Ledger (Ledger SAS, Paris, founded 2014) is the largest hardware-wallet vendor by units shipped and has shaped the mainstream perception of "hardware wallet." The current line spans roughly 399: the Nano S Plus (149), Nano Gen5 (249, E-Ink), and Stax ($399, curved E-Ink). For Bitcoin self-custody, Ledger is the most controversial mainstream vendor, for three substantive reasons. The 2020 customer-data leak exposed 270,000+ customers' names, addresses, and phone numbers; that database is now actively used by criminals to identify physical-attack targets. The 2023 Ledger Recover service introduced a firmware-level capability to exfiltrate the seed off the device — a structural change critics argue undermines the "keys never leave the device" guarantee. The firmware is closed-source and the secure-element interface proprietary, the weakest open-source posture among mainstream vendors. Ledger remains a functional hardware wallet, but the structural questions are real and the alternatives (Coldcard, BitBox, Trezor, Passport, Jade) are now good enough that Bitcoin-only holders have less reason to choose it than in 2018.


Why this note matters

Ledger is unique in this section because the synthesis treats it with substantively more concern than the other mainstream hardware wallets. The note matters because:

  • Many holders already own one. Ledger’s market position means a substantial fraction of self-custody holders have a Ledger as their first or primary hardware wallet — the framework should engage what those holders should do, not just what new buyers should choose.
  • The 2023 Recover controversy is a real shift in security model. The firmware-level capability to exfiltrate the seed is structurally different from anything competitor devices do; it is not a minor PR matter.
  • The 2020 customer-data leak has downstream physical-attack consequences. Per Lopp’s Physical Bitcoin Attack database, leaked Ledger customer data is part of the targeting pipeline for the 2024–2025 surge in physical attacks.
  • The framing should be honest rather than ideological. Ledger remains a functional hardware wallet, and Casa, Unchained, and other collaborative-custody providers still support it as one allowed device — the caution is substantive, not partisan.

What this is

Vendor: Ledger SAS (Paris, France, founded 2014 by Eric Larchevêque, Joel Pobeda, Nicolas Bacca, Thomas France, and Olivier Tomaz). Ledger is the largest hardware-wallet company globally by units shipped (estimated >7 million devices as of 2025). The company has raised substantial venture capital and operates as a major Bitcoin and crypto infrastructure business.

Product line as of 2026-07-15:

  • Ledger Nano S Plus ($79) — USB-only, smaller; budget option
  • Ledger Nano X ($149) — Bluetooth-enabled, larger screen than predecessors; the most common model in the field
  • Ledger Nano Gen5 ($179) — new-generation Nano introduced in late 2025
  • Ledger Flex ($249) — flat e-ink touchscreen; positioned between the Nano line and the Stax
  • Ledger Stax ($399) — curved e-ink touchscreen; the premium-aesthetic option

Firmware: Closed-source. The firmware that runs on Ledger devices is not publicly auditable. Ledger has published portions of supporting code (the BOLOS operating system has some open-source components; the apps that run on top can be open-source) but the secure-element interface and the core signing firmware are proprietary. This is the weakest open-source posture among mainstream hardware-wallet vendors.

Secure element: ST33 or ST33K (STMicroelectronics; EAL5+ or EAL6+ depending on model). Strong physical-attack resistance; this is genuinely good engineering. The trade-off is that the secure element’s behaviour is proprietary and cannot be independently verified.

Multi-coin support: Ledger supports dozens of cryptocurrencies, not just Bitcoin. Each cryptocurrency is implemented as an “app” installed on the device. Multi-coin support is a marketing positive for some users; for Bitcoin-only purists it is attack-surface expansion.


The three specific concerns

1. The 2020 customer-data leak

In June and July 2020, a Ledger e-commerce database was breached. The leak exposed:

  • 1 million email addresses
  • 270,000+ full customer records including name, postal address, phone number, and ordered product details

This data is now public and indexed by criminals. The downstream consequences:

  • Physical-attack targeting. Holders are identifiable as hardware-wallet owners with specific addresses. Per Lopp’s Physical Bitcoin Attack database, the database has been used to identify victims in multiple incidents.
  • Phishing campaigns. The email list has been used for sophisticated Ledger-impersonation phishing attacks; some have specifically referenced personal details from the leak.
  • Long-term targeting risk. Unlike a password compromise, leaked physical addresses cannot be reset. A Ledger purchaser from 2018–2020 is permanently identifiable to anyone with access to the leaked database.

