Ledger SAS, the world’s leading hardware cryptocurrency wallet manufacturer, is facing a proposed class-action lawsuit in the U.S. District Court for the Southern District of New York, with t
Ledger SAS, the world’s leading hardware cryptocurrency wallet manufacturer, is facing a proposed class-action lawsuit in the U.S. District Court for the Southern District of New York, with the plaintiff alleging the company’s alleged failure to properly disclose a 2023 data breach directly enabled a sophisticated social engineering attack that drained nearly $2 million from his crypto wallets.
The lawsuit seeks at least $500 million in damages on behalf of a potential class of up to 210,000 affected users.
How the Alleged Theft Unfolded
Plaintiff Douglas Kim filed the complaint on August 27, 2026. According to the filing, Kim purchased his first Ledger hardware wallet in 2017 and later upgraded to a Ledger Nano X in 2021 — establishing a customer relationship spanning nearly a decade before the alleged theft occurred.
The complaint states that in February 2025, Kim was contacted by individuals claiming to represent Coincover and Ledger. The callers reportedly told him there had been an attempted enrollment in Ledger Recover, the company’s optional key-recovery service, and directed him to a website where he was instructed to provide sensitive information. According to the lawsuit, that information allegedly allowed the attackers to gain access to his cryptocurrency holdings. Kim discovered on February 20, 2025, that approximately $1.95 million had been transferred out of his wallets. He has reportedly not recovered any of the stolen assets.
Tracing the Attack Back to a 2023 Security Incident
The lawsuit’s central legal theory connects Kim’s individual loss to a broader security failure at Ledger dating back to December 2023, when the company’s Connect Kit — a software library that allows Ledger hardware wallets to interface with decentralized applications — was compromised. According to the complaint, attackers gained access through a former Ledger employee and used the compromised software library to facilitate fraudulent transactions across the platform.
The filing further alleges, on information and belief, that customer data exposed during that 2023 incident was subsequently used to specifically target Kim in the February 2025 social engineering scheme — providing attackers with the contact information and contextual detail needed to convincingly impersonate Ledger and Coincover representatives.
A Pattern the Lawsuit Says Goes Back Even Further
The complaint frames the 2023 incident as part of a longer pattern of security failures at Ledger, pointing back to a separate 2020 data breach that exposed personal information belonging to approximately 270,000 customers, including names, email addresses, phone numbers, and other personally identifiable information. According to the lawsuit, Ledger failed to timely and fully disclose the scope of the 2023 breach specifically, and that the leaked data from both incidents ultimately circulated on dark web marketplaces, where it could be purchased and used by scammers to craft convincing impersonation attacks against Ledger’s customer base.
The complaint characterizes this history in stark terms:
“Ledger has demonstrated a disturbing pattern of negligent, reckless, and irresponsible behavior with regard to its security posture and a callous disregard for its obligations to the privacy of its customers’ [personally identifiable information].”
The Legal Claims
Kim’s lawsuit brings multiple causes of action against Ledger, including violations of New York General Business Law Sections 349 and 350 — the state’s core consumer protection statutes governing deceptive business practices — alongside claims of negligence, negligent misrepresentation, promissory estoppel, and breach of the covenant of good faith and fair dealing. The complaint also demands a jury trial.
The Scale of the Proposed Class
Kim is seeking to represent a nationwide class of Ledger users who may have been similarly affected. The complaint estimates the proposed class could encompass up to 210,000 people, with total damages across the class potentially reaching at least $500 million — a figure that, if the class were certified and the plaintiffs prevailed, would represent one of the largest consumer damages awards in the cryptocurrency hardware industry’s history.
Important Legal Caveats
It’s worth emphasizing that, as with any newly filed complaint, none of the allegations against Ledger have been proven in court, and the proposed class has not yet been certified by the presiding judge. The case remains in its early stages within the Southern District of New York, and Ledger has not yet filed a formal public response to the specific allegations at the time of this reporting.
Why This Case Matters for the Broader Crypto Security Landscape
This lawsuit lands amid a broader wave of concern about physical and social engineering attacks targeting hardware wallet customers specifically. Similar incidents involving both Ledger and competitor Trezor have surfaced in recent months, including fraudulent physical mail scams and data exposure incidents tied to third-party shipping and fulfillment partners rather than the wallet manufacturers’ own core infrastructure.
What distinguishes the Ledger case is the legal argument being tested: that a company’s delayed or incomplete breach disclosure can itself become the basis for liability when leaked data is later weaponized in downstream fraud, rather than liability being limited to the original breach alone.
For the broader hardware wallet industry, the outcome of this case could set an important precedent regarding how quickly and thoroughly companies are legally required to disclose security incidents involving customer data — particularly in an industry where the entire value proposition rests on customers trusting that their private keys and personal information remain secure.
If Kim’s theory succeeds, it may push hardware wallet manufacturers toward faster, more comprehensive breach notifications, alongside more aggressive proactive warnings to customers about phishing and impersonation risks whenever a data exposure incident occurs, rather than treating disclosure as a purely discretionary or minimized corporate communications decision.