Is Ledger safe?
Short answer
Ledger scores 74/100 (Good). It is a self-custody hardware wallet made by Ledger SAS (France). Its code is partly public, the latest independent audit was by Synacktiv in January 2026, and 3 security incidents are on record, 1 with user losses.
How Ledger scores
Safety score
74/100
Good
Write the recovery phrase on paper or metal, never in a photo or cloud note. Install wallets only from the maker’s own site or the official app store.
Some of the code is public, but not all of it is open source.
Latest published audit: Synacktiv, January 2026.
Keys are created and kept on a dedicated device, away from the phone or computer you browse with.
3 incidents on record, 2 in the last three years, 1 with user losses. Recent incidents and losses weigh more.
Run by Ledger SAS, a named company in France.
Ledger at a glance
- Type: hardware wallet
- Available on: hardware device, desktop, iOS, Android
- Key storage: Secure element chip. 24-word recovery phrase generated on the device; private keys stay in a certified secure element. Ledger Recover is an optional paid backup service.
- Networks: EVM chains, Bitcoin and Solana. Ledger Wallet page claims "15,000+ crypto" and "100+ chains"; no exact network count published.
- Company: Ledger SAS (France)
- Partly open: The Ledger Wallet app is MIT-licensed. The low-level secure element code stays closed under Ledger's agreement with STMicroelectronics. GitHub
- App ratings: App Store: 4.8 from 15,174 ratings; Google Play: 4.5 from 35,865 ratings
Has Ledger been hacked?
- January 2026 · Breach
Unauthorized access to a cloud system of Global-e, Ledger's cross-border e-commerce partner, exposed names, emails, postal addresses and phone numbers of some Ledger.com customers. No payment data, recovery phrases or funds were exposed; the main risk is targeted phishing. Source - December 2023 · Supply-chain attack User funds lost
An attacker phished a former employee's npm account and published malicious Ledger Connect Kit versions 1.1.5 to 1.1.7, injecting a drainer into DApps that used the library. Ledger shipped a fix within 40 minutes; active draining lasted under two hours. Source - June 2020 · Breach
An unauthorized party used an API key to access Ledger's e-commerce and marketing database, exposing about 1 million email addresses and about 292,000 records with names, postal addresses and phone numbers. Found via bug bounty on 2020-07-14; the data later fuelled phishing waves. No funds or payment data exposed. Source
Ledger security audits
- Synacktiv, January 2026: Ledger OS secure-element code review for Nano S+ v1.5.0, Nano X v2.6.0, Flex v1.5.0, Stax v1.9.0
- Synacktiv, July 2025: Ledger OS secure-element code review for Nano S+ v1.4.0, Nano X v2.5.0, Flex v1.4.0, Stax v1.8.0
- Synacktiv, December 2024: Ledger OS secure-element code review for Nano S+ v1.3.1, Nano X v2.4.1, Flex v1.2.1, Stax v1.6.1
Crypto cards that work with Ledger
These cards spend straight from Ledger or come from the same maker, so your funds stay in self-custody until you pay.
Other wallet safety checks
Frequently asked questions
Is Ledger safe?
Has Ledger ever been hacked?
Is Ledger open source?
Is there a crypto card for Ledger?
Sources
- Ledger Wallet app page · checked September 29, 2026
- Ledger supported crypto assets · checked September 29, 2026
- Ledger OS third-party reports (GitHub) · checked September 29, 2026
- ledger-live repository · checked September 29, 2026
- Ledger is 95% OpenSource, why not 100%? · checked September 29, 2026
- Security Incident Report (Connect Kit) · checked September 29, 2026
- Addressing the July 2020 e-commerce and marketing data breach · checked September 29, 2026
- Global-e Incident to Order Data - January 2026 (Ledger support) · checked September 29, 2026
- CoinDesk: Ledger faces data breach through Global-e partner · checked September 29, 2026
- Ledger CL Card · checked September 29, 2026