The hardware cryptocurrency wallet manufacturer Ledger has once again found itself at the center of a scandal. This time, the company is facing a class-action lawsuit filed in the federal court for the Southern District of New York. The plaintiff, Douglas Kim, accuses the firm of concealing the scale of a data breach that occurred in December 2023.
The essence of the claims boils down to the fact that the incident affected a critical array of clients' personal information: names, email addresses, phone numbers, and other personally identifiable information (PII). Kim insists that Ledger not only delayed the public disclosure of the hack but also deliberately downplayed its severity, which contradicts consumer protection standards.
Chain of attacks and old sins
In the lawsuit documents, the alleged breach is directly linked to a wave of social engineering attacks. This refers to fraudsters who, posing as official Ledger representatives, contacted users and convinced them to approve fictitious transactions. As a result of such manipulations, attackers managed to drain victims' crypto assets.
Special emphasis in the case is placed on the 2020 incident, when data from approximately 270,000 clients was exposed to the public. The plaintiff believes that the current case is a systemic problem, not a one-off mistake. Kim's lawyers classify the company's actions as negligence, negligent misrepresentation, and unfair business practices.
Notably, this lawsuit is not Ledger's only headache. Earlier this year, the research team OneKey Anzen successfully reproduced a transaction substitution attack in a test environment on the wallet's Ethereum application version 1.22.1. Although the vulnerability was promptly patched, the very fact of such findings undermines trust in the ironclad reputation of hardware devices.
My take: The situation around Ledger is a wake-up call for the entire industry. The reputation of "cold storage" as an absolutely secure method is shattered against a reality where the weak link turns out to be not the chip, but the client base and communications. Investors should remember: even the most reliable devices will not protect against phishing if the company does not ensure total data security at all levels.