Ledger, the French hardware wallet manufacturer, is facing a storm of backlash after its e-commerce customer database was leaked for free on the hacker forum Raidforums on December 20, 2020. The breach exposed the emails, phone numbers, and residential addresses of approximately one million customers, prompting legal threats, ransomware attempts, and intense criticism from the cryptocurrency community.
The Leak and Initial Reactions
The dumped data includes not only email addresses but also physical addresses and phone numbers, making customers vulnerable to targeted phishing and even physical threats. Social media exploded with anger. One Twitter user wrote: “Ledger, how in the hell does that happen with a business whose primary focus should be nothing but security? This is unacceptable and inexcusable.” Many echoed the sentiment, accusing Ledger of failing its core mission.
Legal Actions Underway
The law firm Roche Cyrulnik Freedman LLP (RCFLLP) quickly announced an investigation into the breach. Partner Kyle Roche tweeted: “RCFLLP has launched an investigation into the Ledger data breach incident. If you own a Ledger device and lost any of your crypto holdings due to a phishing attack on your device, please reach out to me.” Another Ledger customer directly threatened legal action in a reply to Ledger’s official Twitter account: “I’m going to take legal action against you very soon.”
Ransom and Home Invasion Threats
Perhaps the most alarming consequence was the extortion attempt reported by a Ledger customer. The victim shared an email screenshot in which the blackmailer demanded $500, threatening to show up at the customer’s home with a wrench if the payment was not made. The email read: “If not, I’m not afraid to show up when you least expect it and see how my wrench works against your face, or maybe even wait for you to leave your home and take your belongings while you’re not there to call the police.” The hacker cynically noted that the recent crypto price pump should make the payment easy. Software engineer Jameson Lopp, who shared the screenshot, commented: “Strap in for scareware.” Another user joked that he had provided fake information to Ledger, so the threat was ineffective.
Ledger CEO’s Stance: No Reimbursement
In an interview with Decrypt, Ledger CEO Pascal Gauthier firmly stated that the company would not compensate customers. “When you have a data breach of this magnitude for such a small company, we won’t reimburse for a million users, all the devices, that’s just not possible,” Gauthier said. This stance has further inflamed the community, with many questioning Ledger’s commitment to security. As of now, Ledger has advised users to be vigilant against phishing attempts but has not announced any concrete remediation for the affected customers. The incident serves as a stark reminder that even hardware wallets — often hailed as the safest option for crypto storage — are not immune to data security failures on the corporate side.

