Ledger sued for $500M over alleged data breach and crypto theft

Ledger has been hit with a proposed class action seeking at least $500 million over allegations that poor security and disclosure failures tied to a December 2023 incident exposed customers to cryptocurrency theft and other financial losses. Summary Ledger faces a proposed class action seeking at least $500 million over alleged security and disclosure failures tied to a December 2023 incident. Plaintiff Douglas Kim alleges scammers used compromised customer information to impersonate Ledger representatives before stealing nearly $1.95 million in crypto. The complaint cites Ledger’s 2020 breach affecting more than 270,000 customers as part of an alleged pattern of inadequate data safeguards. The lawsuit brings seven causes of action and seeks actual, compensatory, statutory, treble and punitive damages. The complaint, filed by Douglas Kim in the U.S. District Court for the Southern District of New York on Aug. 27, accuses the hardware wallet maker of failing to adequately protect customer personally identifiable information and cryptocurrency security data. Kim brought the case individually and on behalf of a proposed nationwide class. Kim alleges that Ledger failed to properly notify customers after the December 2023 security incident and did not fully disclose its scope. The lawsuit claims hackers later used customer contact information to impersonate Ledger representatives and gain access to customers’ cryptocurrency wallets and private keys. The complaint brings seven causes of action, including claims under New York General Business Law Sections 349 and 350, negligence, negligent misrepresentation, promissory estoppel and breach of the implied covenant of good faith and fair dealing. Ledger lawsuit centers on December 2023 security incident The December 2023 incident involved Ledger Connect Kit, a software library used to connect hardware wallets with websites and decentralized applications. The complaint says attackers gained access to the NPMJS account of a former Ledger employee through a phishing attack. Ledger had failed to properly revoke the former employee’s access after their employment ended, according to the filing. Ledger acknowledged the access control failure at the time, stating that the former employee’s NPMJS access had not been properly revoked. Once inside the account, the attackers uploaded a malicious version of Ledger Connect Kit that could redirect transactions to addresses they controlled by inducing users to approve malicious transactions. Ledger publicly acknowledged that the malicious software could trick users into signing transactions that drained their wallets. You might also like: CFTC seeks dismissal of CME crypto futures lawsuit crypto.news previously reported that a former Ledger employee was phished before an attacker used the compromised access to publish malicious code. Ledger CEO Pascal Gauthier said at the time that the incident was isolated to third party applications and that Ledger hardware wallets remained unaffected. Estimates at the time put losses from the Connect Kit exploit between roughly $480,000 and $600,000.
عنوان اصلی (انگلیسی): Ledger sued for $500M over alleged data breach and crypto theft
مشاهدهی خبر کامل در منبع ↗ بازگشت به Nanoاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.