Ledger Now Faces A Class Action Demanding $500M For Its Breach

Murtuza Merchant
Murtuza Merchantpage_time_hoursAgo
Customer Douglas Kim seeks $500 million from Ledger over a December 2023 breach and a scam that drained his crypto wallet. (Image: Shutterstock)
Customer Douglas Kim seeks $500 million from Ledger over a December 2023 breach and a scam that drained his crypto wallet. (Image: Shutterstock)

Hardware wallet maker Ledger faces a proposed class action seeking at least $500 million over a December 2023 breach that one customer blames for a $1.9 million theft.

Key Points:

  • Douglas Kim filed a proposed class action against Ledger on Aug. 27 in Manhattan federal court, seeking at least $500 million.
  • The complaint blames a December 2023 Connect Kit compromise for an impersonation scam that cost him $1,948,074 in February 2025.
  • Ledger has sold 7 million units, and the filing assumes 3% of buyers, or 210,000 people, were affected.

Douglas Kim Details Connect Kit Breach

Douglas Kim filed the complaint on Aug. 27 in the U.S. District Court for the Southern District of New York, naming the French company Ledger SAS as the sole defendant. Law firm Ervin Cohen & Jessup brought the case for a proposed nationwide class of buyers.

The case centers on a security incident dated on or about Dec. 14, 2023, when attackers seized the NPMJS account used to publish Ledger Connect Kit.

That library links the company's hardware wallets to decentralized applications, and the attackers reached the account by phishing a former employee whose access was never revoked. Ledger acknowledged that lapse at the time.

Kim says a caller posing as a representative of Coincover reached him on Feb. 18, 2025, and warned that someone in the Netherlands had tried to enroll him in Ledger Recover. A second caller steered him to a lookalike website, where he entered his passphrase, and two days later he found $1,948,074 gone.

Also Read: XRP Ledger Gets BIS Test With 3-5 Second Data Publishing

Ledger Damages Claim Rests On Estimates

The filing lists seven causes of action. They include negligence, negligent misrepresentation, promissory estoppel and violations of New York General Business Law Sections 349 and 350, the state's deceptive practices and false advertising statutes. Kim also wants a declaration that the company breached New York's SHIELD Act by failing to notify affected New York residents within thirty days.

The $500 million figure is an estimate rather than a tally, drawn from Ledger's 7 million units sold and an assumption that 3% of buyers, or 210,000 people, were harmed. Kim's loss came 14 months after the breach, and the complaint links the two on information and belief, reserving the right to amend after discovery.

Ledger Security Record Draws Scrutiny

The Connect Kit exploit drained about $600,000 from people signing transactions blind on Ethereum (ETH) virtual machine applications, by the company's own count days later.

It pledged to make those users whole and moved to phase out blind signing.

Chief executive Pascal Gauthier said then that the problem sat with third-party applications, not Ledger hardware.

A 2020 breach had already exposed the records of more than 270,000 Ledger customers. That data circulated on black market channels, litigation over it is still running in the Northern District of California, and scammers have mailed Ledger-branded letters with QR codes to wallet owners as recently as April 2025.

Read Next: Full Sail Shuts Down After $91K Sui Hack Drains Three Vaults

Murtuza Merchant profile photo

Murtuza Merchant

Murtuza is a seasoned finance journalist with extensive experience covering cryptocurrencies and blockchain technology. He has contributed to Benzinga and Cointelegraph, among other publications, reporting on emerging trends, the regulatory landscape, and more. Find him at @murtuza_merc on Twitter and mmerchant001 on Telegram. Disclosure: Murtuza holds ATOM, AKT, TIA, INJ, and OSMO.

page_article_disclaimer
Ledger Now Faces A Class Action Demanding $500M For Its Breach | Yellow