oll (OP)
Full Member
 

Activity: 453
Merit: 185
old 011
|
Ledger has been hit with a class‑action lawsuit for $500,000,000 — the main plaintiff claims that after the leaks, fraudsters were able to convincingly impersonate company employees and stole nearly $2 million in crypto from him. https://coinmarketcap.com/community/ur/articles/6a992edd7c614e5cdc9ce5bd/This is not the first lawsuit against Ledger. After the database leak in 2020, there was also a lawsuit, which was settled quietly. But now a very large sum is being requested. And apparently, new cases of client hacks via social engineering are precisely possible because of the old 2020 hack. After all, the attackers have the exact contact information of Ledger clients from that time.
|
|
|
|
Charles-Tim
Legendary

Activity: 2408
Merit: 6542
Leading Crypto Sports Betting & Casino Platform
|
 |
September 03, 2026, 12:15:08 PM |
|
Why does a company prefer a wallet that is not open source? Although, Trezor is not very different with the recent data leak, but I still prefer that it is open source, unlike Ledger wallets. Ledger has been hit with a class‑action lawsuit for $500,000,000 — the main plaintiff claims that after the leaks, fraudsters were able to convincingly impersonate company employees and stole nearly $2 million in crypto from him. I know this can happen. No matter how you are good, your employees may not be good like that. That is the reason there are ransomware and other malware commonly affect companies devices. Even the governments devices are not resistant against it. Another thing is that within the company, such attack can easily be planned and the boss will lose money. But the company should blame themselves. Probably it is phishing malware. What if it happened due to another reason?
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
Yamane_Keto
|
claims are gaining credibility. Initially I thought it was due to a data leak and its use in social attacks and phishing, but they managed to access a former employee's account, and Ledger didn't properly revoke the former employee's access after their employment ended. The damage was caused by Ledger's negligence, not just the data leak. Ledger acknowledged the access control failure at the time, stating that the former employee’s NPMJS access had not been properly revoked.
Once inside the account, the attackers uploaded a malicious version of Ledger Connect Kit that could redirect transactions to addresses they controlled by inducing users to approve malicious transactions. Ledger publicly acknowledged that the malicious software could trick users into signing transactions that drained their wallets.
|
|
|
|
dkbit98
Legendary

Activity: 3094
Merit: 8860
|
 |
September 03, 2026, 11:26:56 PM |
|
Very good news.  This could be the final blow that would bankrupt ledger and make them shut down their business forever. I feel sorry for all users who are using their devices and trusting them, but now would be the good time to make a switch and start using better open source signing devices.
|
▄▄██████▄░░░▄██████▄▄ ██▀▀░░░░▀░░░░░▀░░░░▀▀██ ▄▄██████▄░▄██████▄▄ ▄████▀▀▀▀█████▀▀▀▀████▄ ▄███░░░▄▄░░░█░░░▄▄░░░███▄ ▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄ ████████░░░░██░░░░░░░██░░░░████████ ██████████░░░▀▀░░░█░░░▀▀░░░██████████ ████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████ ▀███▄░░▀▀███████████████████▀▀░░▄███▀ ▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀ ▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀ ▀▀█████████████████████▀▀ | | OrangeFren | | ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ ██ | | | | ▄▄█████▄▄ ▄████▀▀▀████▄ ███▀░░░░░░░▀███ ███▀░░░▄█░░░░▀███ ███░░░░░█░░░░░███ ███▄░░░▄█▄░░░▄███ ███▄░░░░░░░▄███ ▀████▄▄▄████▀ █████████ ▐█████████▌ █████░█████ ▐████▌░▐████▌ ▀▀░▀█░░░█▀░▀▀ | | |
|
|
|
Donneski
Sr. Member
  

