Ledger Sued For $500M Over Data Breach And Crypto Theft

15 min read
4 views
Sep 3, 2026

A hardware wallet brand built on trust now faces a $500 million class action. The claim is not only about a 2023 software compromise. It is about what happened after names and phone numbers allegedly reached scammers.

Financial market analysis from 03/09/2026. Market conditions may have changed since publication.

I still remember the first time someone told me a hardware wallet was the grown-up way to hold crypto. The pitch was simple. Keys stay offline. The company sells a box, not a promise to babysit your coins. That story sold millions of devices. It also created a kind of quiet confidence that, looking back, may have been a little too neat. A new proposed class action now asks a harder question. If the device is supposed to be the fortress, what happens when the customer list around that fortress is treated like an afterthought?

Why A $500 Million Claim Changes The Conversation

In late August, a plaintiff named Douglas Kim filed a proposed class action in the U.S. District Court for the Southern District of New York. The filing seeks at least $500 million and leaves the door open to a much larger figure if more customers come forward. The core allegation is not that a steel gadget suddenly stopped being a steel gadget. It is that poor security and incomplete disclosure around a December 2023 incident left people exposed to impersonation, drained wallets, and the expensive cleanup that follows identity-style attacks in crypto.

Kim is suing individually and on behalf of a proposed nationwide class. He says the company failed to adequately protect customer personally identifiable information and cryptocurrency security data. He also says customers were not given a clear enough warning after the 2023 event, which made later social-engineering attacks easier to pull off. That combination is what turns a software scare into a courtroom story.

I’ve found that crypto legal fights often split into two camps. One camp talks about code. The other talks about people. This complaint lives in the second camp. The plaintiff is not arguing that a chip spontaneously leaked a seed. He is arguing that contact details, trust, and delayed candor created a runway for thieves.

What The Complaint Actually Accuses The Company Of Doing

The filing lists seven causes of action. Among them are claims under New York General Business Law Sections 349 and 350, negligence, negligent misrepresentation, promissory estoppel, and breach of the implied covenant of good faith and fair dealing. That mix matters. Consumer-protection statutes can travel farther than a narrow contract claim. Negligence language lets a jury hear about foreseeable risk. Promissory estoppel language tries to pin the company to the security story it sold.

Kim wants declarations that the company violated New York’s SHIELD Act and the two General Business Law sections mentioned above. He also wants findings of negligence and negligent misrepresentation. The requested relief includes actual, compensatory, statutory, treble, and punitive damages, plus attorneys’ fees and costs. He has demanded a jury trial. In plain English, this is not a polite letter asking for a credit-monitoring coupon.

The lawsuit treats customer data as part of the security product, not as leftover paperwork from an online checkout page.

That framing is the part I keep coming back to. Hardware wallet marketing has always drawn a bright line between the device and everything else. The complaint tries to smudge that line. If you collect names, emails, phone numbers, delivery addresses, payment details, product information, and order amounts, you are not only selling a USB-shaped vault. You are holding a map of who owns one.

The December 2023 Incident At The Center Of The Case

The December 2023 event involved Ledger Connect Kit, a software library used to connect hardware wallets with websites and decentralized applications. According to the complaint, attackers gained access to the NPMJS account of a former employee through a phishing attack. The filing says the company had not properly revoked that former employee’s access after employment ended. The company itself acknowledged an access-control failure at the time.

Once inside the account, the attackers uploaded a malicious version of the library. That version could redirect transactions to addresses they controlled by inducing users to approve bad transactions. Public statements at the time accepted that the malicious software could trick people into signing transfers that drained wallets. The company also said the incident was isolated to third-party applications and that the hardware wallets themselves remained unaffected.

Estimates in the weeks after the exploit put immediate losses somewhere between roughly $480,000 and $600,000. The company later said it would reimburse affected users and announced plans to phase out blind signing for Ethereum virtual machine decentralized applications. If the story had stopped there, this might have remained a painful but contained software incident. The new lawsuit insists the story did not stop there.

Kim alleges that hackers accessed and used customer PII, including names, email addresses, and phone numbers. He says the company failed to give customers a sufficient warning about the incident and did not fully disclose its scope. That alleged gap is the bridge between a library compromise and a later phone call that sounds official enough to make a careful person panic.


