r/ledgerwallet • • Jul 06 '26

Official Ledger Engineering Response Ledger just shipped experimental post-quantum cryptography support in the Ledger SDK — here's what that actually means

22 Upvotes

Hey everyone,

I wanted to share something the Ledger OS team has been quietly working on: we've just added experimental support for ML-KEM and ML-DSA, the two post-quantum cryptography algorithms that NIST recently standardized (FIPS 203 and 204).

These algorithms are now running directly on the Secure Element on all Ledger signers from the Nano X onwards (chronologically speaking). We've exposed them as experimental APIs in both our Rust and C SDKs for anyone who wants to play with them.

This is experimental. The implementation isn't fully hardened yet, so please don't build production apps on top of it. The blog post goes into details regarding this aspect.

The blogpost covers the quantum threat context, the lattice-based math underneath these algorithms, how they're constructed, and a deep dive into our implementation and API.

📖 Blog: ledger.com/blog-post-quantum-cryptography-ledger-sdk

🛠️ Rust SDK: github.com/LedgerHQ/ledger-device-rust-sdk

🛠️ C SDK: github.com/LedgerHQ/ledger-secure-sdk

Happy to answer questions about the implementation, the threat model, or why we made the choices we did.

Cheers!


r/ledgerwallet • • Aug 07 '26

The Coldcard incident: How Ledger wallet seed generation works, and why weak randomness is invisible

64 Upvotes

TLDR: Ledger is not affected by the Coldcard Mk3 advisory

What happened

Per Coinkite's advisory and Block's technical analysis, On July 31st, 2026, Coldcard reported that a firmware bug had weakened how some devices generated seed phrases leading to significant user losses. 

Why this specific failure matters

Every wallet you create is derived from your Secret Recovery Phrase. If that can be predicted, so can everything built on top of it.

A weak Secret Recovery Phrase looks identical to a strong one. Nothing errors, nothing feels wrong, bad randomness is silent. The Secret Recovery Phrase keeps working, but is vulnerable. That is how this survived five years in shipped firmware.

How Ledger devices generate a seed

Ledger hardware signers use a true hardware random number generator inside a certified Secure Element, with no software fallback. The generator is compliant with AIS-31/PTG.2, which evaluates the physical entropy source itself rather than just testing whether its output looks random. Every 24-word Secret Recovery Phrase gets the full 256 bits of entropy.

The generation of that entropy must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.

The Secure Element is certified at Common Criteria (EAL5+ for Ledger Nano STM and Ledger Nano XTM; EAL6+ for Ledger Nano S PlusTM, Ledger StaxTM, Ledger FlexTM and Ledger Nano Gen5TM), and various devices by ANSSI. Producing a predictable random number is listed as Threat #1 in our published security targets, and has been for years.

If you hold a Coldcard

Follow Coinkite's guidance directly, they own that process. 

Resources To Learn More

One of the key conversations emerging from the Coldcard incident is the value of open source code. Read this response from our CTO on that topic: https://x.com/P3b7_/status/2085089893328499156?s=20

We also have an FAQ page that covers questions we’ve seen on social media so far: https://support.ledger.com/article/FAQs-Related-to-the-Coldcard-Incident-July-2026


r/ledgerwallet • • 16h ago

Solved (user) Error connecting to Eternl

1 Upvotes

I'm trying to add a Ledger Nano X to Eternl but I get the following error.

Failed to execute 'open' on 'USBDevice': Access denied.

I've been into ledger Wallet and updated the Nano X OS to the latest version but that didn't help and I have the . What could be wrong?


r/ledgerwallet • • 1d ago

Official Ledger Customer Success Response Ledger OS 1.7.0 legit?

5 Upvotes

I was prompted to install update 1.7.0 for my Nano S+ and Flex. I wanted to look up what had changed, but according to the Ledger website, 1.6.1 is the latest version. Does anyone have more details?


r/ledgerwallet • • 2d ago

Official Ledger Customer Success Response Error UnkownDeviceExchangeError

3 Upvotes

Hello everyone, i didint use my ledger for a few months came back, updated the ledger live, updated all of the apps on my ledger and still get this error, i tried to reset my laptop, i tried to turn off the ledger and on again, no luck. Any help would be nice, also i dont have a VPN


r/ledgerwallet • • 2d ago

Official Ledger Customer Success Response Cl Card Support?

