Legal Challenge Against Ledger
Ledger, the well-known manufacturer of cryptocurrency hardware wallets, is facing a significant legal challenge in the form of a proposed class action lawsuit. Filed by a customer named Douglas Kim in the U.S. District Court for the Southern District of New York on August 27, 2025, the suit claims that Ledger is liable for at least $500 million due to alleged lapses in security and disclosure following a security breach in December 2023.
Allegations of Inadequate Security
The lawsuit accuses the company of inadequately safeguarding customer information, failing to protect sensitive data related to cryptocurrency security, and neglecting to timely inform users about the extent of the December incident. This breach was linked to various financial losses and thefts due to hacker activity. According to Kim, miscreants exploited customer contact details to impersonate Ledger representatives, gaining access to private keys and cryptocurrency wallets.
Legal Claims and Breaches
The complaint brings forth several legal claims, including negligence and various breaches of New York General Business Law. It argues that Ledger has not only misrepresented its security protocols but also failed to take appropriate actions following earlier breaches. Included in the allegations is the December 2023 incident related to the Ledger Connect Kit, a software library that allows hardware wallets to interface with online services, which was wrongly accessed through a phishing attack aimed at a former employee’s credentials.
“The malicious code uploaded to Ledger’s NPMJS account allowed attackers to divert transactions to fraudulent addresses, resulting in substantial losses that were initially reported to be between $480,000 and $600,000.”
Following the incident, Ledger pledged to reimburse affected customers and planned to enhance its security practices by eliminating the feature of blind signing for specific decentralized applications. However, Kim contends the harm extends beyond direct financial losses, asserting that Ledger exposed personal identifiable information (PII) to thieves, thereby increasing the risk of identity theft.
Personal Impact and Continued Threats
The complaint details a disturbing incident from February 2025, where Kim himself was targeted in an impersonation scheme. After receiving a phone call allegedly from a Ledger representative warning him of potential registration of his details in the Netherlands, he was guided to a fake website that looked like Ledger’s official page. Under the impression that he was securing his assets, Kim entered sensitive information, which led to the theft of approximately $1.95 million in cryptocurrency.
Despite attempts to recover his assets, Kim has thus far been unsuccessful. The lawsuit points to a pattern of continued impersonation attacks on Ledger customers, including fake letters and phishing attempts aimed at retrieving recovery phrases to further compromise accounts.
Previous Breaches and Class Action Potential
This isn’t the first time Ledger has faced scrutiny over its security practices; an earlier breach in 2020 compromised data from over 270,000 customers, leading to widely available personal information on the dark web. Kim argues that the company failed to significantly enhance its security policies in the aftermath of this incident and has downplayed subsequent vulnerabilities.
The proposed class could include thousands of Ledger customers affected by the breach, with estimates of total damages potentially reaching hundreds of millions to even billions, should the court find the class action justified. Kim’s lawsuit seeks multiple forms of relief, including punitive damages, attorneys’ fees, and a jury trial, demanding accountability for the alleged failures that led to compromised security and financial harm.