What Ledger actually sells you
Every Ledger device is built around a certified secure element, a tamper-resistant chip that generates and stores private keys and never exports them. That single architectural choice is the product.
The chips carry Common Criteria certification, an independent evaluation standard also used for payment cards and passports. The Nano X uses an ST33J2M0 rated CC EAL5+.
Everything else, the screen, the Bluetooth, the app, is convenience layered on top. When you compare Ledger models you are mostly choosing how you want to interact with the same underlying security.
That is worth knowing because the cheaper models are not less secure in any meaningful sense. They are less convenient.
The two controversies, kept separate
Ledger has had two significant trust events, and they get conflated constantly. Neither was a device compromise, and both are legitimate reasons to hesitate.
The 2020 customer database breach
Ledger's e-commerce database was breached, exposing names and contact details of buyers. No device or key was compromised, but it produced a list of confirmed crypto owners with home addresses, and years of targeted phishing followed.
The seed-recovery announcement
Ledger announced a service that could reconstruct a recovery phrase through shards held by third parties. The backlash was not about the feature so much as what it proved: firmware could be built to handle key material in ways owners had assumed impossible.
Neither is a broken device
To be precise about it, no Ledger secure element has been defeated in the wild. The criticisms are about the company and the trust model, not the chip.
Both are fair to weigh
If a company holding your address is a threat to you, or if closed firmware is a dealbreaker, those are reasonable conclusions rather than overreactions.
Which Ledger, and when not to buy one at all
The honest ladder: no hardware wallet at all until the amount you hold would genuinely upset you to lose, then the cheapest model that fits how you actually use crypto.
If you manage crypto from a phone, the Bluetooth models are the ones that will not annoy you into leaving assets on an exchange. Our full assessment is in the Ledger Nano X review below.
If you only ever plug into a laptop, a cheaper USB-only model does the identical security job with the identical class of chip.
And if auditability is central to how you think about security, no Ledger will satisfy that. Trezor ships an EAL6+ certified secure element described as NDA-free, which is what allows its firmware to stay open. That is a real difference, not a marketing one.
Your situation, our answer
If this is you, do this
You want cold storage and manage crypto by phone
A Bluetooth Ledger
This is where Ledger is genuinely ahead. Read the Nano X review for the detail before choosing a model.
You want open firmware you can audit
Not Ledger
No certification substitutes for inspectable code. Buy a Trezor instead and do not talk yourself out of the requirement.
You bought a Ledger before 2021
Treat all contact as hostile
Your details were likely in the breached customer database. Ledger will never ask for your recovery phrase, and any message that does is an attack.
You are protecting under a few hundred dollars
Do not buy hardware yet
A free software wallet is the right tool. Buy a device when the value clearly exceeds its price.
You are buying from a marketplace reseller
Stop
Buy direct from Ledger. Supply-chain tampering is a real attack, and a device arriving with a pre-filled recovery sheet is always a scam.
The honest ledger
Pros and cons
What we like
- Certified secure elements across the entire product range
- Ledger Live covers 500+ assets natively on desktop and mobile
- Thousands more assets supported through third-party wallets
- Bluetooth models are the best hardware option for phone-first users
- A genuine price ladder rather than one device at one price
- No Ledger secure element has been defeated in the wild
What to watch
- Closed-source firmware that cannot be independently audited
- The 2020 customer database breach still drives targeted phishing
- The seed-recovery announcement damaged trust with security-focused users
- Trezor ships a higher assurance level, EAL6+, with an NDA-free chip
- Assets beyond the 500+ native list need a third-party interface
Show your working
How we scored this review
This is a documentary review. Every figure above was read from published documentation on August 16, 2026 and is cited. We did not open a funded account, and we do not claim hands-on testing we did not do.
| Criterion | Weight | Mark | Why |
|---|---|---|---|
| Hardware security architecture | 25% | 4.8 | Certified secure elements across the range. The Nano X uses a CC EAL5+ rated ST33J2M0, the same class of chip used in payment cards. |
| Software ecosystem | 20% | 4.2 | Ledger Live is mature, covers 500+ assets natively, and runs on desktop and mobile. Thousands more assets work through third-party wallets. |
| Transparency | 20% | 2.5 | Firmware is closed-source. Security rests on certification and on trusting the company rather than on code anyone can inspect. |
| Trust and incident history | 20% | 3.0 | No device has been broken in the wild, but the 2020 customer database breach and the seed-recovery controversy both did lasting reputational damage. |
| Product range | 15% | 4.5 | A genuine ladder from entry USB-only devices to Bluetooth models, so the line covers most budgets and use cases. |
Weights total 100. Weighted average: 3.8 / 5. Read our editorial policy.
What we could not verify
- Current pricing across the product line. Ledger's product page did not state a USD figure in the content we retrieved on August 16, 2026.
- Specifications for models other than the Nano X. We verified the Nano X directly and have not confirmed chip models or certifications for the rest of the range.
- The exact figures of the 2020 breach, including how many records were exposed. Widely reported, not confirmed by us against a primary disclosure.
- The current status and default configuration of the seed-recovery service, which has changed since launch.
- Independent confirmation that no secure element has been defeated. This is the absence of a known public compromise rather than a positive proof.
Ledger FAQs
Is Ledger safe?
The hardware is among the most rigorously certified in consumer crypto, built around secure elements carrying Common Criteria certification, and no Ledger device has been broken in the wild. The reservations are about the company rather than the chip: firmware is closed-source, a 2020 breach exposed customer contact details, and a later seed-recovery announcement showed firmware could be made to handle key material in unexpected ways. Whether those outweigh the hardware quality is a genuine judgment call.
Was Ledger hacked?
Not the devices. In 2020 Ledger's e-commerce customer database was breached, exposing names and contact details of people who had bought hardware wallets. No private keys were compromised and no device was defeated. What it produced was a list of confirmed crypto owners with addresses, which fuelled years of convincing phishing emails and physical mail scams. Treat any unsolicited contact claiming to be from Ledger as hostile.
Which Ledger should I buy?
If you manage crypto from a phone, a Bluetooth model is worth the premium because it is the difference between using cold storage and leaving assets on an exchange out of laziness. If you only connect to a laptop, a cheaper USB-only model uses the same class of secure element and does the same job. Read our Ledger Nano X review for the full assessment of the Bluetooth option.
Ledger or Trezor?
Ledger for phone-first convenience and a broader native asset list in its own software. Trezor if auditability matters to you: it ships an EAL6+ certified secure element described as NDA-free, a higher assurance level than the Nano X's EAL5+, and its open-source development means the security claims can be inspected rather than trusted. Neither answer is universal. See our Trezor review.
Why do people say Ledger is closed source?
Because the firmware is not published for public inspection. Ledger's security case rests on independent certification of the chip and on the company's engineering record, not on code that researchers can audit. That is a coherent position, and it is also why the seed-recovery announcement caused such a reaction: users discovered they had been trusting assumptions about firmware behaviour that were never guaranteed.
Where should I buy a Ledger?
Directly from Ledger, without exception. Supply-chain tampering is a genuine attack against hardware wallets, and the discount on a marketplace listing is never worth it. A device that arrives with a recovery phrase already written on the card is a scam every single time, with no exceptions and no innocent explanation.
The bottom line
Should you use Ledger?
Buy a Ledger if you want certified cold storage and phone convenience matters to you, and buy it directly from Ledger. Buy a Trezor instead if you want the security claims to be inspectable rather than certified, because no amount of hardware quality answers that requirement.
This page currently carries no affiliate links. Affiliate disclosure. Nothing here is financial advice. Crypto is volatile and you can lose money.