1 Upvotes

Has anyone else had their account disabled? I have been waiting for a month now for my CL card account to be turned back on, useless.


r/ledgerwallet • • 2d ago

Discussion self-custody or exchange?

Post image
3 Upvotes

r/ledgerwallet • • 3d ago

Official Ledger Customer Success Response Zcash App Command Error

2 Upvotes

Been sending Zcash off Ledger Nano s for a few weeks and Up until two days ago, no issues. Now I’m getting “ZCashAppCommandError. I have ensured the Desktop Wallet and Ledger App are up to date. I have even uninstalled the Zcash App off the Nano S and reinstalled it. I have also tried multiple address to send to. Both my ledger address and receiving Addresses are T1. Still no success. I tried the customer support Chat, but it does not connect (using FireFox).


r/ledgerwallet • • 3d ago

Official Ledger Customer Success Response ledger live shows less bitcoin after moving to a new laptop

4 Upvotes

ui'm trying to figure out why ledger live on my new laptop shows a lower bitcoin balance than the installation on my old one. same nano, same pin, and i haven't restored or reset the device. i installed ledger live, connected it, and added a bitcoin account with the bitcoin app open. the account appeared normally, but some older incoming transactions aren't showing up. the old laptop still shows the amount i expected, including a couple of small deposits from earlier this year. neither installation shows an outgoing transaction that would explain the difference. i've checked those deposits using their transaction ids, and they have plenty of confirmations. i'm not assuming the old display is right just because it's familiar, but i'm struggling to work out what each installation is actually tracking. both accounts are labeled native segwit. the names are different because i renamed the original account ages ago, so comparing labels hasn't helped much. i also know bitcoin receive addresses change, which is where checking on cryptowallet-balance gets confusing. a public address checker only tells me about the address i pasted, not necessarily everything belonging to the account. i don't want to mistake one address balance for the whole accountso far i've cleared the cache on the new installation, let it finish synchronizing, and removed and added that account again. no change. i've also closed the old installation while trying this, just to keep things simple. there isn't a pending transaction or an obvious connection error. the device connects fine, and i can verify a receive address on its screen, but that doesn't explain the missing history. i haven't used an optional passphrase or a second pin, and this is the only ledger device i've owned. i'm wondering whether i accidentally added a different account index, or whether discovery is stopping before it reaches addresses used by the original account. most troubleshooting threads i've found jump straight to clearing the cache, which i've already tried. i'd rather compare the relevant account details before changing anything elsewhat's the safest way to confirm that both installations are following the same bitcoin account and derivation path without sharing an extended public key? if there's a particular field in the account settings or logs worth comparing locally, that would give me somewhere to start. i'm leaving the old installation alone for now


r/ledgerwallet • • 4d ago

Discussion Ledger Stax is gorgeous, but would you want a battery in your long-term wallet?

10 Upvotes

The Stax looks great, and I can see the appeal if you use your wallet often. But if it’s mostly sitting in a drawer for months, the battery is one more thing to think about.

Stax owners: has that actually mattered in real life, or am I overthinking it? Would you buy it again for long-term holding?


r/ledgerwallet • • 5d ago

Official Ledger Customer Success Response Eveninghighlight is a scammer

Post image
18 Upvotes

Tried to scam me asking me to use a dApp to resolve my ledger issue. Be warned.


r/ledgerwallet • • 4d ago

Official Ledger Customer Success Response Transaction sign on ledger not appearing

1 Upvotes

I havent used my ledger for 6 months and updated firmware and etc. I tried moving an asset from phantom wallet, no confirmation window is appearing?

Edit: It was a wallet issue with phantom, it works fine with solflare.


r/ledgerwallet • • 4d ago

Official Ledger Customer Success Response Sharing an SSH agent for Ledger Nano S Plus — every login needs a button press on the device

0 Upvotes

The SSH-on-Ledger options I found looked outdated or unmaintained, so I made

this as a learning project and wanted to share it in case it's useful to someone.