How The Plaintiff Says Nearly $1.95 Million Disappeared

Kim first bought a hardware wallet around 2017 and purchased a Nano X in New York City in 2021. That timeline is useful. It paints him as a long-time customer, not a tourist who bought a device last week after seeing a viral clip. On February 18, 2025, he received a call from someone claiming to represent Coincover, which the caller presented as a department inside the company. The caller allegedly said someone in the Netherlands had tried to register for a recovery-related service using his information and that his assets could be at risk.

A second person then contacted him while posing as another company representative and asked him to check his email as proof that the caller was legitimate. Kim received what appeared to be an email from the brand. The complaint alleges, on information and belief, that attackers used customer contact information originating from the December 2023 incident to identify him as a customer and trigger that email. He reserved the right to amend that allegation after seeing forensic and incident-response records in discovery. That reservation is lawyer-speak for: we think this is the source, and we intend to prove it with the company’s own files.

The purported representative directed him to a website designed to resemble official services and instructed him to enter his confidential passphrase to reset the device. He complied and was given what he believed was a replacement passphrase. Two days later he checked his holdings and found cryptoassets valued at $1,948,074 gone. He has not recovered any of those assets. That number is specific enough to sting. It is also large enough to explain why a single plaintiff’s story can anchor a half-billion-dollar class theory.

Was he supposed to know better? Plenty of people will say yes. Never type a seed. Never trust a cold call. Never follow a link from a stranger. All of that is true. It is also true that social engineering works because it borrows the company’s voice. A fake department name. A fake urgency about a foreign registration. A fake email that arrives on cue. The complaint is betting that a jury will see those details as foreseeable, not as a random act of God.

Impersonation Did Not End With One Phone Call

Customers have continued to face impersonation attempts well after 2023. In February 2026, scammers sent fake branded letters directing recipients to phishing websites designed to collect wallet recovery phrases. Similar physical mail attacks were reported in April 2025, when scammers reportedly used data leaked in 2020 to send branded letters containing QR codes that led to sites seeking recovery phrases. Paper in the mailbox is an old trick. In crypto it still works because a letter feels heavier than a text.

That persistence is part of why this case feels larger than one exploit. A software library can be patched. A leaked address book keeps paying dividends for years. If names and phone numbers circulate, the attack surface is no longer a Git package. It is every kitchen table where someone owns a device and fears losing everything in one afternoon.

  • Phone calls that invent an internal department and a foreign registration attempt
  • Follow-up contacts that ask the victim to “verify” an email
  • Lookalike websites that request a confidential passphrase
  • Physical letters and QR codes that collect recovery phrases

None of those methods require breaking a secure element. They require a list, a script, and a person who believes the brand is calling to help. Perhaps the most interesting aspect is how ordinary the sequence looks once you write it down. Urgency. Authority. Proof. Then the seed. It is almost boring. Boring attacks scale.

The 2020 Breach Is Being Used As A Pattern, Not A Footnote

Kim’s lawsuit reaches back to 2020. That earlier incident, according to the complaint, affected more than 270,000 customers and exposed information that included names, physical addresses, and phone numbers. The data later appeared on black-market channels. Separate litigation over that breach was brought in the Northern District of California. The new complaint says the company failed to improve its security practices enough after that event and downplayed both the earlier breach and the December 2023 incident.

This is a classic pattern argument. One incident can be described as bad luck. Two incidents, years apart, get described as culture. I am not saying a court will accept that leap. I am saying plaintiffs always try it when a brand’s public identity is security itself. If you sell peace of mind, your history becomes evidence.

The complaint also argues that security representations were especially important because customers must provide information to buy the products. The company has advertised encryption, employee training, role-based authentication, two-factor authentication, continuous system monitoring, and independent security testing, according to statements reproduced in the filing. The lawsuit calls those representations deceptive because, in the plaintiff’s view, the company failed to implement adequate measures and did not address foreseeable risks after earlier incidents.

When a company markets itself as the adult in the room, every leftover admin account becomes a story about broken promises.

In my experience, access revocation is the unglamorous part of security that companies underfund until it explodes. Former employees. Old vendor accounts. Package-registry tokens that nobody remembered. The 2023 narrative, as told in the complaint, is almost embarrassingly familiar. Someone left. The key stayed live. An attacker used it. Users paid the price in signed transactions they thought were routine.

Later Security Headlines Did Not Help The Mood

Security questions resurfaced in August when the company said an Ethereum signing flaw was fixed before another security firm publicly disclosed the issue. A company executive said users running updated firmware and applications were protected, and no independently verified thefts linked to that specific vulnerability had been reported at the time. Days later, the company rejected claims it was hacked after another wallet team reproduced a transaction-substitution flaw using an outdated version of an Ethereum application. The company said protections had already been added in a newer application version.