Ledger’s response to the leak has been substantive (security improvements, customer notifications, ongoing legal action against the leaker) but the data is in the wild and cannot be retracted.

Implication for current holders: Existing Ledger users who appear in the leak should treat their home address as compromised in their threat model. This affects Threat modeling for self-custody specifically — the local physical attackers category becomes more salient.

Implication for new buyers: Buying a Ledger creates a new customer record. Whether the customer database is at greater risk than competitor databases is debatable; the empirical record is that Ledger’s database has been breached and others have not (at least not publicly).

2. The 2023 Ledger Recover service

In May 2023, Ledger announced the Ledger Recover service — a paid subscription that allows users to back up their seed phrase off-device, with the encrypted seed shards held by three custodians (Ledger, Coincover, Onfido). The recovery process involves identity verification, after which the three custodians cooperate to restore the seed.

The controversy: implementing Recover required a firmware change that gives the device the capability to exfiltrate the seed off the secure element. Users who do not opt into Recover still have a device whose firmware can do this. The structural argument: a device that can exfiltrate the seed has a fundamentally different security model than a device that cannot.

Ledger’s position:

  • Users must opt in to Recover; the seed is never exfiltrated without explicit user consent
  • The firmware-level capability is a technical necessity for the service to exist
  • The secure-element guarantees still hold for non-Recover users
  • The service serves a legitimate user need (recovery support for holders who cannot maintain backup discipline)

The critique (articulated by Lopp, BitBox, Coldcard, and others):

  • The marketing of hardware wallets (“keys never leave the device”) implicitly relied on the fact that they couldn’t leave. The 2023 change makes this an opt-in matter rather than a structural guarantee.
  • The closed-source firmware means users cannot verify what conditions actually trigger seed-exfiltration. They must trust Ledger’s assurances.
  • The service introduces three new counterparties (Ledger, Coincover, Onfido) whose policies, security practices, and regulatory exposures the holder cannot easily audit.
  • Subpoena risk: the three custodians are subject to court orders in their respective jurisdictions; users with Ledger Recover have a legal-exposure footprint they may not have understood.

The synthesis’s read: The Recover service is a legitimate product for a specific user need. The firmware-level capability that enables it is the load-bearing concern — it changes the security model in a way users buying Ledger before 2023 may not have understood and may not have accepted.

Implication for current holders: Ledger users (especially Bitcoin-only holders who do not use Recover) should engage the question of whether the device’s firmware capability meaningfully changes their threat model. For many holders the answer is “minor concern, but not a deal-breaker”; for others it is reason to migrate to a different vendor.

Implication for new buyers: Knowing about Recover is part of the informed decision. Holders who would not opt into Recover and who can articulate why the firmware capability doesn’t bother them can reasonably buy Ledger. Holders who find the firmware capability structurally objectionable should choose a different vendor.

3. Closed-source firmware

The Ledger firmware is not publicly auditable. The BOLOS operating system has some open-source components, and individual coin apps can be open-source, but the core secure-element interface and the signing firmware are proprietary.

The argument for closed-source: the secure-element vendor (STMicroelectronics) requires NDAs to interface with the chip’s full capabilities. Opening the firmware would either eliminate access to the secure element’s features or violate the NDA.

The argument against: closed-source firmware cannot be independently verified. Users must trust Ledger’s internal security practices, audit results (which are sometimes published), and bug-disclosure track record. The competitive landscape now includes vendors (BitBox02, Trezor, Foundation Passport, Blockstream Jade) that achieve secure-element-level physical-attack resistance with at least partial open-source firmware. The “secure element requires closed-source” argument has been undermined empirically.

The synthesis’s read: closed-source firmware is a real disadvantage versus open-source competitors. It is not a deal-breaker in isolation but combined with the Recover-firmware-capability concern, the closed-source nature means users cannot verify what the firmware does.


