Ledger A.I CyberSecurity Scoring
Ledger
Company Information
Website:https://www.ledger.com
Employees number:824
Number of followers:91,625
NAICS:541514
Industry Type:Computer and Network Security
Homepage:ledger.com
Ledger Risk Score (AI oriented)
Between 0 and 549
LedgerComputer and Network Security
Updated:
03/09/2026
03/09/2026
101/1000
Critical
C
Ledger Global Score (TPRM)
xxxx
LedgerComputer and Network Security
Score locked

LedgerCritical
Current Score
101C (CRITICAL)
01000
14 incidents
-44.75 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
113
SEPTEMBER 2026
100
AUGUST 2026
288
Breach
27 Aug 2026 • Ledger
Ledger: Ledger sued for $500M over its many data breaches
Ledger Faces $500M Lawsuit Over Repeated Data Breaches and Crypto Theft
100
CRITICAL-188
LED1788458082
Ledger Faces $500M Lawsuit Over Repeated Data Breaches and Crypto Theft
Crypto wallet manufacturer Ledger is at the center of a $500 million class action lawsuit filed on August 27, alleging systemic negligence in protecting customer data. The plaintiff, Douglas Kim, claims to have lost nearly $2 million after attackers exploited stolen personal information from Ledger’s 2020 and 2023 breaches to target his crypto assets.
The lawsuit outlines a pattern of security failures, including a 2020 breach that exposed the personal data of nearly 300,000 users, later sold on dark web marketplaces. In 2023, a phishing attack on a Ledger employee led to malware distribution, enabling attackers to redirect funds from users’ wallets. A separate 2026 breach unrelated to the lawsuit involved a hack of payments processor Global-e, further compromising Ledger users’ data.
The complaint accuses Ledger of downplaying the breaches, delaying customer notifications, and failing to strengthen security measures. It alleges that these lapses allowed criminals to exploit leaked data, resulting in preventable financial losses. The lawsuit also cites violations of New York’s Stop Hacks and Improve Electronic Data Security Act and seeks damages ranging from $500 million to potentially billions, along with a jury trial.
Ledger has declined to comment on the ongoing legal matter.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
299
Cyber Attack
01 Aug 2026 • Ledger
Ledger: MacSync Stealer RAT Uses Fake Claude Guides to Steal Passwords and Crypto Wallets
MacSync Malware Campaign Targets macOS Users via Fake Claude AI Guides
279
CRITICAL-20
LED1785572706
MacSync Malware Campaign Targets macOS Users via Fake Claude AI Guides
A newly uncovered macOS malware campaign, dubbed MacSync, exploits fake Claude AI installation guides to deploy a sophisticated six-stage stealer and remote access trojan (RAT). Discovered by Huntress, the attack targets browser credentials, keychain secrets, cryptocurrency wallets, and other sensitive data.
The campaign begins when victims search for "how to install Claude on a Mac" and click a malicious Google-sponsored ad, redirecting them to a weaponized claude.ai/share page disguised with a fake "Shared by Apple Support" badge. The page instructs users to execute a Base64-obfuscated curl command in Terminal, which fetches a loader from domains like agenticsora[.]com or malwareaudit[.]com while bypassing certificate validation.
The malware unfolds in six stages, starting with a polymorphic zsh loader that establishes persistence via a background daemon. Subsequent stages include an AppleScript that tricks users into granting Full Disk Access, harvests credentials, and installs a Mach-O RAT written in C++ with OpenSSL. The RAT persists through a LaunchAgent mimicking legitimate updaters (e.g., Google Keystone, Adobe ARM) and deploys a helper app named "Screen Recording" to gain screen-capture permissions.
The final stage trojanizes hardware-wallet companion apps including Ledger Live, Ledger Wallet, and Trezor Suite to phish seed phrases. Huntress reports the stealer targets 60+ wallet browser extensions, 21 desktop wallet apps, and three trojanized hardware wallet tools, indicating cryptocurrency theft as the primary objective.
