Hardware wallet company **Ledger** has been pulled into a class-action lawsuit seeking at least $500 million (about 680 billion won) in damages related to a security incident that occurred in December 2023. The customer who filed the complaint attributes the theft of assets worth about $1.9 million to the fallout from this incident.
Key points
Customer Douglas Kim filed a class-action lawsuit against “Ledger” in the U.S. District Court for the Southern District of New York on August 27, seeking at least $500 million in damages.
The complaint cites the December 2023 “Connect Kit” account breach as the backdrop for phishing losses totaling $1,948,074 that occurred in February 2025.
Ledger has sold roughly 7 million wallets to date, and the plaintiffs estimated that about 210,000 people (3%) among them would have been harmed.
“The Connect Kit hack led to scam-related victim losses”
Douglas Kim submitted a complaint to the U.S. District Court for the Southern District of New York on August 27, naming Ledger SAS, a French corporation, as the sole defendant. The law firm Ervin Cohen & Jessup is leading the case in the form of a proposed class action on behalf of Ledger buyers across the United States.
The lawsuit focuses on a security incident that occurred around December 14, 2023. At the time, the attackers compromised an NPMJS account that was distributing the Ledger “Connect Kit.”
The Connect Kit is a library that connects Ledger hardware wallets with decentralized applications (DApps). The attackers exploited accounts of a former employee who had left Ledger, by phishing them, and then took advantage of the fact that the permissions were not revoked in time. Ledger has also acknowledged this management lapse at the time.
According to Kim’s claims, on February 18, 2025, a phone call came in impersonating a Coincover representative. The caller warned that “someone in the Netherlands tried to sign up for Ledger Recover,” and then the second impersonation call directed Kim to a similar website. Kim entered the recovery passphrase on that site, and two days later discovered that assets worth $1,948,074 had disappeared from the account.
Related article: XRP Ledger to be put on the BIS test bench by publishing data at 3–5 second intervals
The $500 million damages calculation is an “estimate”
In this lawsuit, the plaintiffs raised a total of seven causes of action. Specifically, these include negligence, negligent misrepresentation, promissory estoppel, and violations of New York General Business Law Sections 349 and 350 (prohibiting deceptive business practices and false or inflated advertising).
Kim is also seeking a confirmatory ruling that Ledger violated New York State’s “SHIELD Act” by failing to notify New York residents affected within 30 days after the data breach.
The $500 million figure presented as damages is not an accounting of actual harm; rather, it is an estimate based on an assumption that 210,000 people (3% of 7 million wallets sold by the ledger) would have been victims. Kim’s personal loss occurred about 14 months after the security incident. The complaint states that, “based on information available and reasonable inference,” it argues a causal link between the two events, while reserving the right to amend the allegations after future discovery procedures.
Ledger’s security history back on the hot seat
According to Ledger, in attacks that exploited a Connect Kit vulnerability at the time, about $600,000 was stolen from users running applications based on the Ethereum (ETH) virtual machine that performed “blind signing.”
Ledger said it would compensate all victims and also disclosed that it would phase out the blind signing feature.
At the time, Pascal Gauthier, CEO, argued that, “The root cause of the problem was a third-party application, not a security flaw in the Ledger hardware itself.”
However, Ledger’s security track record already has a blemish. In 2020, an incident occurred in which customer information for more than 270,000 people was leaked, and the data has since been circulating through illegal distribution networks such as the dark web. Related litigation is still ongoing at the U.S. District Court for the Northern District of California.
Meanwhile, phishing groups have continued to send mail to wallet holders impersonating Ledger logos, as recently as April 2025, using tactics that lure recipients to malicious sites via QR codes.
Next read: Full Sail shuts down after all three bolts are fully drained in a $91,000 Sui hack