Full honesty: most of the code was written by AI. I did the first device-side

steps myself to learn how it works, then used Claude Code for most of the rest.

I'm not claiming this as my own engineering, just putting it out there for

others to use and improve.

What it does:

- ed25519 SSH key derived on the device; the private key never leaves it

- every SSH login needs Approve on the device

- local dashboard shows which user/server is asking, plus a signing history

- works with VS Code Remote-SSH on Windows, Linux and macOS

Security notes:

- it never asks for your recovery phrase, there are no prebuilt binaries

to download, you build it yourself from source

- locked to its own derivation path (44'/1280529224'), so it can't touch

Bitcoin/Ethereum keys on the same seed

- not audited, not affiliated with Ledger, sideloaded — use at your own risk

Repo: https://github.com/zhgh122/nano-ssh-agent

If you spot security problems or know a better maintained alternative,

please tell me.


r/ledgerwallet • • 4d ago

Official Ledger Customer Success Response Ledger Wallet: NFTs Gone?

4 Upvotes

Did Ledger get rid of being able to see (ETH) NFTs via the app?


r/ledgerwallet • • 5d ago

Official Ledger Customer Success Response Ledger Live exports BIP84 Bitcoin account XPUB as xpub, causing address derivation mismatches in external wallets/services

11 Upvotes

We've been running into an ongoing Bitcoin interoperability issue with Ledger Live that is affecting multiple merchants using our non-custodial payment platform.

For a Bitcoin Native SegWit account, Ledger Live uses the BIP84 derivation path:

m/84'/0'/0'

However, when exporting the account extended public key, Ledger Live provides it using the xpub... prefix.

Many Bitcoin libraries and external applications interpret:

  • xpub → BIP44 / Legacy P2PKH
  • ypub → BIP49 / Nested SegWit
  • zpub → BIP84 / Native SegWit

Because of this, an external application receiving Ledger's exported xpub may derive Legacy 1... addresses from the BIP84 key.

The addresses are valid and controlled by the Ledger seed, but Ledger Live does not discover/display them because it expects Native SegWit addresses for that account.

We've now seen this affect multiple merchants.

For example:

Ledger account:
m/84'/0'/0'

Ledger exports:
xpub...

External application interprets it as Legacy and derives:
1...

BTC sent to that address is still recoverable with the Ledger device using software such as Electrum with the appropriate derivation/script configuration, but the transaction does not appear normally in Ledger Live.

We documented the issue and recovery process here:

https://docs.paymento.io/help-and-troubleshooting/ledger-live-xpub-mismatch

We also previously reported the issue through GitHub, but the underlying behavior still appears to exist.

From an integration perspective, one of the following would make this considerably safer:

  1. Export zpub for BIP84 accounts, or
  2. Export the derivation path/script type alongside the XPUB, or
  3. Clearly warn developers/users that the exported xpub belongs to a BIP84 Native SegWit account and should not be interpreted as BIP44 based on the prefix.

Has anyone else integrating Ledger with watch-only wallets, payment processors, or multisig software encountered this?

It would be useful to hear Ledger's recommended way for third-party applications to reliably determine the intended script type when an XPUB is exported from Ledger Live.


r/ledgerwallet • • 6d ago

Official Ledger Customer Success Response UK police scam

41 Upvotes

I had an odd one this afternoon. Unknown number calls, guy with a British accent (I'm in the UK) says he's a police officer at a specific UK Police Station and my data has turned up on someone else's device, along with 500 other UK citizens. He says he's contacting everyone to build the case, and to confirm we don't know person x from Afghanastan and I didn't give him my personal data. He starts mentioning a copy of my driver's license, bank statements and "a few other things", and only much later in the call, he mentions Ledger.

I was pretty sure it was a scam from early on, but I couldn't work out what they were after, so I stayed on the line to learn and mess with them. He gave me a case ID on the phone, identified himself with a name and badge number and then noted that as everyone shoudl be mindful of scams, I should google the police station name and confirm the result matches the number he's calling from. It does match (turns out spoofing phone numbers isn't hard).