Infrastructure spans Cloudflare-fronted delivery domains, an operator panel at 103.216.221[.]95, and a raw-IP TLS channel (85.206.161[.]241:8443) for RAT control. Stolen data is exfiltrated to domains like sdhomeinspectors[.]com and southcarolinacounselor[.]com. Russian-language comments in the source code and collection techniques suggest ties to the AMOS/Atomic Stealer lineage, though researchers note this as a family resemblance rather than confirmed shared authorship.
Detection relies on behavioral indicators, including curl commands piped into zsh, osascript bridges executing stealer logic, and unexpected Full Disk Access or Screen Recording grants tied to newly signed apps. Persistence artifacts include paths like ~/.local/com.apple.<8hex>.hcpi and mutex files at /tmp/macsync_<token>.lock.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
290
JUNE 2026
299
Cyber Attack
01 Jun 2026 • Ledger
Electrum, Exodus, Ledger and Trezor: Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain
279
CRITICAL-20
ELEEXOLEDTRE1784199019
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain
Security researchers at SlowMist have uncovered a sophisticated macOS-focused infostealer designed to harvest credentials, wallet databases, and session data for offline cryptocurrency theft. Detected by the MistEye monitoring system, the malware casts a wide net, extracting sensitive information from Apple Keychain, Safari and Chromium browsers, Telegram Desktop, Apple Notes, and multiple wallet applications including Electrum, Exodus, Atomic, Wasabi, Monero, Bitcoin Core, Ledger Live, and Trezor Suite.
The malware’s primary threat lies in its ability to pair stolen wallet databases with potential unlocking material, such as passwords from Keychain or browser stores. While most wallet apps encrypt data locally, attackers can test harvested credentials against exfiltrated wallet files in an isolated environment, bypassing the limitations of online password-guessing attacks. SlowMist demonstrated this by successfully decrypting Atomic Wallet data using a password obtained from the victim’s Keychain. Once a wallet’s recovery phrase or private key is extracted, simply reinstalling the app or changing its password offers no protection.
The malware also employs social engineering tactics, including a fake "Google API Connector" update prompt to capture the victim’s macOS password. It validates credentials using the `dscl` authentication utility, ensuring attackers obtain the correct login details. Additionally, it targets Chrome Safe Storage secrets from Keychain, which can decrypt stored browser logins and cookies.
Telegram users face a separate risk: the stealer copies the `tdata` directory, containing encryption keys and session state. In lab tests, restoring these files on a compatible Mac immediately granted access to the victim’s account without requiring SMS codes or two-factor authentication effectively hijacking an active session. Stolen `tdata` artifacts could also be converted into programmable Telegram API sessions, enabling full chat access.
For Ledger Live and Trezor Suite users, the malware deploys phishing pages disguised as legitimate wallet applications. After removing the real software, it installs lookalike WebView loaders that connect to attacker-controlled sites, tricking victims into entering recovery phrases or PINs under the guise of trusted desktop apps.
The campaign highlights how infostealers exploit the interplay between credentials, encrypted local stores, and user trust. While a stolen wallet database alone may be secure, pairing it with Keychain secrets and reused passwords creates a portable target for offline decryption. Indicators of compromise (IOCs) include malicious domains and IP addresses linked to the phishing infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
292
APRIL 2026
294
Vulnerability
17 Apr 2026 • Ledger
Espressif Systems and Ledger: Fake Ledger Hardware Wallets on Chinese Marketplaces Steal Crypto Seeds and PINs
Sophisticated Supply Chain Attack Targets Crypto Users with Counterfeit Ledger Wallets
285
LOW-9
ESPLED1776435883
Sophisticated Supply Chain Attack Targets Crypto Users with Counterfeit Ledger Wallets
A Brazilian cybersecurity researcher uncovered a large-scale supply chain scam involving counterfeit Ledger Nano S Plus hardware wallets sold on a Chinese marketplace. The fake devices, designed to drain cryptocurrency across 20 blockchains, were engineered with tampered hardware, trojanized software, and cross-platform malware creating a seamless phishing pipeline.
