Ledger, the French manufacturer of crypto hardware wallets widely used across Europe, is facing a $500 million class action lawsuit filed in the Southern District of New York. The suit, lodged on August 27, 2026, accuses the company of failing to properly disclose a security incident that struck its Connect Kit software in December 2023.
The lead plaintiff, Douglas Kim, alleges that in February 2025 he lost $1,948,074 in crypto assets after being targeted by scammers impersonating both Ledger and Coincover, a separate firm involved in crypto asset recovery. Kim is seeking $2 million in personal compensation as part of the broader action.
The complaint centers on the December 14, 2023 incident, in which attackers compromised Ledger's Connect Kit after stealing credentials from a former employee through an impersonation attack. Ledger has previously stated it fixed the flaw within 40 minutes and initially estimated damages at $600,000. The company has also acknowledged it did not manually revoke access on NPMJS, the external package registry where the malicious code was distributed. CriptoNoticias reported on the original 2023 attack at the time it occurred.
Allegations of negligence
The lawsuit argues that Ledger \"did not disclose the incident, nor the scope of exposed customer data, in a timely and complete manner.\" It further describes what it calls a \"disturbing pattern of negligent, reckless and irresponsible conduct,\" and accuses the company of \"callous disregard\" toward affected users. Several of the claims regarding the scope of exposed data are made, in the plaintiffs' own words, \"on information and belief.\"
To calculate the scale of potential damages, the filing uses Ledger's reported sales figure of 7 million hardware wallet units. Assuming that 3% of buyers were harmed and estimating an average loss of $20,000 per affected customer, the plaintiffs arrive at the $500 million figure sought from the company.
What it means for European users
Ledger's devices are a fixture among European crypto holders seeking offline storage for their assets, and the case puts renewed scrutiny on how the company communicates with customers when its software infrastructure is compromised. The lawsuit does not allege a new breach, but rather challenges the adequacy of Ledger's response to the 2023 incident and the information it provided to users in its aftermath.
The case is proceeding in the Southern District of New York. No ruling has been issued, and Ledger has not been reported as having responded publicly to the specific claims in the filing.




