claims are gaining credibility. Initially I thought it was due to a data leak and its use in social attacks and phishing, but they managed to access a former employee's account, and Ledger didn't properly revoke the former employee's access after their employment ended. The damage was caused by Ledger's negligence, not just the data leak.
Ledger acknowledged the access control failure at the time, stating that the former employee’s NPMJS access had not been properly revoked.
Once inside the account, the attackers uploaded a malicious version of Ledger Connect Kit that could redirect transactions to addresses they controlled by inducing users to approve malicious transactions. Ledger publicly acknowledged that the malicious software could trick users into signing transactions that drained their wallets.
A hardware wallet company that supposedly security conscious forgot to revoke NPMJS access of their former employee is such a huge red flag.
Ledger security feels very sloppy and their closed source code only makes it worse.
But the kim's case outlined on the lawsuit was because of data leak, it happened more than a year after the supply chain attack and the supply chain attack was only used as supporting allegations, so 500m claim is unlikely.
Regardless, I'd prefer to see the lawsuit going somewhere so that hardware wallets company can learn and be more privacy conscious toward their users, such as reducing data retention as minimal as possible and using anonymous shipping.