Ledger, reviewed
Hardware custody is a set of trade-offs, not a magic box. What a Ledger actually protects you from, what it cannot, and the trust-the-vendor question the marketing does not dwell on.
Before we talk about the device, let us do the briefing. A hardware wallet exists to solve exactly one problem: keeping your private keys off an internet-connected computer. That is the whole job. It does not protect you from signing a malicious transaction, from a scammer on the phone, or from writing your recovery phrase on a sticky note. Know what the seatbelt does before you buy the seatbelt.
With that frame set, Ledger is one of the two names most people reach for first, and mostly for good reasons. Mostly.
The product, on paper
What it does well
The core loop is genuinely good. Keys are generated on the device, inside a secure-element chip of the kind used in payment cards, per Ledger’s published materials. Transactions are signed on the device, and the details appear on the device’s own screen — which matters, because your computer’s screen can lie to you and the wallet’s screen is much harder to reach. Confirm the address on the device, every time, even when you are tired, especially when you are tired. That habit has saved more funds than any chip specification.
Ledger Live, the companion app, has matured into a reasonable control room: accounts, firmware updates, and staking and swap integrations offered through third parties. The integrations are convenience features, and convenience features are where I remind you that every extra button is extra surface. Use what you understand; ignore what you do not.
Supply chain, and the ritual of arrival
A hardware wallet’s life begins in the post, which is exactly where a paranoid person would attack it. The discipline here is not optional. Buy directly from the maker or an authorised reseller — never from a marketplace listing, never secondhand, never “new, box opened”. When it arrives, the device itself verifies its own firmware against Ledger’s servers during setup, which is your strongest tamper check; per the company, a genuine device will fail that check if its software has been altered.
And now the line you have heard from me before, delivered with the calm of a flight attendant pointing at exits: a genuine device generates its recovery phrase on its own screen and never asks you to type it anywhere. If any device, email, or “support agent” wants the phrase entered into a computer, a phone, or a website, that is theft in progress. The phrase goes on paper or steel, offline, and nowhere else — not into a keyboard, not into a photo, not into a cloud note, not to support, not to me.
On that subject: in 2020 the company disclosed a breach of its e-commerce and marketing database that exposed customer names and contact details. Not keys, not funds — but Ledger buyers have been phished by name ever since, and that tax has not fully expired. Assume anyone who emails you knowing you own a Ledger is an attacker until proven otherwise.
The trust-the-vendor question
Here is the part the marketing does not dwell on. The secure element’s firmware is not fully open to public inspection, so some of your assurance rests on Ledger’s certifications and reputation rather than on code you can read. For years the community assumption was that the seed physically could not leave the chip. Then came Ledger Recover — an opt-in, paid service which, per the company, shards an encrypted copy of your seed to third-party custodians against your verified identity. The company says the service is strictly opt-in, and I have no evidence otherwise. But the announcement proved the firmware can be written to export a seed under some conditions, and that moved the product from “cannot betray you” to “promises not to without your consent”. Those are different sentences. For most threat models the promise is acceptable; you should simply know which sentence you are buying.
Recovery discipline
The device is replaceable; the phrase is not. Write the 24 words by hand, verify them using the device’s own check, and store them somewhere that survives fire, water, and curious houseguests — steel plates are cheap relative to what they guard. Consider a test restore onto a spare or wiped device before large sums ride on the setup. And never, at any point in this process, does the phrase touch a keyboard. You have heard this before. You will hear it again. That is how briefings work.
The file, both columns
Verdict
A Ledger meaningfully raises the cost of stealing your keys, and that is the correct thing to spend money on in this asset class. It does not make you unrobbable, and no device does. Crypto assets remain high-risk whatever box they live in — so match the tool to your own threat model, and do your own research before trusting any vendor, this one included, with the keys to anything you cannot afford to lose.