๐Ÿ“… Saturday, 5 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Ledger Digugat $500 Juta - Satu Akses Karyawan yang Lupa Dicabut Bikin Aset Pengguna Lenyap $1,9 Juta

Ledger Hit with $500M Lawsuit - Unrevoked Employee Access Blamed for $1.9M User Loss

Douglas Kim filed a class-action lawsuit against Ledger in the U.S. District Court for the Southern District of New York on August 27, 2026. He is seeking at least $500 million in damages after losing $1,948,074 in crypto assets to a scam rooted in a series of customer data breaches.

On February 18, 2025, Kim was contacted by an individual claiming to represent “Coincover” - purported to be an internal division of Ledger. The scammer directed him to a spoofed website and prompted him to input his secret passphrase, leading to his entire holdings being drained two days later on February 20, 2025.

The Dangers of Unrevoked Access

Kim alleges that the attackers targeted him using contact details leaked during Ledger’s December 2023 security incident. In that breach, hackers gained access to an NPMJS account belonging to a former Ledger employee via a phishing attack after the company failed to revoke the employee’s access permissions following their departure.

The attackers subsequently published a malicious version of the Ledger Connect Kit to redirect user transactions to attacker-controlled addresses. Ledger acknowledged the access control lapse, which resulted in direct losses between $480,000 and $600,000 from the Connect Kit exploit, and pledged to compensate affected victims.

Having been a Ledger user since 2017 and having purchased a Nano X model in New York City in 2021, Kim asserted seven legal claims. These include violations of New York General Business Law Sections 349 and 350, negligence, negligent misrepresentation, promissory estoppel, and breach of implied covenant.

A Trail of Past Data Breaches

Kim accuses the company of failing to safeguard customers’ personally identifiable information and failing to disclose the full scope of the 2023 incident. He contends that Ledger downplayed both breaches and failed to adequately enhance protections following its first major data leak in 2020.

In the 2020 incident, personal data from over 270,000 customers - including names, physical addresses, and phone numbers - was exposed and circulated across online black-market channels. The ripple effects of that breach persisted into February 2026, when scammers sent fraudulent physical letters bearing the Ledger logo containing QR codes directing recipients to phishing sites, mirroring an April 2025 campaign that also leveraged the historical leaked contact data.

Who Is Responsible for Buyers’ Identities?

Kim’s lawsuit argues that a hardware wallet provider’s obligations extend beyond manufacturing physical security devices. Ledger actively collects sensitive data such as names, email addresses, shipping addresses, phone numbers, payment details, product information, and order quantities. When the identities and home addresses of customers buying high-grade security devices are repeatedly exposed, the hardware’s built-in cryptographic protections ultimately fail to save victims.

Sourced from crypto.news.

Read also: Lenovo ID Flaw Left 5,000 Dropbox Accounts Exposed for 18 Days - No Password or Inbox Needed


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share