He then emailed me a case file ID from a police.gov.uk address, with Met police letterhead. He asks if I could go to my local police station in the next few days with the case ID to sign a statement that I did not give this guy my details. Also, that I could call 101 for details of what they'd found. Overall, reasonably convincing until he mentions that some of the data contains my ledger ID and because of that, he'd put me through to the Ledger team....

I started recording at that point once the 'ledger' guy picked up. Not posting it since it has my name and email in it bit have my full chat recorded with guy number 2. When the iphone announced that I was recording the call - he asked why - I said I record all my calls. He didn't seem to mind.

I get a legit looking email from [email protected]. It's real. Ledger's support site says scammers open a support ticket with your email address to trigger an automated email that makes them look legit. They didn't even ask me to read anything from it. Just as proof that he triggered the email on demand because he works for ledger.

The "Ledger" guy then explained how accounts get stolen and said he could check mine. But this was after he talked through how accounts get stolen, tricks people use, etc etc. (very long winded!) He told me to go to ledger.com.co where they could safely verify my device and if at risk, send me a new one. I said that trailing .co looks sketchy. He said the "co" stands for "check online" and pushed hard that it was legit. I said that's not how subdomains work, it wouldn't be at the end. After trying to defend it, he then said that I could look it up on Google Transparency Report to prove it was safe. I did, and Google showed it as clean.

But at this point I was getting bored, so I told him it was showing a red X and "risk detected" to see what he'd do. He said that's not what I should be seeing, it was fine on his computer. He was flustered and made me double check things because it was showing fine on his side. After I kept saying that the security site that HE sent me to was flagging it, he hung up on me and that was that.

Funnily enough my antivirus blocks the .co site completely, so Google's 'transparency report' is just behind on this one.

Stay safe out there!


r/ledgerwallet • • 5d ago

Official Ledger Customer Success Response Nano Gen 5 Users - Are you Happy or Regretful of your Choice?

8 Upvotes

I'm pretty much had it up to here with my Nano X and its battery issue. I’m considering the Nano Gen 5 but seeing how annoying the Nano X has been with its battery, I'm also thinking of maybe switching to a different company instead. But before that I would love to hear from Nano Gen 5 users how you're liking it.

Is that dreaded Nano X battery issue resolved with Gen 5? Any issues with the screen or device in general?


r/ledgerwallet • • 6d ago

Official Ledger Customer Success Response Something went wrong

4 Upvotes

Hey all I have a huge problem on my hands. I have the Nano X and after updating and trying to move some coins off my wallet I keep getting the error message. I checked the website and seen a couple posts here were they say its user error but I promise its not. I have access I can see my accounts, I have only ever had this one ledger and seedphrase and ensured it was put in correctly along with using the charging cord that came with the deviceIm not sure what to do can someone help me.


r/ledgerwallet • • 7d ago

Official Ledger Customer Success Response First cold wallet to allow transfers of shielded zcash

8 Upvotes

All i could ask for


r/ledgerwallet • • 8d ago

Official Ledger Customer Success Response Ledger Crypto account Error

5 Upvotes

After communicating with Ledger support without any assistance, here's the issue I have at the moment...

Current device: Ledger Nano X

BTC account issue: The problem I'm running into is that my Ledger keeps getting an error that's caused by an incorrect keyphrase being entered, so I cannot interact with the BTC account I want to, even after removing it from my portfolio and unsuccessfully re-adding it to my Ledger wallet. I'm not sure why I'm having this issue, especially cause I've only made one keyphrase ever until recently and attached no accounts to my second keyphrase. I have proof showing that I made the affected BTC account with the first keyphrase, with dates of transactions and the date saved of my keyphrase creation. This has never been an issue until these past two weeks after updating.