The researcher, u/Past_Computer2901, purchased the device at the same price as the official Ledger store, with packaging that appeared authentic. Suspicion arose only after the device failed Ledger’s Genuine Check when connected to a legitimate Ledger Live installation. A physical teardown revealed the original secure element chip had been replaced with an ESP32-S3 microcontroller, a generic IoT component from Espressif Systems, with its markings scraped off to avoid detection. The counterfeit device also included a WiFi/Bluetooth antenna, absent in genuine Ledger wallets.
Firmware analysis exposed the full extent of the compromise: every PIN entry and seed phrase was stored in plaintext and transmitted to attacker-controlled command-and-control (C2) servers, including the domain kkkhhhnnn[.]com. The fake firmware, labeled "Nano S+ V2.1" a version that doesn’t exist in Ledger’s official releases was designed to impersonate a legitimate update.
The scam extended beyond the hardware. The counterfeit device shipped with a QR code directing users to a cloned phishing site, where they downloaded a trojanized Ledger Live app. The fake app bypassed security warnings with a hardcoded "Genuine Check" that always returned a success screen, ensuring victims remained unaware of the breach. The malware also exfiltrated wallet data upon use and was distributed across Android, Windows, macOS, and iOS, with the iOS variant spread via Apple’s TestFlight to evade App Store reviews.
Infrastructure analysis linked the operation to a Shanghai-based shell company, with three C2 servers, a cloned website, and a QR code redirect chain. While Ledger’s official Genuine Check can detect the counterfeit device, the scam’s success relied on victims never using the legitimate Ledger Live app.
The researcher submitted a full technical report to Ledger’s security team, with further analysis pending. The attack has already resulted in confirmed financial losses exceeding $9.5 million across more than 50 victims, marking one of the most advanced hardware wallet supply chain attacks documented to date.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
286
FEBRUARY 2026
289
Cyber Attack
01 Feb 2026 • Ledger
OpenClaw, Coinbase, MetaMask, 1Password and Ledger Live: Hackers Use Fake OpenClaw Installer to Steal Crypto Wallet and Password Manager Credentials
Hologram Infostealer Campaign Targets Crypto Wallets and Password Managers via Fake OpenClaw Installer
270
CRITICAL-19
METLED1PACOIOPE1778262200
New "Hologram" Infostealer Campaign Targets Crypto Wallets and Password Managers via Fake OpenClaw Installer
A sophisticated infostealer campaign, dubbed "Hologram," has been active since at least February 2026, targeting sensitive data stored in 250+ browser extensions tied to crypto wallets and password managers. The malware spreads via a fake installer for OpenClaw, a legitimate open-source AI assistant, hosted on a convincing typosquat domain (openclaw-installer[.]com), registered on March 9, 2026.
### How the Attack Works
1. Initial Infection
- Victims download OpenClaw_x64[.]7z, a 130MB Rust-based executable padded with fake documentation to evade antivirus scans and bypass sandbox upload limits.
- The dropper, named "Hologram" in its manifest, performs anti-analysis checks, including:
- Scanning for virtual machine BIOS strings and suspicious software libraries.
- Waiting for real mouse movement (automated sandboxes don’t trigger this).
- If checks pass, it disables Windows Defender, opens firewall ports, and downloads six modular components from an attacker-controlled Azure DevOps repository.
2. Credential Theft & Persistence
- The malware fetches a dynamic targeting list (hosted on Azure DevOps) covering:
- 201 crypto wallets (MetaMask, Phantom, Coinbase, Ledger Live, etc.).
- 49 password managers/authenticators (Bitwarden, LastPass, 1Password, Google Authenticator, etc.).
- The list is remotely updatable, allowing attackers to expand targets without recompiling the malware.
