Bitcoin Forum
September 03, 2026, 04:45:46 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Ledger has been hit with a class‑action lawsuit for $500,000,000  (Read 42 times)
oll (OP)
Full Member
***
Offline

Activity: 419
Merit: 172


old 011


View Profile
Today at 12:00:20 PM
Last edit: Today at 12:11:45 PM by oll
 #1

Ledger has been hit with a class‑action lawsuit for $500,000,000 — the main plaintiff claims that after the leaks, fraudsters were able to convincingly impersonate company employees and stole nearly $2 million in crypto from him.

https://coinmarketcap.com/community/ur/articles/6a992edd7c614e5cdc9ce5bd/

This is not the first lawsuit against Ledger. After the database leak in 2020, there was also a lawsuit, which was settled quietly. But now a very large sum is being requested. And apparently, new cases of client hacks via social engineering are precisely possible because of the old 2020 hack. After all, the attackers have the exact contact information of Ledger clients from that time.

Charles-Tim
Legendary
*
Offline

Activity: 2394
Merit: 6525


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 12:15:08 PM
 #2

Why does a company prefer a wallet that is not open source? Although, Trezor is not very different with the recent data leak, but I still prefer that it is open source, unlike Ledger wallets.

Ledger has been hit with a class‑action lawsuit for $500,000,000 — the main plaintiff claims that after the leaks, fraudsters were able to convincingly impersonate company employees and stole nearly $2 million in crypto from him.
I know this can happen.

No matter how you are good, your employees may not be good like that. That is the reason there are ransomware and other malware commonly affect companies devices. Even the governments devices are not resistant against it.

Another thing is that within the company, such attack can easily be planned and the boss will lose money.

But the company should blame themselves. Probably it is phishing malware. What if it happened due to another reason?

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Yamane_Keto
Hero Member
*****
Offline

Activity: 980
Merit: 601



View Profile WWW
Today at 02:36:37 PM
 #3

claims are gaining credibility. Initially I thought it was due to a data leak and its use in social attacks and phishing, but they managed to access a former employee's account, and Ledger didn't properly revoke the former employee's access after their employment ended. The damage was caused by Ledger's negligence, not just the data leak.

Quote
Ledger acknowledged the access control failure at the time, stating that the former employee’s NPMJS access had not been properly revoked.

Once inside the account, the attackers uploaded a malicious version of Ledger Connect Kit that could redirect transactions to addresses they controlled by inducing users to approve malicious transactions. Ledger publicly acknowledged that the malicious software could trick users into signing transactions that drained their wallets.

▄███████████████████████▄
█████████████████████████
██████████▀▄▄▄▀██████████
███████████████████████
████████▀▀▄▄▄▀█████████
███████░░░█████░░░███████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
██████░░░▐█████▌░░░██████
███████░░░█████░░░███████
████████▄▄▀▀▀▄█████████
█████████████████████████
▀███████████████████████▀
 
 Lock.com 
█▀▀











█▄▄
▀▀█











▄▄█
█▀▀











█▄▄
▀▀█











▄▄█
 
  Open  code isolated Crypto Wallet     Sign Up    
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!