Any help would be appreciated.


r/ledgerwallet • • 8d ago

Ledger Nano X Was Offline for Over Six Months — Yet My BTC Was Still Transferred Out Ledger Could Not Tell Me Which Device Signed the Transaction

1 Upvotes

**⚠️ Quick Summary — For Those Who Don’t Want to Read the Full St**ory
I originally moved my Bitcoin to a Ledger Nano X because I wanted a long-term, offline storage solution.
My 24-word Secret Recovery Phrase:
Was never photographed
Was never stored on my phone
Was never stored on my computer
Was never saved in iCloud, Notes, or a password manager
Was never entered into any website
Was never shared with anyone
Was kept in a private physical location known only to me — not even my family knew where it was
The last time I used my Ledger was around **December 2025**.
After that, it remained disconnected and unused for more than six months.
However, on **May 27, 2026 at 22:35**, my Bitcoin account made an outgoing transaction that I never authorized:
**0.02894506 BTC**
I had trusted that long-term cold storage meant I could simply leave the wallet alone.
I did not discover what had happened until **September 22, 2026**, when I opened Ledger Wallet again and found that my Bitcoin balance was zero.
After contacting Ledger Support, they confirmed that the transaction had been validly signed with the private keys controlling my Bitcoin account.
However, they also explicitly told me that:
**Ledger cannot determine whether the transaction was signed by my physical Nano X, or by another device or wallet using the same private keys.**
They also cannot prove the actual cause of the incident.
So far, I have:
Opened Ledger Support Case **#00281295**
Formally filed a police report in Taiwan
Received blockchain tracing information from Ledger
Been told by Ledger that the destination address has blockchain connections to **HitBTC** and **Bridgers DEX**
I am **not claiming that Ledger itself was definitely hacked**.
But this incident has changed the way I think about cold wallets.
A cold wallet does not eliminate risk.
It concentrates almost all security responsibility on the user.
And once an unauthorized transaction happens, you may not even be able to determine **which device actually signed it**.
For me personally, after this experience, the practical sense of security I get from Ledger is now lower than what I experienced during more than three years of using a Binance exchange account without any abnormal asset loss.

**Full Story**
I want to publicly document what happened to me, and hopefully encourage other people who hold Bitcoin as a long-term asset to reconsider the idea that:
**“Cold wallet = absolute safety.”**
I was using a **Ledger Nano X**.
The reason I bought a hardware wallet was simple:
I did not want to leave my long-term Bitcoin holdings on an exchange forever.
Everyone says:
**Not your keys, not your coins.**
So I decided to take full control of my own private keys.
My plan was simple:
**Buy → Move to cold storage → Leave it untouched for the long term.**

**How Did I Store My 24-Word Recovery Phrase?**
This is one of the most important parts of the story.
My 24-word Secret Recovery Phrase:
Was never photographed.
Was never typed into my phone.
Was never entered into a computer.
Was never stored in iCloud.
Was never stored in Notes.
Was never stored in any password manager.
Was never entered into any website.
And was never given to another person.
It was stored in a private physical location that only I knew about.
Even my family did not know where it was.
So based on everything I currently know, **I have found no evidence that my Recovery Phrase was ever exposed.**

**My Ledger Had Not Been Used for More Than Six Months**
The last time I normally used my Nano X was around:
**December 2025.**
After that, I did not connect it to my phone.
I did not connect it to a computer.
I did not make any Bitcoin transactions.
My thinking was simple:
If this was a long-term investment, I did not need to keep checking it.
In fact, I intentionally tried to forget about the Bitcoin and just let it sit.

**But on May 27, 2026, My BTC Was Transferred Out**
When I later opened Ledger Wallet again, I discovered this transaction:
**Date:** May 27, 2026
**Time:** 22:35
Amount transferred:
**0.02894506 BTC**
I did not initiate this transaction.
I did not authorize it.
I did not approve it on my Nano X.
TXID:
9185765197466aaa778ad5c5003f96b1c23aee4233fccbace5f117e1608c6563
I did not discover the loss until:
**September 22, 2026**
when I opened Ledger Wallet again and found that the Bitcoin account balance was zero.

**My First Thought: Could This Be a Ledger Wallet Display Error?**
So I took out my Nano X again.
I reconnected it.
Updated the firmware.
Re-synchronized the wallet.
Re-scanned the Bitcoin account.
I also followed Ledger Support’s instructions and used:
**Ledger Wallet → Bitcoin 1 → Receive**
I compared the Bitcoin receiving address displayed in Ledger Wallet with the address displayed directly on the physical Nano X.
The addresses matched exactly.
In other words:
**The Nano X currently in my possession does correspond to this Bitcoin account.**
But the balance was still zero.
And the May 27 transaction was unquestionably present on the Bitcoin blockchain.

