oll (OP)
Full Member
 

Activity: 423
Merit: 177
old 011
|
 |
September 03, 2026, 12:00:20 PM Last edit: September 03, 2026, 12:11:45 PM by oll Merited by vapourminer (1), dkbit98 (1) |
|
Ledger has been hit with a class‑action lawsuit for $500,000,000 — the main plaintiff claims that after the leaks, fraudsters were able to convincingly impersonate company employees and stole nearly $2 million in crypto from him. https://coinmarketcap.com/community/ur/articles/6a992edd7c614e5cdc9ce5bd/This is not the first lawsuit against Ledger. After the database leak in 2020, there was also a lawsuit, which was settled quietly. But now a very large sum is being requested. And apparently, new cases of client hacks via social engineering are precisely possible because of the old 2020 hack. After all, the attackers have the exact contact information of Ledger clients from that time.
|
|
|
|
Charles-Tim
Legendary

Activity: 2394
Merit: 6533
Leading Crypto Sports Betting & Casino Platform
|
 |
September 03, 2026, 12:15:08 PM |
|
Why does a company prefer a wallet that is not open source? Although, Trezor is not very different with the recent data leak, but I still prefer that it is open source, unlike Ledger wallets. Ledger has been hit with a class‑action lawsuit for $500,000,000 — the main plaintiff claims that after the leaks, fraudsters were able to convincingly impersonate company employees and stole nearly $2 million in crypto from him. I know this can happen. No matter how you are good, your employees may not be good like that. That is the reason there are ransomware and other malware commonly affect companies devices. Even the governments devices are not resistant against it. Another thing is that within the company, such attack can easily be planned and the boss will lose money. But the company should blame themselves. Probably it is phishing malware. What if it happened due to another reason?
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
Yamane_Keto
|
 |
September 03, 2026, 02:36:37 PM Merited by vapourminer (4) |
|
claims are gaining credibility. Initially I thought it was due to a data leak and its use in social attacks and phishing, but they managed to access a former employee's account, and Ledger didn't properly revoke the former employee's access after their employment ended. The damage was caused by Ledger's negligence, not just the data leak. Ledger acknowledged the access control failure at the time, stating that the former employee’s NPMJS access had not been properly revoked.
Once inside the account, the attackers uploaded a malicious version of Ledger Connect Kit that could redirect transactions to addresses they controlled by inducing users to approve malicious transactions. Ledger publicly acknowledged that the malicious software could trick users into signing transactions that drained their wallets.
|
|
|
|
dkbit98
Legendary

Activity: 3080
Merit: 8847
|
 |
September 03, 2026, 11:26:56 PM |
|
Very good news.  This could be the final blow that would bankrupt ledger and make them shut down their business forever. I feel sorry for all users who are using their devices and trusting them, but now would be the good time to make a switch and start using better open source signing devices.
|
▄▄██████▄░░░▄██████▄▄ ██▀▀░░░░▀░░░░░▀░░░░▀▀██ ▄▄██████▄░▄██████▄▄ ▄████▀▀▀▀█████▀▀▀▀████▄ ▄███░░░▄▄░░░█░░░▄▄░░░███▄ ▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄ ████████░░░░██░░░░░░░██░░░░████████ ██████████░░░▀▀░░░█░░░▀▀░░░██████████ ████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████ ▀███▄░░▀▀███████████████████▀▀░░▄███▀ ▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀ ▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀ ▀▀█████████████████████▀▀ | | OrangeFren | | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | | | | ▄▄█████▄▄ ▄████▀▀▀████▄ ███▀░░░░░░░▀███ ███▀░░░▄█░░░░▀███ ███░░░░░█░░░░░███ ███▄░░░▄█▄░░░▄███ ███▄░░░░░░░▄███ ▀████▄▄▄████▀ █████████ ▐█████████▌ █████░█████ ▐████▌░▐████▌ ▀▀░▀█░░░█▀░▀▀ | | |
|
|
|
Donneski
Sr. Member
  

