Ledger is facing another customer data leak after on-chain investigator ZachXBT disclosed on January 5, 2026 that users of the hardware wallet maker were affected by a fresh exposure of personal information. The report spread quickly across the crypto community, with several users reposting the warning and sharing screenshots of notification emails received by affected customers.
Global-e identified as the source of the exposure
The incident was not described as a direct compromise of Ledger’s own systems. Based on the information disclosed so far, the leak stemmed from a security flaw at Global-e, a payment service provider that works with Ledger. The exposed data reportedly included customer names, physical addresses, and phone numbers. Seed phrases, passwords, and private keys were not part of the leak.
That distinction matters, but it does not remove the danger. Once contact details are exposed, attackers can build targeted phishing campaigns, pose as official support staff, or send fraudulent emails and text messages designed to push users into revealing recovery phrases or installing fake update software.
The 2020 breach still shapes user concerns
This is not the first time Ledger has dealt with a customer data incident. In 2020, the company’s ecommerce database was breached, exposing more than 1 million customer email addresses along with some personal information. That breach was followed by years of phishing attempts, as scammers used the leaked data to send fake messages aimed at collecting wallet recovery phrases. Some users later reported asset losses.
The new case, tied to a third-party provider rather than Ledger itself, puts supply-chain security back in focus. User funds are not said to be directly at risk from this specific incident. Even so, leaked identity and contact data can create long-term exposure by making social engineering attacks more convincing.
Users urged to treat recovery phrase requests as red flags
Security guidance shared around the incident centers on skepticism. Users are advised to treat any unexpected Ledger-related email, SMS, or phone call with caution, especially messages asking for a 24-word recovery phrase, requesting a device reset, or urging the download of update software.
Other recommended steps include using a dedicated email account for crypto activity, enabling two-factor authentication, and reviewing wallet authorization records on a regular basis. Users who received a breach notification email are also advised to check Ledger’s official website directly for the latest statement rather than following links embedded in the message.