Those later episodes are not the same as the 2023 library compromise. They still matter to public trust. Customers do not keep a tidy timeline in their heads. They hear “flaw,” “outdated app,” “not a hack,” and “update your firmware” in the same month they hear about a class action. The emotional result is fatigue. Fatigue is dangerous in self-custody because tired people either ignore warnings or overreact to the wrong warning.

Who Would Be In The Proposed Class

Kim proposes a nationwide class covering U.S. individuals whose PII, cryptoassets, cryptocurrencies, or crypto credentials were compromised as a result of the alleged data breach and who suffered financial losses, unauthorized transactions, or identity-theft mitigation costs. The complaint says the proposed class could number in the thousands. A separate New York subclass would cover qualifying customers whose transactions with the company, including product or service purchases or the creation of accounts, occurred in New York.

The filing estimates Kim’s damages at approximately $2 million and claims collective class damages could reach at least $500 million, potentially running into billions depending on how many customers were affected and how large individual losses were. Those figures are plaintiff estimates. A court has not established them. That distinction is easy to lose in headlines and important to keep in the body of any serious write-up.

Piece of the caseWhat the plaintiff allegesWhy it matters
2023 software incidentAccess not revoked, malicious library publishedShows a concrete operational failure
Customer contact dataNames, emails, and phones used by scammersLinks software event to later thefts
2020 historical breachMore than 270,000 customers exposedSupports a pattern theory
Individual lossAbout $1.95 million stolen after a 2025 callGives the class a human face
Requested reliefAt least $500 million plus broader damagesRaises the stakes for settlement talks

Class certification is its own mountain. Courts ask whether the stories are similar enough to travel together. A person who lost six figures after a scripted phone call is not automatically in the same factual box as a person who only spent money on credit monitoring. The complaint tries to sweep both into one group by focusing on compromised information and resulting harm. Defense lawyers will almost certainly try to split those experiences apart.

Self-Custody Was Never Supposed To Mean Self-Defense Against The Brand

Hardware wallets exist because exchanges get hacked and people get tired of asking permission to move their own money. The social contract is blunt. You accept the burden of a seed phrase. The vendor accepts the burden of not turning your checkout data into a hunting list. When that bargain wobbles, the whole category feels less adult than advertised.

I keep thinking about the phrase “reset the device.” That is the moment the complaint becomes painfully human. A person who bought a product to avoid trusting strangers is asked, in a moment of fear, to type the one secret the product was built to protect. The attacker did not need a zero-day in silicon. The attacker needed the customer to believe the company was already inside the problem.

There is a lesson here that does not require picking a winner in court. Security theater and security operations are not the same thing. Training slides, 2FA badges, and independent-testing slogans look great on a product page. Revoking a former employee’s package-registry access is dull. Dull work is usually the work that would have prevented the headline.

What Customers Should Take From The Allegations Without Panic

No filing is a verdict. Allegations have to be proven. Discovery can shrink a story as easily as it can enlarge one. Still, people who hold keys on a device can treat this case as a reminder rather than a doom scroll.

  1. Treat every inbound call about your wallet as hostile until proven otherwise through a channel you initiated.
  2. Never enter a recovery phrase on a website, even one that looks official and arrives after a “verification” email.
  3. Assume leaked names and phone numbers can be reused for years, including in physical mail.
  4. Keep firmware and applications current, because outdated versions become the easy exhibit in every later debate.
  5. Separate the security of the device from the security of the account you used to buy the device.

That last point is the one people skip. They obsess over seed storage and forget the inbox attached to the order confirmation. Scammers love that gap. They do not need the metal. They need the relationship around the metal.

If someone already typed a phrase during a panic call, the honest next step is to treat the old wallet as burned and move remaining assets, if any remain, with extreme care. I will not walk through tactics that belong in a recovery guide. The point for this article is simpler. Once a seed is spoken or typed into a stranger’s page, the legal case and the coins are different problems. One may take years. The other is often already over.

Why The Legal Theories Were Written This Way

New York consumer statutes are attractive because they target deceptive practices and false advertising in everyday language. Negligence asks whether a company failed to use reasonable care. Negligent misrepresentation asks whether security claims were sloppy rather than merely optimistic. Promissory estoppel tries to hold a company to assurances customers relied on. The implied covenant claim argues that even if the fine print is tight, there is still a duty not to hollow out the deal.