Activity: 770
Merit: 267
Contact Hhampuz for campaign
|
 |
September 04, 2026, 12:55:08 AM |
|
Imagine a former employee's access not properly revoked by a hardware wallet company that's trusted by so many people across the globe to protect their digital assets, if that's established to be true, that's a huge security failure from Ledger.
For a hardware wallet, users are supposed to be worry less about the number of things to trust but this time, it's another security issues involving the same company, that's very disturbing and should be taken very serious. $500M lawsuit will definitely be determined through a legal process but I don't think the underlying security concerns is something that should be dismissed like that, not when we're talking about a popular brand like Ledger.
|
|
|
|
|
X-ray
|
 |
September 04, 2026, 01:17:14 AM Last edit: September 04, 2026, 01:29:45 AM by X-ray Merited by vapourminer (1) |
|
claims are gaining credibility. Initially I thought it was due to a data leak and its use in social attacks and phishing, but they managed to access a former employee's account, and Ledger didn't properly revoke the former employee's access after their employment ended. The damage was caused by Ledger's negligence, not just the data leak. Ledger acknowledged the access control failure at the time, stating that the former employee’s NPMJS access had not been properly revoked.
Once inside the account, the attackers uploaded a malicious version of Ledger Connect Kit that could redirect transactions to addresses they controlled by inducing users to approve malicious transactions. Ledger publicly acknowledged that the malicious software could trick users into signing transactions that drained their wallets. A hardware wallet company that supposedly security conscious forgot to revoke NPMJS access of their former employee is such a huge red flag. Ledger security feels very sloppy and their closed source code only makes it worse. But the kim's case outlined on the lawsuit was because of data leak, it happened more than a year after the supply chain attack and the supply chain attack was only used as supporting allegations, so 500m claim is unlikely. Regardless, I'd prefer to see the lawsuit going somewhere so that hardware wallets company can learn and be more privacy conscious toward their users, such as reducing data retention as minimal as possible and using anonymous shipping.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
Yamane_Keto
|
 |
September 04, 2026, 09:07:43 PM |
|
Regardless, I'd prefer to see the lawsuit going somewhere so that hardware wallets company can learn and be more privacy conscious toward their users, such as reducing data retention as minimal as possible and using anonymous shipping.
usually end in out-of-court settlements, and that could happen in this case as well. If their team continues to make these mistakes, it won't be long before the Ledger Recover service gets hacked.
|
|
|
|
Z-tight
Legendary

Activity: 1708
Merit: 1325
|
 |
September 04, 2026, 10:29:38 PM |
|
usually end in out-of-court settlements, and that could happen in this case as well.
Yeah, they would opt for that option if they assess their chances of winning and conclude that it is slim. So, rather than go through a long and expensive litigation process, they would simply prefer to compensate the victim. However, Ledger reimbursed the victims of the 2023 Connect Kit breach, but the plantiff in this lawsuit fell for a phishing attack in 2025. Yeah, the attackers were able to get their hands on Kim's personal information because of Ledger's poor security and privacy practice, but in the end, the attackers were able to steal Kim's funds because they exposed their seed phrase.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|
X-ray
|
 |
September 05, 2026, 02:37:31 AM |
|
usually end in out-of-court settlements, and that could happen in this case as well. If their team continues to make these mistakes, it won't be long before the Ledger Recover service gets hacked.
Yeah seems to be the case, the lawsuit getting class certified is just bonus at this point considering the $500 million is still hypothetical. As far as I know the concrete claim is the $2 million from the named plaintiff and maybe they primarily seeks that out-of-court settlement for the individual recovery.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
PX-Z
Legendary

Activity: 2296
Merit: 1374
Wallet Transaction Notifier - @txnNotifierBot
|
 |
September 05, 2026, 04:26:32 AM Merited by vapourminer (1) |
|
If their team continues to make these mistakes, it won't be long before the Ledger Recover service gets hacked.
Just for context, aside from coldcard, i don't think there has been a major incident where the hardware wallet company's own services were actually hacked. Most of the recent data breaches involved third party services or partners only. If it happens, then that's the end of Ledger's journey.
|
|
|
|
|