- Persistence mechanisms include:
- Registry autoruns.
- Windows logon hijacking.
- Scheduled tasks.
- Telegram-based droppers that survive even if the main implant is removed.
3. Evasive Infrastructure
- Command-and-control (C2) servers are never hardcoded instead, the malware retrieves them from Telegram channel descriptions, allowing rapid rotation if domains are blocked.
- Victim data (usernames, IPs, timestamps) is routed through Hookdeck, a legitimate webhook relay service, obscuring the attacker’s backend.
- Researchers observed infrastructure rotation during analysis, with domains and IPs changing before findings were published.
### Key Indicators of Compromise (IoCs)
- File Hashes: Multiple Rust-based droppers (e.g., `OpenClaw_x64[.]exe`, `svc_service[.]exe`) and secondary payloads (e.g., `onedrive_sync[.]exe`, `WinHealhCare[.]exe`).
- Domains:
- `openclaw-installer[.]com` (delivery).
- `hkdk.events` (C2 relay via Hookdeck).
- `dev.azure.com/sagonbretzpr` (payload staging).
- Hijacked Brazilian law firm domain (`frr.rubensbruno.adv.br`) and others.
- IPs: `193.202.84.14`, `45.55.35.48`, `188.114.97.3` (C2 beacons).
- Registry Keys & Paths:
- `HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit` (logon hijack).
- `C:\Users\Public\` (stage-2 binary drop location).
- `%APPDATA%\Ledger Live` (targeted for wallet theft).
### Why This Campaign Stands Out
- Advanced Evasion: Uses Rust-based malware, in-memory .NET assembly loading (via `clroxide`), and Telegram for C2 rotation.
- Dynamic Targeting: The remote Git repository allows attackers to silently expand their target list without detection.
- Persistence: Multiple layers of registry, scheduled tasks, and Telegram-based backdoors ensure long-term access.
Researchers at Netskope Threat Labs identified this as a second, more advanced iteration of the campaign, following an earlier variant. The attack highlights the growing sophistication of infostealers, particularly in crypto and credential theft.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
344
Breach
05 Jan 2026 • Ledger
Ledger and Global-e: Crypto wallet firm Ledger faces new data breach through Global-e partner
Ledger Data Exposure via Third-Party Payment Processor Global-e
281
CRITICAL-63
LEDGLO1767622098
Ledger Customers Exposed in Third-Party Payment Processor Breach
Hardware wallet provider Ledger is addressing a data exposure incident tied to its third-party payment processor, Global-e. The breach, first reported by blockchain investigator ZachXBT on X, involved unauthorized access to Ledger users' personal details—including names and contact information—stored in Global-e’s cloud system.
Global-e detected the suspicious activity and launched an investigation, confirming that an unauthorized party accessed customer order data. While the exact number of affected users and the timeline of the breach remain undisclosed, forensic experts verified the improper access. The company stated that payment information was not compromised.
Ledger clarified that the incident occurred at Global-e, not within its own systems, and emphasized that no hardware, software, or cryptocurrency-related data—such as seed phrases or wallet balances—was exposed. As the data controller, Global-e issued notifications to impacted customers. The breach also affected other brands using Global-e’s services, as the compromised cloud system contained order data from multiple retailers.
This is not Ledger’s first security incident. In 2020, a breach via e-commerce partner Shopify exposed data from 270,000 customers, and in 2023, a hack resulted in nearly $500,000 in losses for decentralized finance applications. Ledger has stated it is collaborating with Global-e to provide updates to affected users.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
363
Cyber Attack
01 Jan 2026 • Ledger
Microsoft, Trezor, Audacity, GitHub and Ledger: OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases
New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics
344
CRITICAL-19
LEDGITMICAUDTRE1784125944
New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics
A sophisticated malware framework, OkoBot, has emerged as a major threat to cryptocurrency users, employing a multi-stage attack chain to steal recovery phrases, credentials, and wallet data. First observed in January 2026, the campaign builds on the TookPS downloader, which has been active since March 2025.
