On 20 December 2020 Ledger was told that a customer database had been dumped on RaidForums. The company said it looked like the e-commerce and marketing database stolen in June, which it had disclosed in July after a third-party API key was abused. July’s forensic read of logs had put detailed records at about 9,500 people plus roughly a million emails. The public file showed about 272,000 names, postal addresses and phone numbers. Devices, firmware, keys and recovery phrases were not in that shop database. Ledger emailed the larger subset on 21 December.
A later Shopify-support-agent export (noticed around 23 December) added more records — later, and still not the device. The 2024 Trezor helpdesk leak and the 2026 ShipMonk parcel leak are cousins: different vendor, same lesson. Do not collapse them.
What happened
You can keep coins on a metal wallet and still appear in a company’s order book. Attackers who have a name, a phone and proof you bought a Ledger do not need to break the Secure Element. They need a convincing email or a knock. That is the harm model.
Why it matters
If you bought from Ledger in that window, treat unexpected “firmware”, “reset” or “support” mail as hostile. Nobody at Ledger needs your 24 words. See how crypto wallets actually work, what cold storage is, and the practical checklist. The device being fine is not the same as the inbox being fine.
What happens next
Years of phishing, a few physical threats that used the addresses, and a long reminder that a shop is a company. We will not tell you to throw the hardware away. Nothing here is a review score or a prompt to move coins tonight.