Who this is for

Ledger remains a reasonable fit for:

  • Existing Ledger users who have made informed decisions — holders who own Ledgers, do not use Recover, have engaged the considerations, and are comfortable with the trade-offs
  • Mainstream multi-coin users — for holders who actually use Ledger to manage Bitcoin alongside altcoins, Ledger’s multi-coin support is the best in the field
  • Ledger Stax / Flex aesthetic-prioritizing users — the design is genuinely premium; for some holders this matters
  • Collaborative-custody users where the partner supports Ledger — Casa, Unchained, and others still support Ledger as one allowed device

Ledger is less appropriate for:

  • New Bitcoin-only buyers who are unaware of the considerations above — these holders are better served by BitBox02, Trezor, Foundation Passport, or Coldcard
  • The strictly open-source-aligned — Ledger’s closed-source firmware is the weakest open-source posture among mainstream vendors
  • Holders concerned about KYC-data correlation with physical attacks — the 2020 leak is structurally a concern that competitor devices don’t have to the same degree
  • Sovereignty-first holders — the Recover firmware capability is structurally at odds with the strongest sovereignty position

Features and capabilities

Ledger devices share most operational features with their competitors:

  • PSBT support — modern Ledger firmware handles PSBT well
  • BIP-380 descriptor support — multisig works across coordinators
  • Native multisig — standard 2-of-3, 3-of-5 configurations supported
  • BIP-39 passphrase support — entered on device
  • BIP-85 — supported but with limited variants
  • Strong multisig signing performance — Ledger handles large PSBTs well per Lopp’s reports
  • Bluetooth (Nano X, Stax, Flex) — convenient for mobile; some holders disable it for paranoia reasons

The principal capability discussion is not the technical features but the considerations above.


Tradeoffs vs alternatives

DimensionLedger Nano XColdcard Mk4BitBox02 BTC-onlyTrezor Safe 5Foundation Passport
Price$149$150$137$129$199
Bitcoin-onlyNo (multi-coin)YesYesNoYes
Open-source firmwareNo (closed)Source-availableYes (OSI)Yes (GPL)Yes (OSI)
Secure elementYes (EAL5+/6+)YesYesYes (EAL 6+)Yes
Air-gap signingNo (USB / Bluetooth)MicroSD onlyNoNoYes (strict QR-only)
Public customer-data leakYes (2020)NoNoNoNo
Seed-exfiltration firmware capabilityYes (since 2023)NoNoNoNo
Multi-vendor multisig pairingYes (functional)YesYesYesYes
Lopp 100-input signingFastFastFastModerateFast

The capability comparison is largely competitive; the structural considerations are the differentiators. Ledger’s strengths (multi-coin support, mainstream UX, strong signing performance) and weaknesses (closed-source firmware, 2020 leak, 2023 Recover) are clearly drawn.


What existing Ledger holders should do

The synthesis’s pragmatic advice for holders who already own a Ledger:

If you own a Ledger and do not use Recover, and the 2020 leak concern is acceptable to you:

  • Continue using the device for its intended purpose. The device works; the multisig support is good; the cryptography is sound.
  • Engage the 2020 leak as a threat-model input. If the home address was in the leaked database, treat the local-physical-attacker category as more salient than otherwise.
  • Stay informed on firmware updates. Ledger publishes security advisories; the disclosure track record is reasonable.
  • Consider the device part of a multi-vendor multisig rather than a sole signer for Tier 2+ holdings.

If you own a Ledger and the considerations bother you enough that you would not buy a new one today:

  • Migrate at a convenient time. Sweep funds from the Ledger-signed wallet to a new wallet using a different device.
  • Use the Ledger for non-load-bearing purposes — testing, learning, secondary signing.
  • The migration is straightforward operationally; the principal cost is the new hardware-wallet purchase and the operational time.

If you use Ledger Recover:

  • Engage what Recover actually does. The seed is in encrypted shards held by Ledger, Coincover, and Onfido. The three custodians cooperate to restore.
  • Know that the firmware-level seed-exfiltration capability is what makes Recover work; this is the structural property the critique focuses on.
  • Decide whether the recovery support is worth the structural trade. For some holders it is. For others it is not.

Setup and operation

The setup flow:

  1. Verify packaging — Ledger ships with tamper-evident packaging
  2. Initialize via Ledger Live or another coordinator — Ledger Live is the official companion
  3. Generate seed — 24 words displayed on device screen; the holder records them
  4. Verify the seed — on-device check
  5. Optionally set up a passphrase — entered on device
  6. Install Bitcoin app on the device — the multi-coin architecture requires explicit per-coin app installation
  7. Pair with a coordinator — Ledger Live for single-sig (and basic multisig); Sparrow, Specter, Nunchuk for substantive multisig

The signing flow is standard for hardware wallets: PSBT in, verify on device, sign, PSBT out.