OkoBot operates as a modular platform with over 202,020 payloads, allowing attackers to deploy capabilities remotely via SSH infrastructure. Initial infections occur through ClickFix social-engineering attacks and trojanized applications hosted on GitHub, including a fake Microsoft SQL Server Management Studio (SSMS) repository that delivered a malicious Audacity installer.
Once executed, TookPS installs an SSH service, establishes a tunnel to attacker-controlled servers, and conducts system reconnaissance identifying security software, harvesting browser data, and preparing for deeper compromise. The malware also enables remote desktop (RDP) access by modifying firewall rules, creating backdoor user accounts, and patching termsrv.dll to allow concurrent sessions.
A key component, HDUtil, bypasses User Account Control (UAC) using Windows RPC and msconfig.exe, while SeedHunter targets Ledger Live, Ledger Wallet, and Trezor Suite by injecting fake recovery prompts. When a victim enters their seed phrase, it is exfiltrated to moonsand[.]store and stored locally in an RC4-encrypted file.
Additional plugins include:
- MC Keylogger – Logs clipboard data, USB devices, and screenshots.
- OkoSpyware – Records keystrokes and video streams from wallet apps and password managers.
Kaspersky researchers detected hundreds of victims across 25+ countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye. While attribution remains unclear, Russian-language artifacts, Rilide stealer usage, and CIS geoblocking suggest ties to Russian-speaking cybercrime groups.
The malware’s ability to bypass security controls, maintain persistence, and exfiltrate sensitive data makes it a significant risk for cryptocurrency holders and organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
357
NOVEMBER 2025
372
Cyber Attack
19 Nov 2025 • Ledger
Ledger / Trezor (Cryptocurrency Wallet Providers)
Nova Stealer macOS Malware Campaign Targeting Cryptocurrency Users
352
CRITICAL-20
LED5093550111925
The Nova Stealer malware campaign targets macOS users by replacing legitimate Ledger Live and Trezor Suite cryptocurrency wallet applications with malicious counterparts. The attack begins with a dropper downloading a shell script (`mdriversinstall.sh`) from a C2 server, establishing persistence via a hidden directory (`~/.mdrivers`) and a LaunchAgent (`application.com.artificialintelligence`). The malware operates stealthily using detached `screen` sessions, ensuring survival across reboots.Key modules include:- `mdriversfiles.sh`: Exfiltrates wallet data (e.g., Trezor’s `IndexedDB`, Exodus’ `passphrase.json`, Ledger’s `app.json`).- `mdriversswaps.sh`: Replaces genuine wallet apps with unsigned FAT Mach-O executables (Swift-based) that render phishing pages (`wheelchairmoments[.]com`, `sunrisefootball[.]com`). These pages use BIP-39/SLIP-39 validation to harvest recovery phrases (12–33 words) via keystroke logging (200–400ms debounce) and real-time tracking (`/track` endpoints).- `mdriversmetrics.sh`: Conducts system reconnaissance (installed apps, processes).Victims unknowingly interact with counterfeit apps (registered in Dock via `PlistBuddy`), leading to full compromise of cryptocurrency assets. The modular design allows remote updates, extending the campaign’s lifespan while evading static detection. The attack focuses on high-value targets (crypto users), with potential for mass financial loss and irreversible asset theft due to exposed recovery phrases.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
437
Breach
18 Aug 2025 • Ledger
Canadian Investment Regulatory Organization: 750,000 Impacted by Data Breach at Canadian Investment Watchdog
CIRO Data Breach Exposes Personal Information of 750,000 Individuals
349
CRITICAL-88
CIR1768585990
CIRO Data Breach Exposes Personal Information of 750,000 Individuals
The Canadian Investment Regulatory Organization (CIRO) disclosed a data breach on August 18, 2025, revealing that hackers accessed the personal information of approximately 750,000 individuals in an August cyberattack. The breach stemmed from a sophisticated phishing incident, which led to temporary system shutdowns, though CIRO confirmed its critical regulatory functions remained unaffected.
