Ledger says a recent customer data exposure came from Global-e, its third-party ecommerce partner, and did not affect wallet infrastructure, private keys, recovery phrases, or crypto holdings. The company framed the incident as an external vendor issue rather than a compromise of Ledger’s own systems.
Exposed data was tied to purchases and shipping
In a January support update, Ledger said the unauthorized access took place in systems operated by Global-e, a merchant-of-record provider that handles international orders placed through Ledger’s online store. The company said the exposed information was limited to order-related customer records, including names, contact details, and shipping information linked to purchases. Payment card details, wallet balances, recovery phrases, and private keys were not part of the breach.
Ledger said Global-e detected suspicious activity in part of its cloud environment and then notified the wallet maker. After that, Global-e contained the incident and began contacting affected customers directly. Ledger noted that Global-e acts as the data controller for checkout information, which is why customer notifications are being handled by the partner.
Ledger draws a line between order data and wallet security
In its public response, Ledger repeated that its hardware wallets use a self-custodial model. Private keys and recovery phrases stay on the device and are not accessible to outside service providers. The company also said the incident did not affect its products, firmware, or cryptographic systems.
Details of the breach spread quickly on social media. Onchain investigator ZachXBT posted on X that Ledger had suffered another data leak through payment processor Global-e, exposing customer names and other contact information. Complaints from users followed soon after, showing how sensitive any personal-data incident remains for the company.
Phishing risk returns to the center
Ledger warned customers to watch for phishing attempts that could use exposed contact details. The company said it will never ask users to share recovery phrases or sensitive wallet information by email, phone call, or direct message. That warning sits at the center of the fallout.
Ledger did not say how many customers were affected. It said it is cooperating with Global-e and supporting an ongoing forensic investigation to determine the scope of the incident, with independent security experts involved in the review. The episode has also revived attention on Ledger’s 2020 ecommerce and marketing database breach. That earlier case did not expose wallet data either, but it was followed by long-running phishing campaigns and harassment attempts targeting affected users.
The latest Global-e case puts the spotlight back on third-party service risk. Ledger’s core wallet systems may have remained secure, but exposure of order and contact records still creates an opening for social-engineering attacks.