Security considerations

Strengths

  • Strong secure element — EAL5+/6+ certified; physical-attack resistance is good
  • Strong multisig signing performance — well-implemented PSBT handling
  • Long vendor track record — Ledger has been shipping since 2014
  • Mainstream coordinator support — every coordinator supports Ledger

The three concerns above

The 2020 leak, the 2023 Recover firmware capability, and the closed-source firmware are the substantive considerations. Each is worth engaging on its own terms.

Supply-chain integrity

Buy directly from ledger.com or authorized resellers. Tamper-evident packaging.

The 2020 leak affects historical Ledger customers; new purchases create new records. Holders concerned about KYC-data correlation should consider shipping options (non-residential addresses, etc.).


Pricing and acquisition

As of 2026-07-15 (prices reverified; prior review 2026-05-14):

  • Ledger Nano S Plus: $79 USD
  • Ledger Nano X: $149 USD
  • Ledger Nano Gen5: $179 USD (new-generation Nano, late 2025)
  • Ledger Flex: $249 USD
  • Ledger Stax: $399 USD

Authorized channels: ledger.com directly; authorized resellers. Avoid generic marketplaces given the supply-chain considerations.


Common pitfalls

Adopting Ledger as a first hardware wallet without engaging the considerations. This is the dominant pattern in the broader market — Ledger is recommended by mainstream Bitcoin onboarding flows because of its market position and brand recognition. New buyers should engage the considerations before defaulting.

Treating the 2020 leak as a closed chapter. The data is in the wild and continues to be used. Holders affected by the leak should treat their home address as compromised in their threat model permanently.

Opting into Recover without understanding the trade. Recover is a real product with real benefits for the right user — but the trade is significant and should be made deliberately.

Treating the closed-source firmware as a non-issue. It is a real disadvantage versus open-source competitors; not necessarily a deal-breaker but worth engaging.

Three identical Ledgers in multisig. Same vendor-diversity pitfall. Ledger’s closed-source firmware and 2023 Recover capability make multi-Ledger setups structurally weaker than diversified configurations.

Buying via generic marketplace. Supply-chain integrity concerns apply with extra weight given Ledger’s market position (counterfeit risk is higher for popular products).

Continuing to use Ledger out of inertia after the considerations would have led you elsewhere. Migration is operationally straightforward; sunk-cost in the device is not a reason to continue if the considerations have shifted.


Tooling and resources

Ledger documentation (as of 2026-05-14):

  • ledger.com — official site
  • Ledger Live — official companion app
  • Ledger’s bug bounty and security advisories — published

Coordinator software supporting Ledger:

  • Ledger Live — official, single-sig and basic multisig
  • Sparrow Wallet, Specter Desktop, Nunchuk — multisig
  • Bitcoin Core (with PSBT)
  • Casa, Unchained — collaborative-custody platforms

Critical writing on the considerations:

  • Lopp’s discussion of the 2020 leak and its physical-attack implications; see Jameson Lopp
  • BitBox’s published commentary on the 2023 Recover firmware change
  • Coldcard team’s commentary on the same
  • The broader Bitcoin Twitter / X discussion around Recover (substantial; partisan in both directions)

The synthesis document: Bitcoin Self-Custody & Security (LegacyCipher, April 2026) — Ledger treated as the controversial choice; the three considerations explicitly engaged.

As of 2026-05-14: Ledger continues to ship devices and update firmware. The Recover service is opt-in and not aggressively marketed. The 2020 leak data remains in the wild.


Open questions for further development

  • Has the Recover firmware capability been used in any incident affecting non-opt-in users? The structural concern is real but the empirical record so far does not include a documented misuse.
  • The closed-source firmware is the weakest open-source posture among mainstream vendors; competitor pressure may eventually force Ledger to open at least partial firmware. Are there signs of movement?
  • Ledger’s regulatory exposure is meaningful — the Recover service involves identity verification through Onfido, and the three-custodian structure spans jurisdictions. How would court orders or regulatory action in any of those jurisdictions affect Recover users?
  • The framework treats Ledger differently from other hardware-wallet products. Is this calibrated appropriately, or does it overweight the considerations relative to the still-strong cryptography and operational utility?

The framing context:

Per-device alternatives:

Relevant capabilities:

Custody configurations:

Operational practice:

The principal practitioners:

  • Jameson Lopp — substantial writing on Ledger’s considerations

The sub-MOC home: