What it makes
Ledger sells small devices that hold a Bitcoin private key and sign with it. The point of the design is that the key is generated inside a Secure Element chip and never leaves it. The computer or phone the device is plugged into builds the transaction and asks for a signature. It never sees the seed, so a compromised computer cannot spend the coins on its own. The screen on the device is the other half of the idea: the user confirms the amount and the destination on hardware the attacker does not control.
The company's own brand statement dates the work from 2015, and describes the starting
point as "using a secure element chip to protect digital assets for crypto enthusiasts".
This entry gives no founded year. That page dates the work rather than the company, and
no primary record of the company's formation was opened here, so the spec's instruction to
omit rather than approximate applies. The same page states that more than 8 million Nano signing devices have been sold, and lists
the current line as Ledger Stax, Ledger Flex and Ledger Nano Gen5, read in August 2026.
The legal entity is a simplified joint-stock company under French law, registered office at 106 rue du Temple, 75003 Paris, share capital 1,224,265 euros, entered on the Paris Trade and Companies Register under number 529 991 119. That detail is on Ledger's own legal page.
On the record
A marketing database was breached in 2020. The devices were not. Keeping those two apart is the whole substance of this section.
Ledger's disclosure states that on 25 June 2020 an unauthorised third party reached part of its e-commerce and marketing database through an API key. A researcher on Ledger's bug bounty programme reported it on 14 July 2020, and the company says it fixed the hole the same day. Ledger notified the CNIL, the French data protection authority, on 17 July 2020, engaged Orange Cyberdefense to assess the damage, notified customers on 29 July, and filed a complaint with the French public prosecutor on 5 August 2020.
What was exposed, in Ledger's own accounting: approximately 1 million email addresses, plus 9,532 records that also held first and last name, postal address and phone number. On 20 December 2020 the stolen data was published on a public forum, and Ledger's chief executive then stated that "approximately 272,000 detailed information such as postal address, last name, first name and telephone number" had in fact been leaked, a larger subset than the July figure. A separate theft at Shopify, notified to Ledger on 23 December 2020, affected about 292,000 Ledger customers, of whom roughly 20,000 were not in the earlier set.
Ledger's statement on what was not touched is explicit: the breach "has no link nor impact on our hardware wallets, the app or your funds." No seed, no key and no firmware was involved, because none of that is held by the company in the first place. The harm was of a different kind. Customers whose home addresses were now public received phishing email, text messages impersonating Ledger and asking for the 24-word recovery phrase. Ledger says it worked with Chainalysis, the FBI and the Royal Canadian Mounted Police on the resulting investigations.
