Close Menu
Crypto Valley Journal
    Facebook X (Twitter) Instagram
    Crypto Valley Journal
    • Hot Topics
      • News
      • Minds
    • Focus
      • Background
      • Blockchain
      • Legal & Compliance
      • Non-Fungible Token (NFTs)
    • Investing
      • Markets
      • Financial Products
      • Decentralized Finance (DeFi)
      • Exchange overview
    • Education
      • Basics
      • Glossary
      • Politicians on crypto
    • Statistics
      • Bitcoin-ETF-Flows
      • Ethereum-ETF-Flows
      • Crypto market data
      • On-chain data
    • Academy
      • Overview
      • Part 1: Blockchain
      • Part 2: Money
      • Part 3: Bitcoin
      • Part 4: Cryptocurrencies
      • Part 5: Decentralized Finance
      • Part 6: Investing
    • English
      • Deutsch
    Crypto Valley Journal
    You are at:Home»Hot Topics»News»Ledger user data leaked again
    Ledger user data leaked again

    Ledger user data leaked again

    By CVJ.CH Content Partner BeInCrypto on 21. December 2020 News

    Hardware wallet manufacturer Ledger has suffered another massive data breach for the second time this year. The exposure of thousands of clients’ personal information has increased the threat of SIM swapping as an attack vector.

    For the second time this year, personal data from Ledger wallet buyers has been dumped online. The leak was posted by several members of the crypto community who found files allegedly containing the ‘full database’ of Ledger customers containing emails, phone numbers, and even physical addresses.

    Major data leak

    Ledger published a statement on Twitter, claiming it was old data from the June 2020 server breach.

    Today we were alerted to the dump of the contents of a Ledger customer database on Raidforum. We are still confirming, but early signs tell us that this indeed could be the contents of our e-commerce database from June, 2020.

    — Ledger (@Ledger) December 20, 2020


    A wave of phishing attacks followed the breach from June. Ledger originally claimed that only around 9'500 users were affected, but it now turns out to be as many as 270'000. Industry researchers called it "unforgivable". Hasu, Writer for Deribit Insights, said that "you simply can’t sell hardware wallets and store the personal information of your customers on an online server." In order to make Ledger take physical security more seriously, he recommended cutting off business with them completely.

    Analyst Larry Cermak, Director of Research for The Block, said this latest leak was "much much worse" than the last;

    This Ledger leak is much much worse than I thought. Did some cross checks with people that have purchased Ledgers and the hit rate (anecdotally) is like 50%. The info includes home addresses as well as phone numbers.

    — Larry Cermak (@lawmaster) December 20, 2020

    There is also now an inherent danger that SIM swapping attacks will be used to target Ledger customers now that their phone numbers and addresses have been leaked.

    What is SIM swapping and how to avoid it?

    SIM swapping occurs when an attacker contacts the victim’s wireless/mobile carrier and is able to convince the call center employee that they are the victim using stolen personal data. With an arsenal of new data including email addresses, the phone number itself, and even physical addresses for Ledger users, this would be relatively easy to pull off for cybercriminals.

    The attacker then asks the provider to activate a new SIM card connected to the victim’s phone number on a new phone in their possession. With this, they can access the 2FA security measures used by Ledger devices and crypto exchanges. What happens next is inevitable — an emptied hardware wallet.

    Industry analyst Alex Krüger has warned of an impending wave of SIM swapping attacks following the Ledger leak. Since phone numbers were leaked and smartphones are normally used to authenticate transactions, the fallout could be devastating;

    The personal data of 272,000 Ledger buyers has been leaked. If your data was compromised, make sure you are not using your number for 2FA anywhere. Change to a VoIP number, or GA. Alternatively, contact @haseeb a bitcoin OG whose company provides protection against sim swapping.

    — Alex Krüger (@krugermacro) December 21, 2020

    The U.S. Federal Trade Commission issued a warning and prevention guide which includes suggestions on limiting the sharing of personal information. However, when companies that are trusted with security cannot secure data themselves, what hope has the consumer got? As a number of Ledger users have painfully found out, crypto-assets can be easily stolen from hardware wallets. The victims are left to suffer alone when it happens as there is usually little-to-no recourse whatsoever from the manufacturers.

    Share. Facebook Twitter LinkedIn Email Telegram WhatsApp

    About the author

    CVJ.CH Content Partner BeInCrypto
    • Website

    BeInCrypto is a news website founded in August 2018 that specializes in cryptographic technology, privacy, fintech, and the Internet — among other related topics. The primary goal is to inject transparency into an industry rife with disingenuous reporting, unlabeled sponsored articles, and paid news masquerading as honest journalism.

    Related Articles

    Robinhood misses Q1 2026: crypto revenue halved to 134 million USD, stock falls 11 percent. Schwab and Coinbase intensify competition.

    Robinhood misses Q1 estimates: Crypto revenue cut in half

    OKX, BlackRock and Standard Chartered launch a joint framework that makes tokenized RWAs usable as margin collateral under G-SIB custody.

    OKX, BlackRock and Standard Chartered use tokenized treasuries as collateral

    Hoskinson calls support of the CLARITY Act by Garlinghouse and the XRP community insanity and accuses Ripple of harming the industry.

    XRP vs. Cardano: Hoskinson calls CLARITY Act support “insanity”

    Robinhood misses Q1 2026: crypto revenue halved to 134 million USD, stock falls 11 percent. Schwab and Coinbase intensify competition.
    30. April 2026

    Robinhood misses Q1 estimates: Crypto revenue cut in half

    Canada announces national crypto ATM ban. Roughly 4,000 machines are affected as Ottawa targets fraud and money laundering.
    29. April 2026

    Canada bans crypto ATMs

    OKX, BlackRock and Standard Chartered launch a joint framework that makes tokenized RWAs usable as margin collateral under G-SIB custody.
    29. April 2026

    OKX, BlackRock and Standard Chartered use tokenized treasuries as collateral

    twitter image button instagram image button linkedin image button youtube image button

    About Crypto Valley Journal
    About Crypto Valley Journal

    On the pulse of the movement

    • Academy
    • Contact
    • Advertising
    • About us
    • Partner
    • Imprint
    • Privacy
    • Disclaimer
    Search

    Type above and press Enter to search. Press Esc to cancel.