Activity: 784
Merit: 271
Contact Hhampuz for campaign
|
 |
September 04, 2026, 12:55:08 AM |
|
Imagine a former employee's access not properly revoked by a hardware wallet company that's trusted by so many people across the globe to protect their digital assets, if that's established to be true, that's a huge security failure from Ledger.
For a hardware wallet, users are supposed to be worry less about the number of things to trust but this time, it's another security issues involving the same company, that's very disturbing and should be taken very serious. $500M lawsuit will definitely be determined through a legal process but I don't think the underlying security concerns is something that should be dismissed like that, not when we're talking about a popular brand like Ledger.
|
|
|
|
|
X-ray
|
 |
September 04, 2026, 01:17:14 AM Last edit: September 04, 2026, 01:29:45 AM by X-ray Merited by vapourminer (1) |
|
claims are gaining credibility. Initially I thought it was due to a data leak and its use in social attacks and phishing, but they managed to access a former employee's account, and Ledger didn't properly revoke the former employee's access after their employment ended. The damage was caused by Ledger's negligence, not just the data leak. Ledger acknowledged the access control failure at the time, stating that the former employee’s NPMJS access had not been properly revoked.
Once inside the account, the attackers uploaded a malicious version of Ledger Connect Kit that could redirect transactions to addresses they controlled by inducing users to approve malicious transactions. Ledger publicly acknowledged that the malicious software could trick users into signing transactions that drained their wallets. A hardware wallet company that supposedly security conscious forgot to revoke NPMJS access of their former employee is such a huge red flag. Ledger security feels very sloppy and their closed source code only makes it worse. But the kim's case outlined on the lawsuit was because of data leak, it happened more than a year after the supply chain attack and the supply chain attack was only used as supporting allegations, so 500m claim is unlikely. Regardless, I'd prefer to see the lawsuit going somewhere so that hardware wallets company can learn and be more privacy conscious toward their users, such as reducing data retention as minimal as possible and using anonymous shipping.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
|
Yamane_Keto
|
 |
September 04, 2026, 09:07:43 PM |
|
Regardless, I'd prefer to see the lawsuit going somewhere so that hardware wallets company can learn and be more privacy conscious toward their users, such as reducing data retention as minimal as possible and using anonymous shipping.
usually end in out-of-court settlements, and that could happen in this case as well. If their team continues to make these mistakes, it won't be long before the Ledger Recover service gets hacked.
|
|
|
|
Z-tight
Legendary

Activity: 1722
Merit: 1334
|
 |
September 04, 2026, 10:29:38 PM |
|
usually end in out-of-court settlements, and that could happen in this case as well.
Yeah, they would opt for that option if they assess their chances of winning and conclude that it is slim. So, rather than go through a long and expensive litigation process, they would simply prefer to compensate the victim. However, Ledger reimbursed the victims of the 2023 Connect Kit breach, but the plantiff in this lawsuit fell for a phishing attack in 2025. Yeah, the attackers were able to get their hands on Kim's personal information because of Ledger's poor security and privacy practice, but in the end, the attackers were able to steal Kim's funds because they exposed their seed phrase.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
|
X-ray
|
 |
September 05, 2026, 02:37:31 AM |
|
usually end in out-of-court settlements, and that could happen in this case as well. If their team continues to make these mistakes, it won't be long before the Ledger Recover service gets hacked.
Yeah seems to be the case, the lawsuit getting class certified is just bonus at this point considering the $500 million is still hypothetical. As far as I know the concrete claim is the $2 million from the named plaintiff and maybe they primarily seeks that out-of-court settlement for the individual recovery.
|
| ..Stake.com.. | | | ▄████████████████████████████████████▄ ██ ▄▄▄▄▄▄▄▄▄▄ ▄▄▄▄▄▄▄▄▄▄ ██ ▄████▄ ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██ ██████ ██ ██████████ ██ ██ ██████████ ██ ▀██▀ ██ ██ ██ ██████ ██ ██ ██ ██ ██ ██ ██████ ██ █████ ███ ██████ ██ ████▄ ██ ██ █████ ███ ████ ████ █████ ███ ████████ ██ ████ ████ ██████████ ████ ████ ████▀ ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██ ██ ▀▀▀▀▀▀▀▀▀▀ ██ ▀█████████▀ ▄████████████▄ ▀█████████▀ ▄▄▄▄▄▄▄▄▄▄▄▄███ ██ ██ ███▄▄▄▄▄▄▄▄▄▄▄▄ ██████████████████████████████████████████ | | | | | | ▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄ █ ▄▀▄ █▀▀█▀▄▄ █ █▀█ █ ▐ ▐▌ █ ▄██▄ █ ▌ █ █ ▄██████▄ █ ▌ ▐▌ █ ██████████ █ ▐ █ █ ▐██████████▌ █ ▐ ▐▌ █ ▀▀██████▀▀ █ ▌ █ █ ▄▄▄██▄▄▄ █ ▌▐▌ █ █▐ █ █ █▐▐▌ █ █▐█ ▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█ | | | | | | ▄▄█████████▄▄ ▄██▀▀▀▀█████▀▀▀▀██▄ ▄█▀ ▐█▌ ▀█▄ ██ ▐█▌ ██ ████▄ ▄█████▄ ▄████ ████████▄███████████▄████████ ███▀ █████████████ ▀███ ██ ███████████ ██ ▀█▄ █████████ ▄█▀ ▀█▄ ▄██▀▀▀▀▀▀▀██▄ ▄▄▄█▀ ▀███████ ███████▀ ▀█████▄ ▄█████▀ ▀▀▀███▄▄▄███▀▀▀ | | | ..PLAY NOW.. |
|
|
|
PX-Z
Legendary

