The complaint, filed by Douglas Kim in the U.S. District Court for the Southern District of New York, centers on the fallout from a December 2023 security incident involving Ledger’s Connect Kit. Attackers compromised a former employee’s account to inject malicious code, which redirected user transactions. While Ledger acknowledged the breach at the time, Kim argues the company failed to adequately protect personal information, enabling hackers to identify and target him later with a convincing impersonation campaign.
According to the lawsuit, Kim lost over $1.94 million in digital assets after scammers posed as Ledger representatives, citing the previous security incident to gain his trust. The filing contends that this breach is part of a broader pattern of negligence, pointing to a massive 2020 data leak that exposed the personal details of 270,000 customers. Kim alleges that Ledger failed to improve its security protocols despite these recurring vulnerabilities, effectively leaving its user base exposed to ongoing phishing and identity theft.
The lawsuit brings seven causes of action, including negligence and violations of New York business laws. Beyond the specific losses suffered by the plaintiff, the complaint seeks to represent a nationwide class of affected users. While the $500 million estimate remains preliminary, the filing notes that total damages could scale significantly higher depending on the number of customers who fell victim to similar impersonation attacks.

Comments (0)
No comments yet. Be the first!