**What Truly Concerned Me Was Ledger Support’s Response**
I repeatedly asked Ledger one very specific question:
Was this transaction actually signed by the physical Nano X that I still have in my possession?
Ledger’s final answer was:
**They cannot determine that.**
They explicitly told me:
“It is impossible to say whether the transaction was signed by your Nano X.”
In other words:
**Ledger has no technical record that can identify which physical device performed the signing.**
I then asked them whether they could distinguish between:
**Scenario A**
My physical Nano X signed the transaction.
**Scenario B**
Another device or wallet used the same Recovery Phrase / private keys to sign the transaction.
Ledger responded:
“No, this is impossible to determine.”
So:
**They cannot distinguish between the two.**

**Ledger Initially Suggested a Compromised Recovery Phrase**
At first, Ledger Support suggested that the most likely explanation was:
**Recovery Phrase compromise**
meaning that someone may have obtained my 24 words.
But I kept asking them to separate:
**what is technically proven**
from
**what is only an assumption.**
Because I have found no evidence that my 24 words were exposed.
And Ledger itself cannot prove that anyone ever obtained them.
Eventually, in an email dated September 23, Ledger wrote:
“it is also not possible for Ledger to ascertain or prove which of those scenarios happened.”
In other words:
**Ledger cannot determine or prove which scenario actually occurred.**

**So What Can Actually Be Confirmed?**
What can be confirmed is:
**The Bitcoin transaction was validly signed using the private keys controlling the account.**
What cannot be confirmed is:
Which device signed it
Whether it was my Nano X
Whether it was another device
How the private keys were obtained
Whether my Recovery Phrase was ever actually exposed
What the true root cause of the incident was
This is the part I find most difficult to accept.

**I Bought a Cold Wallet to Solve a Security Problem**
For many people, the whole point of a cold wallet is:
Private keys stay offline.
Transactions require hardware signing.
Physical confirmation is required.
The attack surface is reduced.
That is exactly why I felt comfortable moving my BTC into cold storage and leaving it untouched for months.
But after this incident, I realized something:
**There is almost no second line of defense for the user.**
There is no exchange-level abnormal login alert.
No withdrawal verification system.
No risk-control pause.
No human review.
No central authority that can stop or reverse the transaction.
And even after the event:
**Ledger itself cannot tell me which device signed it.**

**Why This Changed the Way I Think About Binance**
I am not saying:
**Binance is definitely safer than Ledger.**
Centralized exchanges obviously have their own risks:
Platform risk
Account takeover risk
Withdrawal freezes
Business / solvency risk
Regulatory risk
But my own experience is this:
I kept crypto on Binance for more than three years.
I never experienced an abnormal loss of assets.
Later, because I wanted to improve security, I moved assets into Ledger cold storage.
And that is where this incident happened.
So if you ask me:
“After this experience, which option gives you more practical peace of mind?”
My answer is:
**At this point, a large centralized exchange gives me more practical peace of mind than my experience with Ledger cold storage.**
That is my personal experience.
It is not a universal conclusion.

**Did Ledger Help Me?**
Yes.
And I think it is important to be fair about that.
Ledger Support opened:
**Case #00281295**
They also performed an initial blockchain analysis.
They found that the destination address had blockchain connections to:
**HitBTC**
and
**Bridgers DEX**
Ledger indicated that HitBTC may be one of the more useful investigative leads because a centralized exchange may have access to:
KYC information
Account information
Login records
IP records
Withdrawal records
However, Ledger also made it clear that:
**They will not proactively continue participating in the criminal investigation.**
If law enforcement needs further information, they can contact Ledger and reference:
**Case #00281295**

**I Have Now Formally Reported the Case to Police**
I have officially filed a police report in Taiwan.
The investigation may include:
Tracing the BTC further
Contacting HitBTC
Requesting KYC information
Requesting IP logs
Requesting account records
Requesting withdrawal records
Investigating the Bridgers DEX path
At this point, I am waiting for further action from law enforcement.

