Breach report
CryptoLedger
Physical addresses of 270K Ledger owners leaked on hacker forum
Contact details stolen from hardware-wallet maker Ledger, including home addresses of more than 270,000 buyers, were dumped publicly, fueling years of phishing and alarming threats against crypto holders.
Reported by BleepingComputer
Records exposed
1.1M
About 1.08 million email addresses, including 272,853 with full contact details
Scale vs. largest on file
- When
- 2020
- How they got in
- Unauthorized access to e-commerce and marketing database via website vulnerability
- Sector
- Crypto
In July 2020, French hardware-wallet maker Ledger announced that an unauthorized party had accessed its e-commerce and marketing database the previous month. The company said the attacker exploited a flaw on its website to reach customer contact information, and that the issue was fixed once discovered. At the time, Ledger said about 1 million email addresses had been exposed, along with more detailed information for a smaller group of customers.
The incident escalated sharply on December 20, 2020, when the full dataset was posted for free on a popular hacking forum. It contained 1,075,382 email addresses from newsletter subscribers and customers, plus 272,853 records with the names, mailing addresses and phone numbers of people who had ordered Ledger devices. The public dump meant anyone, not only the original thief, could now identify and locate owners of a device used to store cryptocurrency.
Ledger emphasized that no funds, recovery phrases or payment information were compromised, and that the wallets themselves remained secure. The problem was the link between a real-world identity and likely crypto ownership. Even before the dump, customers had reported waves of phishing emails and text messages impersonating Ledger, often urging them to download fake versions of its Ledger Live software or enter their recovery phrases on bogus sites, which would give attackers control of their coins.
After the public leak, some victims reported receiving threatening messages demanding payment, and security experts warned that exposed home addresses could invite physical robbery. Ledger faced criticism for underestimating the scope of the breach in its initial disclosure and for how long the data had been circulating. The company said it was working with authorities to pursue those behind the leak and was pushing to take down phishing sites impersonating its brand. A class-action suit was filed in the United States on behalf of affected customers.
The Ledger breach became a cautionary tale for any company selling security products to cryptocurrency users. Its core product was never compromised, yet a marketing database revealed exactly who was worth targeting. It illustrated why businesses in the crypto sector should minimize the customer data they retain and why buyers of hardware wallets increasingly use alternate shipping addresses and dedicated email accounts.