According to CIRO, the compromised data includes sensitive details such as annual income, dates of birth, government-issued ID numbers, phone numbers, investment account numbers, social insurance numbers, and account statements information collected during routine regulatory and compliance activities. The organization clarified that passwords, PINs, and security questions were not exposed, as CIRO does not store such data.
While CIRO reported no evidence of data misuse or dark web exposure, it continues to monitor for malicious activity. Impacted individuals clients and former clients of CIRO dealer members are being notified and offered two years of free credit monitoring and identity theft protection services. An FAQ page has also been published to provide further details.
CIRO, a pan-Canadian self-regulatory body overseeing investment and mutual fund dealers, stated that the incident is contained with no active threat remaining in its environment. The breach follows a series of recent cybersecurity incidents affecting financial and healthcare sectors globally.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2025
483
Breach
02 Mar 2025 • Ledger
SafePal: SafePal data breach impacts 39,798 customers, stolen info for sale
SafePal Data Breach Exposes Nearly 40,000 Customers’ Order Information
400
CRITICAL-83
SAF1786926220
SafePal Data Breach Exposes Nearly 40,000 Customers’ Order Information
SafePal, a cryptocurrency hardware wallet provider, has disclosed a data breach affecting 39,798 customers after a flaw in its order-tracking system was exploited to steal personal information. The incident impacts users who placed orders between March 2, 2025, and April 11, 2026, exposing names, email addresses, shipping details, phone numbers, and purchase information.
The breach did not compromise wallet seed phrases, private keys, passwords, payment details, or government-issued IDs. SafePal confirmed that no evidence suggests unauthorized access to customer funds or wallets. Impacted users were notified via email on August 16, 2026, and the company released an online verification tool to check if order data was exposed.
A threat actor is now selling the stolen data on a cybercrime forum, matching SafePal’s disclosed timeline and customer count. The seller offered to verify order details using SafePal’s tool to prove legitimacy. While the data’s authenticity has not been independently confirmed, customers reported phishing attempts including fake firmware update emails and fraudulent calls as early as May 2026.
SafePal first detected suspicious activity in early May 2026 but initially treated it as an isolated case. A full investigation in July 2026 uncovered an authorization flaw in a third-party order-tracking plugin, which allowed unauthorized access to customer data. The company patched the vulnerability and implemented additional security measures, later discovering a separate configuration error that caused order data to be retained longer than intended back to March 2025.
SafePal has since purged exposed personal data from active servers, retaining an encrypted offline copy for potential law enforcement use. The company also took down over 30 fraudulent websites and phishing links tied to the breach. While customers do not need to replace hardware wallets or move funds, those who shared seed phrases or private keys in response to phishing attempts should transfer assets to a new wallet.
SafePal is working with a third-party security firm to validate fixes and review its order-processing systems. The incident highlights risks of targeted phishing and social engineering attacks using stolen order data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2025
671
Breach
18 Feb 2025 • Ledger
Ledger: Ledger sued for $500M over alleged data breach and crypto theft
Ledger Faces $500M Class Action Over Alleged Security Failures and Crypto Theft
481
CRITICAL-190
LED1788441237
Ledger Faces $500M Class Action Over Alleged Security Failures and Crypto Theft
Ledger, the hardware wallet manufacturer, is facing a proposed class action lawsuit seeking at least $500 million in damages over alleged security and disclosure failures tied to a December 2023 breach. The complaint, filed on August 27 in the U.S. District Court for the Southern District of New York by plaintiff Douglas Kim, accuses Ledger of negligence, deceptive practices, and failing to protect customer data leading to nearly $1.95 million in stolen cryptocurrency from Kim alone.
