Skip to main content
Breach Signal

Breach report

Crypto

Ledger

Physical addresses of 270K Ledger owners leaked on hacker forum

Contact details stolen from hardware-wallet maker Ledger, including home addresses of more than 270,000 buyers, were dumped publicly, fueling years of phishing and alarming threats against crypto holders.

Reported by BleepingComputer

Records exposed

1.1M

About 1.08 million email addresses, including 272,853 with full contact details

Scale vs. largest on file

When
2020
How they got in
Unauthorized access to e-commerce and marketing database via website vulnerability
Sector
Crypto

In July 2020, French hardware-wallet maker Ledger announced that an unauthorized party had accessed its e-commerce and marketing database the previous month. The company said the attacker exploited a flaw on its website to reach customer contact information, and that the issue was fixed once discovered. At the time, Ledger said about 1 million email addresses had been exposed, along with more detailed information for a smaller group of customers.

The incident escalated sharply on December 20, 2020, when the full dataset was posted for free on a popular hacking forum. It contained 1,075,382 email addresses from newsletter subscribers and customers, plus 272,853 records with the names, mailing addresses and phone numbers of people who had ordered Ledger devices. The public dump meant anyone, not only the original thief, could now identify and locate owners of a device used to store cryptocurrency.

Ledger emphasized that no funds, recovery phrases or payment information were compromised, and that the wallets themselves remained secure. The problem was the link between a real-world identity and likely crypto ownership. Even before the dump, customers had reported waves of phishing emails and text messages impersonating Ledger, often urging them to download fake versions of its Ledger Live software or enter their recovery phrases on bogus sites, which would give attackers control of their coins.

After the public leak, some victims reported receiving threatening messages demanding payment, and security experts warned that exposed home addresses could invite physical robbery. Ledger faced criticism for underestimating the scope of the breach in its initial disclosure and for how long the data had been circulating. The company said it was working with authorities to pursue those behind the leak and was pushing to take down phishing sites impersonating its brand. A class-action suit was filed in the United States on behalf of affected customers.

The Ledger breach became a cautionary tale for any company selling security products to cryptocurrency users. Its core product was never compromised, yet a marketing database revealed exactly who was worth targeting. It illustrated why businesses in the crypto sector should minimize the customer data they retain and why buyers of hardware wallets increasingly use alternate shipping addresses and dedicated email accounts.

More from the wire

More in Crypto.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.