Why stack seven theories instead of one clean count? Because different facts survive different motions to dismiss. A judge might trim advertising claims and leave negligence. Or the reverse. Plaintiffs build a menu. Defendants try to send the whole menu home. That is not cynicism. That is civil procedure.

The SHIELD Act angle is about data protection duties under New York law. If a court entertains that theory, the case becomes less about crypto exceptionalism and more about ordinary information-security obligations. I think that is smart pleading. Juries understand a leftover admin account. They do not always understand a JavaScript library on a package registry.

The Money Number Is A Strategy, Not A Scoreboard

Half a billion dollars is a siren. It is also an opening bid dressed as an estimate. Class damages in data cases often start life as a multiply-the-class-by-a-scary-average exercise. Crypto makes the math wilder because one customer can lose nearly two million while another loses nothing but time. That spread will haunt certification and any settlement model.

Treble and punitive damages are there to signal alleged recklessness. They also raise the temperature in negotiations. Companies hate uncertainty more than they hate a defined check. Plaintiffs know that. So the complaint talks about billions as a ceiling and $500 million as a floor. Readers should hear those words as advocacy, not as an appraised value of the dispute.

How the public number is being built:
  Individual alleged loss near $2 million
  Proposed class in the thousands
  Combined estimate of at least $500 million
  Possible upside into the billions if losses stack

Would a trial ever spit out a clean billion-dollar verdict? Maybe not. Could the existence of the filing change how hardware-wallet firms talk about customer databases? That seems more likely. Litigation is a branding event whether anyone likes that fact or not.

Trust, Marketing, And The Awkward Middle Ground

Hardware wallet ads love words like encryption, monitoring, and independent testing. Those words are not fake by default. They can still be incomplete. A product can have a hardened chip and a sloppy offboarding process. A company can be right that the device was not “hacked” and still be wrong, in a plaintiff’s telling, about how it handled the human layer around the device.

That middle ground is where this case will live if it survives early motions. Not “the vault melted.” Not “customers were perfect.” Something messier. A vendor that collected rich customer records, suffered prior exposure, then faced a 2023 access-control failure that, according to the complaint, left people easier to impersonate.

I’ve found that crypto users forgive bugs faster than they forgive tone. “Your hardware is fine” can be technically accurate and emotionally tone-deaf if people are getting letters with QR codes. Communication is part of incident response. The complaint says disclosure was late and incomplete. If that claim sticks even in part, expect every future advisory from the sector to get longer and more anxious. That may be healthy. It may also train people to ignore warnings. Both outcomes can be true.

What Happens Next In A Case Like This

The next chapters are predictable even if the ending is not. The company will have a chance to respond. There may be a motion attacking the pleadings. If the case proceeds, discovery becomes the real battlefield: incident reports, access logs, notification drafts, customer-support tickets about impersonation, and the forensic narrative of 2023. Kim has already flagged that he wants those records before he locks in every theory about how scammers found him.

Class certification would then decide whether this stays a large story or becomes one person’s expensive nightmare. Settlement can arrive at almost any point. Crypto companies sometimes settle to end a branding bleed. They also sometimes fight to protect a security narrative. Either path will be read as an admission by somebody on the internet. That is the tax of doing business in public markets for trust.

For everyone watching from outside the docket, the useful question is smaller than $500 million. Did the industry learn that customer PII is part of wallet security? Or will the next product launch still treat the shop database as a marketing asset and the seed phrase as the only sacred object? I know which answer I want. I am less sure which answer we will get.


A Closing Thought For Anyone Who Still Sleeps Better With A Device In A Drawer

Self-custody remains one of the few honest ideas in this market. You hold the keys. You accept the terror that comes with that privilege. A lawsuit does not erase that idea. It does force a more adult version of it. The box in the drawer is only half the product. The other half is every email, phone number, shipping label, and support script orbiting that box.

If the allegations in this filing are proven, the expensive lesson is already on the table. If they are not, the cheaper lesson is still worth keeping. Nobody serious should ever ask you for a recovery phrase. Not on a call. Not in a letter. Not after an email that arrived at the perfect second. The people who want that phrase are not trying to reset your device. They are trying to finish a story that started the moment your name joined a list.

That is why this case, even before a single juror is seated, already changed the conversation. It took a familiar software incident and asked whether the real leak was human context. Names. Numbers. Trust. The boring stuff. The stuff that does not fit on a product render and still decides whether a $1.95 million balance is there on Thursday morning.

I don't measure a man's success by how high he climbs but by how high he bounces when he hits the bottom.
— George S. Patton
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>