Skip to main content
btc$85,828+1.03%eth$2,712+0.74%usdt$0.9998-0.01%bnb$791.44+0.49%xrp$1.51+1.09%usdc$1.0000-0.00%sol$120.84-0.02%trx$0.3350-0.08%figr_heloc$1.07+0.11%zec$1,321-0.82%hype$91.32+1.63%doge$0.0956+2.88%link$14.13+0.84%wbt$85.49+1.27%ada$0.2703+10.65%xmr$538.48-2.35%btc$85,828+1.03%eth$2,712+0.74%usdt$0.9998-0.01%bnb$791.44+0.49%xrp$1.51+1.09%usdc$1.0000-0.00%sol$120.84-0.02%trx$0.3350-0.08%figr_heloc$1.07+0.11%zec$1,321-0.82%hype$91.32+1.63%doge$0.0956+2.88%link$14.13+0.84%wbt$85.49+1.27%ada$0.2703+10.65%xmr$538.48-2.35%
CoinPulse

Ledger

Hardware wallet·2014·France·ledger.com

Ledger is a French company founded in 2014 that makes hardware wallets — small devices, such as the Nano S and Nano X, that keep your crypto private keys on a certified secure-element chip and sign transactions offline. It is the best-known name in the category, paired with its Ledger Live desktop and mobile app. Its devices have never been remotely drained, but the company has had two incidents worth understanding before you buy.

Key facts
Founded
2014, Paris, France2014
Legal entity
Ledger SAS, France
Flagship devices
Nano S Plus, Nano X, Ledger Stax and Flex
Security model
Certified secure-element chip; private keys never leave the device · source

Nano X, Nano S and how Ledger works

A Ledger is a hardware wallet: it generates and stores your private keys on a bank-card-grade secure-element chip and signs transactions inside the device, so the keys never touch your internet-connected computer or phone. You confirm each transaction on the device's own screen and buttons, which is what defends you against malware on the host machine.

The Nano S Plus is the cheaper wired model; the Nano X adds Bluetooth for mobile use and more app storage; Stax and Flex are the newer touchscreen models. All of them pair with Ledger Live, the companion app for installing coin apps, checking balances and sending. The device is what matters for security; the app is a convenience layer around it.

Is Ledger safe?

The device's core promise — that your keys stay on the secure element and never leave it — has held: no Ledger device has been remotely drained of the keys it protects. What has gone wrong twice sits around the device. In 2020 Ledger's marketing database was breached, exposing customers' names and addresses (but no keys or funds); that data still fuels phishing and physical-threat scams today, which is why Ledger will never email or message you asking for your 24-word recovery phrase. In 2023 malicious code in Ledger's Connect Kit software library briefly drained funds from users of certain third-party dApps — again not the hardware — and Ledger committed to reimburse those affected. Both are covered in the incident record below.

The practical rules that follow: buy only from Ledger or an authorised reseller, never enter your recovery phrase anywhere but the device itself, and treat any message asking for it as an attack.

Incident record

E-commerce and marketing data breach2020-07

An unauthorised third party accessed Ledger's e-commerce and marketing database, exposing around one million email addresses and the fuller personal details (names, postal addresses, phone numbers) of roughly 270,000 customers. No private keys, recovery phrases or funds were affected, and hardware wallets were not compromised. The leaked data continues to drive phishing and physical-threat scams.

Funds not affectedSource
Ledger Connect Kit supply-chain exploit2023-12-14

Malicious code was injected into Ledger's Connect Kit JavaScript library, draining about $600,000 from users of third-party dApps (including SushiSwap and Revoke.cash) who blind-signed transactions. Ledger hardware wallets themselves were not compromised. Ledger pushed a fix within hours and committed to reimburse affected users, with repayments completed in the following weeks.

Recovery confirmedLoss $600,000Recovered $600,000Source

In our ratings

Where we score Ledger against its peers on open data. The number lives there, not here.

Compare with

Frequently asked

Is Ledger safe?+

The device's keys have never been remotely drained — they stay on a certified secure-element chip and sign offline. Ledger's two incidents were around the device: a 2020 marketing-database breach (no keys or funds), and a 2023 exploit of its Connect Kit software library that drained about $600,000 from dApp users, for which Ledger reimbursed those affected. Never enter your recovery phrase anywhere but the device.

What is the difference between the Nano S and Nano X?+

Both store your keys on a secure element and sign offline. The Nano S Plus is wired and cheaper; the Nano X adds Bluetooth for mobile use and holds more coin apps at once. For security they are equivalent; the difference is convenience and storage.

Will Ledger ever ask for my recovery phrase?+

No. Ledger will never email, call or message you asking for your 24-word recovery phrase. Because the 2020 data breach exposed customer names and addresses, phishing that impersonates Ledger is common — any request for your phrase is a scam.

What changed

  • 2026-09-28Profile created: founding and security model, the Nano line, and both incidents — the 2020 data breach (funds not affected) and the 2023 Connect Kit exploit with a confirmed-reimbursement verdict.