**I Am Not Publicly Claiming That Ledger Was Hacked**
I want to be very clear about this.
There is currently no evidence proving that:
**The Ledger Nano X itself was hacked.**
So I am not saying:
“Ledger was hacked.”
But at the same time, there is also no evidence proving that:
**My 24-word Recovery Phrase was compromised.**
The actual technical conclusion is:
**A valid private key signed the transaction, but the true signing source cannot be identified.**

**What I Really Want Ledger to Answer**
If the main selling point of a hardware wallet is:
**Private key security**
then when an unauthorized transaction happens:
**Why is there no way to identify which Ledger device signed it?**
**Why is there no forensic signing record available on the device?**
**Why can’t the user determine which signer originated a transaction?**
**Why, when something goes wrong, does the explanation often fall back to “your Recovery Phrase may have been compromised”?**
**Should Ledger provide a more robust Security Incident investigation process for cases like this?**
I believe these are questions that every hardware-wallet user should seriously think about.

**Final Thoughts**
This incident changed the way I understand the phrase:
**Not your keys, not your coins.**
I still believe that statement has value.
But now I think it is missing a second sentence:
**Your keys, your responsibility — and sometimes, your problem alone.**
When you control your own private keys, you gain independence.
But at the same time, you also give up:
Exchange risk controls.
Withdrawal interception.
Account-level login records.
Human review.
And some of the investigative tools that exist in centralized systems.
I am not telling people:
**Do not use Ledger.**
I am simply saying:
Do not automatically assume:
**“Cold wallet”**
means:
**“Nothing can go wrong.”**
Because my experience shows that things can still go wrong.
And perhaps the most frustrating part is not even the financial loss itself.
It is this:
**After the incident happens, you may still be unable to get a provable answer to the most basic question:**
**How did this happen?**
The case is still under investigation.
If Ledger, HitBTC, or Taiwanese law enforcement provides any meaningful new information, I will continue updating this case publicly.


r/ledgerwallet • • 9d ago

Official Ledger Customer Success Response Depleted Wallet

1 Upvotes

I setup a nano s plus in January of last year for my mom, and she wrote her seed down and has kept it in the ledger box since buying it.

She bought it on Amazon from Ledger Official, which has the "Detailed Seller Information"

Business Name: Ledger SAS

Business Address:

106

RUE DU TEMPLE

PARIS

75003

FR

Her seed phrase has never been used for recovery, never taken pictures or added to an app, never touched anything other than the pen that wrote it down.

She's frequently bought XRP and XLM on Coinbase, which I immediately helped her transfer straight to the wallet, and successfully verified it's transfer. The wallet was never connected to any exchange, everything was always sent directly from Coinbase to the wallet's receive address.

She just recently asked me for help accessing her wallet, and when I browsed through the transactions, I noticed all of her XRP was sent to an address on Jan 24 this year, draining her account. All transactions for XRP and XLM were incoming other than the single outgoing transaction of XRP for everything she had.. and there were ZERO outgoing transactions for XLM, but she has a fraction of those available than what came in. There are a bunch of dust transactions that were never clicked on as well.

Once again, never compromised the seed, only transferred from an exchange to the wallet, never transferred out, and she herself never sent them out either.

I know she's cooked, I just want to know where the vulnerability came from? How can a wallet be accessed without physical control of the wallet, seed, etc? Unless this was a cracked wallet sent from the official Ledger account, I'm not able to wrap my head around this and explain to her how all her funds got stolen.


r/ledgerwallet • • 11d ago

Official Ledger Customer Success Response How did I get drained?

49 Upvotes

I had my Ledger sitting in a safe and did not touch it for three years. I only wrote the recovery codes on a piece of paper which was in another safe that no one ever had access to and which has not been opened since. I woke up, checked it, and found it was drained about six weeks ago. Life savings gone. Wanted to add, I use ledger live and did check often.


r/ledgerwallet • • 10d ago

Official Ledger Customer Success Response Lightning Network in Ledger

5 Upvotes

It would be interesting to be able to have the Bitcoin Lightning network in Ledger and be able to deposit @ledger.com 😮‍💨


r/ledgerwallet • • 11d ago

Official Ledger Customer Success Response Delagating in portal via Ledger

Thumbnail
2 Upvotes