The lawsuit centers on a December 2023 incident involving Ledger’s Connect Kit, a software library used to link hardware wallets with decentralized applications. Attackers compromised a former employee’s NPMJS account via phishing, exploiting Ledger’s failure to revoke access post-employment. The hackers then deployed a malicious version of the Connect Kit, tricking users into approving transactions that drained their wallets. While Ledger initially estimated losses at $480,000–$600,000, the company later committed to reimbursing affected users and announced plans to phase out blind signing for Ethereum-based dApps.
Kim’s complaint alleges that the breach exposed customer personally identifiable information (PII), including names, emails, and phone numbers, which scammers later used to impersonate Ledger representatives. In February 2025, Kim received a fraudulent call from individuals posing as Ledger’s Coincover department, warning of a security threat and directing him to a phishing site. After entering his passphrase, Kim lost $1.95 million in cryptoassets none of which have been recovered.
The lawsuit also highlights Ledger’s 2020 data breach, which exposed over 270,000 customers’ PII, as evidence of a pattern of inadequate security. Kim argues that Ledger’s public claims about encryption, employee training, and monitoring were misleading, given its failure to address foreseeable risks. The complaint includes seven causes of action, including violations of New York’s SHIELD Act and General Business Law, negligence, and breach of good faith.
The proposed nationwide class covers U.S. customers whose PII or cryptoassets were compromised, with a subclass for New York-based victims. Kim estimates collective damages could exceed $500 million, potentially reaching billions, depending on the number of affected users. The lawsuit seeks actual, compensatory, statutory, treble, and punitive damages, along with attorneys’ fees and a jury trial.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2024
663
Cyber Attack
01 Jan 2024 • Ledger
Ledger
13% Increase in Ransomware Attacks on European Organizations (2024-2025)
638
CRITICAL-25
LED1832718110325
In January 2025, Ledger, a Paris-based crypto-wallet vendor, fell victim to a Violence-as-a-Service (VaaS) attack orchestrated by Russia-linked groups Renaissance Spider and The Com. The co-founder of Ledger was kidnapped in France as part of an extortion scheme tied to cryptocurrency theft. The attack was executed via Telegram-coordinated networks, leveraging physical violence, arson threats, and ransom demands. This incident was among 17 recorded VaaS attacks since January 2024, with 13 occurring in France alone, prompting Europol to establish a dedicated taskforce to counter the escalating threat. The attack not only endangered the executive’s life but also exposed Ledger to reputational damage, operational disruption, and potential financial losses due to ransom pressures. The incident underscores the convergence of cyber extortion and physical violence, targeting high-profile individuals in the crypto sector to exploit digital and real-world vulnerabilities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2023
725
Breach
01 Dec 2023 • Ledger
Ledger
Phishing Attack on Ledger Connect Kit Software
661
HIGH-64
LED743221223
The Ledger Connect Kit software of the Paris-based business was compromised by a phishing attempt targeting a former worker.
During transactions using decentralised applications, or dapps, that utilised the compromised software, the hacker released malicious code that routed user funds to their own wallet.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JUNE 2020
757
Data Leak
01 Jun 2020 • Ledger
Ledger
Ledger Data Breach
680
CRITICAL-77
LED213813123
Major cryptocurrency hardware wallet provider Ledger experienced a data breach.
The company said it was made aware of the breach on July 14 when a researcher participating in its bounty program reached out with details of a potential vulnerability on their website.
While they were able to fix the breach immediately, a further investigation found that an authorized third party carried out a similar action on June 25.
The individual used an API key to access the marketing and e-commerce database the company used to send promotional emails.
This compromised the email addresses of almost one million people.
For a subset of 9,500 customers, details such as first and last name, postal address, and phone number were also exposed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Ledger ??
What was Ledger's A.I Rankiteo Cyber Score in September 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in August 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in July 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in June 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in May 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in April 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in March 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in February 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in January 2026 ??
What was Ledger's A.I Rankiteo Cyber Score in December 2025 ??
What was Ledger's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Ledger's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Ledger ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Ledger's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?