Ledger said on December 20, 2020, that it had been alerted to a public dump of a customer database on the RaidForums forum. The hardware-wallet manufacturer was still authenticating the files, but said early indications pointed to the e-commerce database compromised in June 2020.

The disclosure mattered beyond the size of another corporate data breach. A hardware wallet was designed to keep private keys away from an internet-connected custodian, yet customers had still supplied names and delivery details to a centralized merchant. Publishing those records potentially connected identifiable people and their homes with the purchase of cryptocurrency-security equipment.

A breach already known, but not at this scale

Ledger had disclosed the underlying intrusion on July 29, 2020. Its account said an unauthorized party used a third party’s API key to enter its e-commerce and marketing database on June 25. The company estimated that approximately 1 million email addresses had been exposed, while a subset of about 9,500 customers also had information such as names, postal addresses, telephone numbers or ordered products exposed.

That July estimate defined what customers and the public understood before December 20. Ledger said payment information, account credentials, recovery phrases and private keys were not part of the affected database. It also distinguished the commercial database from the hardware wallets and Ledger Live software.

The public dump changed the known scope. CoinDesk reported late on December 20 that the released files contained approximately 1 million email addresses and 272,000 records containing names, mailing addresses and phone numbers. The detailed-record figure was nearly 29 times Ledger’s July estimate of 9,500. The comparison is a calculation based on those two rounded figures, not a count independently performed by Coinburn.

Have I Been Pwned added the Ledger breach to its notification database on December 20. Its surviving entry rounds the number of affected email addresses to 1.1 million and identifies names, telephone numbers and physical addresses among the compromised fields. Those email and detailed-record totals should not be added together: the smaller collection substantially overlapped the larger email list.

Why contact data altered the threat model

Nothing in the records reviewed for this reconstruction shows that the database contained cryptocurrency balances, blockchain addresses, seed phrases or private keys. The dump therefore did not itself establish that a wallet could be opened or funds transferred.

Its significance was the opportunity for targeted attacks. An email address could support phishing; a telephone number could support impersonation or account-recovery abuse; and a delivery address could identify a household that had purchased a hardware wallet. Ownership of a device did not prove that the buyer still possessed it or held any cryptocurrency, but an attacker could make that assumption.

This exposed a boundary in the self-custody model. A customer could remove cryptographic keys from an exchange while remaining dependent on manufacturers, storefronts and marketing providers to minimize and secure ordinary personal data. The device and the purchasing trail represented separate security systems with different failure modes.

What remained uncertain on December 20

Ledger’s authentication was preliminary on December 20, and Coinburn did not obtain or inspect the stolen files because reproducing or handling victim data was unnecessary to verify the event. The exact number of unique people, the accuracy of every record and the extent to which the information had circulated before the free release could not be established from the event-day record.

Later confirmation

On January 13, 2021, Ledger confirmed that the stolen databases had been made publicly available on December 20 and said approximately 272,000 customer records included names, addresses and phone numbers, in addition to more than 1 million email addresses. That later statement clarifies the December event; it was not information fully confirmed when Ledger issued its initial alert.

Primary sourceLedger communications about the breach and December 20 database alert

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.