, 2025, King received a phone call claiming to be from Coincover, who claimed to be a division of Ledger. The caller told King that someone tried to use his information to register the Ledger Recover service in the Netherlands and that his crypto assets could be at risk.
Later, another person posing as a Ledger representative contacted King and asked him to check the email to prove the caller's identity. King received an email that appeared to be from Ledger. The indictment alleges that based on information and beliefs, the attacker used customer contact information derived from the December 2023 incident to identify Kim as a Ledger customer and triggered the email. King reserves the right to amend the charge after obtaining Ledger's leaked forensic investigation and incident response records through the forensic process.
According to the lawsuit, the alleged representative directed Kim to visit a website designed to mimic Ledger's services and instructed him to enter confidential mnemonic words to reset the device. Jin Zhao did it and obtained a string of what he believed was a new mnemonic words.
Two days later, King checked his position and found that $1,948,074 worth of crypto assets were stolen, but he had not recovered any assets.
Ledger customers continue to face impersonation attempts. In February 2026, scammers sent forged Ledger letters directing recipients to phishing websites designed to collect wallet recovery mnemonics. A similar physical mail attack was also reported in April 2025, when scammers reportedly used leaked data in 2020 to send Ledger branded letters with QR codes to direct customers to websites that requested recovery mnemonics.
indictment points to Ledger's 2020 data breach
King's lawsuit uses Ledger's early security history to support his claim that protection is insufficient. According to the indictment, a 2020 leak affected more than 270,000 Ledger customers, exposing information including names, physical addresses and phone numbers. These data were later circulated on black market channels. A separate lawsuit against that leak has been filed in the Federal District Court for the Northern District of California.
The new indictment accuses Ledger of failing to adequately improve its security practices after that incident and accuses the company of downplaying the impact of the early leaks and the December 2023 incident.
King believes Ledger's security statement is particularly important because the company requires customers to provide information when selling products. The indictment lists various customer data that Ledger collected, including names, email addresses, shipping addresses, phone numbers, payment details, product information and order amounts.
According to statements cited in the indictment, Ledger had promoted its security measures including encryption, employee training, role-based certification, two-factor certification, continuous system monitoring, and independent security testing.
The lawsuit alleges that the statements were misleading because Ledger failed to implement adequate measures to protect customer information and did not adequately address foreseeable risks after previous cybersecurity incidents.
Security issues draw attention again
Security issues surrounding Ledger resurfaced in August when Ledger said it had fixed an Ethereum signature vulnerability before another security company publicly disclosed it. Charles Guillemet, Ledger's chief technology officer, said users running updated firmware and applications were protected and no independent verification theft cases were reported at the time related to this specific vulnerability.
A few days later, Ledger denied claims it had been hacked after One Key's security team recreated the transaction replacement vulnerability using an outdated version of the Ledger Ethereum application. Ledger said protections have been added to the new version of the app.
Class action seeks at least $500 million in damages
King proposes to create a nationwide collective that includes U.S. individuals who suffer financial loss, unauthorized transactions, or mitigation costs of identity theft as a result of an alleged data breach that resulted in damage to personally identifiable information, cryptoassets, cryptocurrency, or credentials. The indictment stated that the number of people in the proposed collective could reach thousands.
A separate New York State sub-group will cover eligible customers whose transactions at Ledger (including purchasing products or services or creating Ledger accounts) occur in New York State.
The indictment estimates Kim's losses at approximately US$2 million and claims that the total collective losses could reach at least US$500 million, which could amount to billions of dollars if the number of customers affected was large and the personal losses were huge. These figures are only estimates proposed by the plaintiff and have not yet been confirmed by the court.
King's filing sought to declare Ledger guilty of violating the New York State SHIELD Act and sections 349 and 350 of the General Business Code, as well as finding him guilty of negligence and negligent misrepresentation. The relief sought includes actual, compensatory, statutory, triple and punitive damages, as well as attorney fees and costs.
The plaintiff has requested a jury trial.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
ETH