• security
  • news
  • 56 min

Ledger Faces $500M Class-Action Lawsuit Over 2023 Hack

The case links the compromise of Connect Kit to subsequent thefts from users’ wallets through fake “Ledger employees.”

0

nft.eu
  • rating +26
  • subscribers 113

On August 27, 2026, a class-action lawsuit was filed in New York against hardware wallet maker Ledger. The plaintiff is seeking at least $500M for himself and other class members. They accuse the company of failing to properly protect customer data and concealing the full scope of the December 2023 incident.

Attackers gained access to the npm account of a former Ledger employee whose access the company failed to revoke after the employee left. npm is a package registry that websites use to pull code for connecting wallets. Using that account, the attackers published a fake version of Connect Kit, a library that connects hardware wallets to browsers and dApps. Users signed transactions that transferred their funds to addresses controlled by the attackers.

In February 2025, Kim received a call from people claiming to be Ledger employees. They told him that someone was trying to connect Ledger Recover, the company’s wallet recovery service, to his wallet and demanded that he urgently reset his device. To do so, Kim visited the website they provided and entered his seed phrase. Two days later, $1.95M was stolen from his wallet. The funds could not be recovered.

The lawsuit alleges that customers’ contact information, including Kim’s, was leaked as a result of the 2023 incident. According to the plaintiffs, this opened the door to targeted calls and emails from people posing as official Ledger representatives. They claim Ledger failed to warn users promptly and fully — just as it had after a 2020 data breach that affected 270,000 people.

Read Also:

This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.

0

Comments

0