Ledger hardware wallets, long considered the gold standard for security in the crypto industry, have once again found themselves at the center of a scandal. This time, the company is facing a class-action lawsuit filed in the U.S. District Court for the Southern District of New York. The plaintiff, Douglas Kim, accuses the manufacturer of concealing the scale of a data breach that occurred in December 2023.

The essence of the claims boils down to the incident affecting confidential client information: names, email addresses, phone numbers, and other personally identifiable information (PII). Kim insists that Ledger not only delayed public disclosure of the hack but also deliberately downplayed its severity, contradicting its obligations to users.

Social Engineering as the Primary Attack Vector

The court documents reveal a direct link between the breach and a wave of fraudulent activity. According to my data, attackers who gained access to personal information actively employed social engineering tactics. They posed as official Ledger representatives, engaged victims in dialogue, and convinced them to approve phishing transactions. As a result, users lost crypto assets while believing they were interacting with a legitimate service.

Special attention in the lawsuit is also paid to an earlier incident. This refers to the 2020 breach, which is estimated to have affected around 270,000 clients. That case had already undermined trust in the company, but now lawyers view it as part of a systemic problem rather than an isolated mistake.

Legal Consequences and Reputational Risks

Ledger is accused of violating consumer protection laws, negligence, and unfair business practices. Standing apart is the charge of negligent misrepresentation, meaning the company may have provided users with incomplete or misleading information about its security.

Against this backdrop, it is worth recalling that back in August, researchers from the OneKey Anzen team successfully reproduced a transaction substitution attack on the Ledger Ethereum application version 1.22.1. Although the vulnerability was promptly patched, the very fact of its existence demonstrates that even "ironclad" protection is not absolute.

My analysis: The current situation is a warning sign for the entire digital asset storage industry. The 2023 PII breach, as well as the 2020 incident, shows that hardware wallets protect keys but do not always protect owners' personal data. While Ledger focuses on its legal defense, the market should consider: ecosystem security is determined not only by the Secure Element chip but also by how the company processes and stores user information. Without transparency and a radical overhaul of privacy approaches, reputational losses could prove more devastating than any legal costs.