
Ledger
Ledger is the mainstream hardware wallet brand: a physical device that keeps private keys inside a Secure Element chip so signing happens offline, not in a browser. Pair with Ledger Live (rebranded Ledger Wallet app) for balances, sends, swaps, staking, and dApp connect. Lineup runs Nano S Plus / Nano X / Nano Gen5 through Flex and Stax touchscreens. Broad coin support. Closed-source SE firmware and optional Ledger Recover still divide the community. Device security is strong; phishing and user error still drain people.
Description
Ledger (Ledger SAS, Paris) sells cold-ish self-custody hardware. Private keys are generated and stored on a certified Secure Element (EAL5+ on older Nanos, EAL6+ on Flex / Stax / newer silicon). The computer or phone never sees the raw seed. You confirm recipient and amount on the device screen, enter the PIN, and the chip signs. That is the whole point versus MetaMask or Trust Wallet alone: malware on the host can try to lie about a transaction, but a careful user verifying the device display catches the bait.
Product ladder in 2026 practice:
- Nano S Plus: budget USB stick, fine for desk cold storage.
- Nano X: Bluetooth classic for mobile without plugging in every time.
- Nano Gen5: newer Nano with Bluetooth / NFC, Clear Signing push, and the current “daily driver” pitch.
- Flex: credit-card form, ~2.84" E Ink touchscreen, easier address checks, EAL6+.
- Stax: premium curved E Ink (Tony Fadell design story), wireless charging, biggest screen, same security class as Flex at luxury price.
Buy only from ledger.com or authorized retailers. Secondhand and random Amazon listings are how supply-chain and fake-device scams work. On first setup, wipe / initialize yourself, write the 24-word Secret Recovery Phrase on the cards (better: metal backup), never type that phrase into a website, email, or “Ledger support” chat. Ledger will not call you for your seed. Fake support after the 2020 customer-data leak (and later marketing-list headaches) is still an industry problem. Scammers email real-looking victims because they know who bought devices.
Software side is Ledger Live / the newer Ledger Wallet app on desktop and mobile. Manage accounts, buy via partners, swap, stake, view NFTs, connect to Web3 via WalletConnect or browser extensions that talk to the device. Clear Signing aims to show human-readable contract details instead of opaque hex. Useful when it works; coverage is not universal across every DeFi contract. You can also use the device as a signer behind MetaMask, Sparrow, and other wallets. Hardware does not make every integrated dApp safe. Blind-signing risk and malicious approvals still exist if you rubber-stamp without reading the screen.
Ledger Recover (opt-in, paid, ID/KYC) shards an encrypted backup of the seed across Ledger, Coincover, and EscrowTech so two-of-three can restore after identity checks. Never enable it and nothing changes: your seed stays only on device / your paper. The 2023 backlash was about the firmware capability existing at all, and about trust in a company that markets pure self-custody while offering a recovery path that leaves the chip. Reasonable for people who fear losing a seed more than they fear custodial / subpoena risk. Wrong for maximalists and anyone who refuses KYC on a backup. Separate from metal seed plates or NFC recovery-key accessories sold with some new models.
Incidents that still matter for due diligence: 2020 e-commerce data breach (phishing fuel, not key extraction). December 2023 Connect Kit NPM supply-chain attack drained DeFi users connecting through a poisoned library (~hundreds of thousands USD); Ledger reimbursed and hardened publishing. No widely confirmed remote extraction of keys from a properly used Secure Element in the field. Losses “with Ledger” are almost always phishing, fake apps, seed entered somewhere, or approving a bad tx on the device without reading it.
Versus Trezor: Trezor leans open-source firmware and air-gapped / transparent culture; Ledger leans Secure Element certifications, larger app ecosystem, and polished retail UX. Versus software wallets alone: Ledger is for size you cannot afford to lose to a browser drain. Versus exchange custody: you own the keys and the recovery burden.
Fees: device is upfront ($79–$399 range depending on model and era). Network gas is always yours. Partner swaps / fiat add spreads. Enterprise Multisig coordination introduced Ledger service fees on some Ethereum actions (flat fee for governance-style ops, small % on transfers, L2s often free per docs). That fee model drew developer backlash in late 2025. Check current Multisig pricing if that is your use case. Recover is a separate subscription if enabled.
Who it’s for: anyone moving meaningful crypto off exchanges into self-custody, active signers who want a readable screen (Flex/Stax/Gen5), and users who pair Ledger with MetaMask / DeFi carefully. Who should skip or look elsewhere: people who want fully open SE firmware (Trezor / others), Bitcoin-only minimalists who hate companion apps, and buyers who will not verify every address on-device.
STRENGTHS
- Keys stay in a certified Secure Element. Host malware cannot casually export the seed
- On-device confirmation (especially E Ink Clear Signing on Flex/Stax/Gen5) beats tiny OLED guesswork
- Wide asset and app support via Ledger Live / Wallet plus third-party wallet integrations
- Mature retail product line from budget Nano to premium Stax. Easy to recommend by use case
- Mobile Bluetooth / NFC options for people who sign away from a desk
- Strong brand, Donjon research / bug bounty culture, and long field history without public remote key drains
- Works as a signer for MetaMask and other interfaces without giving up cold key storage
WEAKNESSES
- Secure Element firmware is closed source. You trust Ledger + certification, not full public audit of the chip OS
- Ledger Recover opt-in path permanently damaged trust for a chunk of the cypherpunk audience
- Customer data leaks turned buyers into phishing targets even when devices stayed secure
- Connect Kit supply-chain incident showed integration risk outside the metal box
- Not air-gapped on Bluetooth/NFC models. More radios than QR-only signers
- Ledger Live / Wallet UX and partner fee flows still frustrate power users; Multisig service fees sparked backlash
- Upfront hardware cost. Older Nano S left behind on newer Clear Signing / Multisig features
- User error still wins: fake support, seed photos, and blind approvals bypass the Secure Element entirely
Tags
Comments
No comments yet.
1000