Activity: 2310
Merit: 1393
|
 |
September 05, 2026, 04:26:32 AM Merited by vapourminer (1) |
|
If their team continues to make these mistakes, it won't be long before the Ledger Recover service gets hacked.
Just for context, aside from coldcard, i don't think there has been a major incident where the hardware wallet company's own services were actually hacked. Most of the recent data breaches involved third party services or partners only. If it happens, then that's the end of Ledger's journey.
|
|
|
|
Pmalek
Legendary

Activity: 3626
Merit: 9543
|
 |
September 12, 2026, 07:14:19 AM |
|
I wish him luck but I doubt he is getting a $500 payout or anything close to it. Perhaps Ledger pays him an out-of-court settlement if the lawsuit gets to a point where the company may feel their interests are in danger. I wonder how he got to that number of $500 million. Why not $1 billion or ask for $5 billion while you are at it?
The biggest concern in this entire affair is the ex-employee who still had access to company systems he should have no business accessing any longer. That shows such a negligence from a company that should have security as the first, second, and third priority before anything else.
|
| EARNBET | | | ⚽ 🏀 🏈 🏓 🎯 🥊 |
| ⚾ 🎾 ⛳ 🏐 🏏 🏎️ | | |
███████▄▄███████████ ████▄██████████████████ ██▄▀▀███████████████▀▀███ █▄████████████████████████ ▄▄████████▀▀▀▀▀████████▄▄██ ███████████████████████████ █████████▌████▀████████████ ███████████████████████████ ▀▀███████▄▄▄▄▄█████████▀▀██ █▀█████████████████████▀██ ██▀▄▄███████████████▄▄███ ████▀██████████████████ ███████▀▀███████████ | ....HIGHEST.... VIP REWARDS ✔ G U A R A N T E E D
| | | 🜲 | KING OF THE CASTLE $200K in prizes | | | ..PLAY NOW.. |
|
|
|
bitmover
Legendary

Activity: 3164
Merit: 7761
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
September 12, 2026, 02:08:00 PM Merited by vapourminer (1) |
|
claims are gaining credibility. Initially I thought it was due to a data leak and its use in social attacks and phishing, but they managed to access a former employee's account, and Ledger didn't properly revoke the former employee's access after their employment ended. The damage was caused by Ledger's negligence, not just the data leak.
This is more serious than just a data leak. Basically every company out there had suffered some data leak, even governments. If some judge decides to punish just a data leak, all big companies in the world would be facing similar actions. However, a cybersecurity company that does not properly revoking access from former employee is much serious. Lets see how this goes.
|
| DΞX.fo | | | | | | ▄▄██████ █████████ ██████████ ██████████ ██████████ █████████ ▀▀██████
▄███████ ▄██████████ ████████████ █████████████ █████████████ | | | | ▄▄█ ▄████▀ ▄███▀█▄ ▄██▀█▄██ █████▀▀█ ████████ ████████ ▀██▄████ ▄████▄▄█ ▄█████▀███ ▄█████▀████▀ █████▀███████ ▀██▀█████████ | | | | | BTC XMR DAI LTC Fees 0.8% |
|
|
|
ABCbits
Legendary

Activity: 3738
Merit: 10380
|
 |
September 17, 2026, 08:51:40 AM |
|
claims are gaining credibility. Initially I thought it was due to a data leak and its use in social attacks and phishing, but they managed to access a former employee's account, and Ledger didn't properly revoke the former employee's access after their employment ended. The damage was caused by Ledger's negligence, not just the data leak.
This is more serious than just a data leak. Basically every company out there had suffered some data leak, even governments. If some judge decides to punish just a data leak, all big companies in the world would be facing similar actions. However, a cybersecurity company that does not properly revoking access from former employee is much serious. Lets see how this goes. FWIW, there are few cases where a company fined due to data leak. For example, On November 25, 2022, Ireland’s Data Protection Commission (“DPC”) released a decision fining Meta Platforms, Inc. (“Meta”) €265 million for a 2019 data leak involving the personal information of approximately 533 million Facebook users worldwide.
In the decision, the DPC argued that Meta failed to comply with the GDPR’s requirement of providing privacy “by design and default” when it failed to prevent the disclosure of users’ phone numbers, email addresses, full names, dates of birth and other personal information on an online hacking forum. The leak was a result of a hacking group exploiting a weakness in Facebook’s data processing measures to scrape public profiles and connect user profiles with email addresses.
It's probably small amount for Meta, but it could happen to other company, especially if they operate in EU.
|
|
|
|
|