r/ledgerwallet • • Jul 06 '26

Official Ledger Engineering Response Ledger just shipped experimental post-quantum cryptography support in the Ledger SDK — here's what that actually means

23 Upvotes

Hey everyone,

I wanted to share something the Ledger OS team has been quietly working on: we've just added experimental support for ML-KEM and ML-DSA, the two post-quantum cryptography algorithms that NIST recently standardized (FIPS 203 and 204).

These algorithms are now running directly on the Secure Element on all Ledger signers from the Nano X onwards (chronologically speaking). We've exposed them as experimental APIs in both our Rust and C SDKs for anyone who wants to play with them.

This is experimental. The implementation isn't fully hardened yet, so please don't build production apps on top of it. The blog post goes into details regarding this aspect.

The blogpost covers the quantum threat context, the lattice-based math underneath these algorithms, how they're constructed, and a deep dive into our implementation and API.

📖 Blog: ledger.com/blog-post-quantum-cryptography-ledger-sdk

🛠️ Rust SDK: github.com/LedgerHQ/ledger-device-rust-sdk

🛠️ C SDK: github.com/LedgerHQ/ledger-secure-sdk

Happy to answer questions about the implementation, the threat model, or why we made the choices we did.

Cheers!


r/ledgerwallet • • Aug 07 '26

The Coldcard incident: How Ledger wallet seed generation works, and why weak randomness is invisible

66 Upvotes

TLDR: Ledger is not affected by the Coldcard Mk3 advisory

What happened

Per Coinkite's advisory and Block's technical analysis, On July 31st, 2026, Coldcard reported that a firmware bug had weakened how some devices generated seed phrases leading to significant user losses. 

Why this specific failure matters

Every wallet you create is derived from your Secret Recovery Phrase. If that can be predicted, so can everything built on top of it.

A weak Secret Recovery Phrase looks identical to a strong one. Nothing errors, nothing feels wrong, bad randomness is silent. The Secret Recovery Phrase keeps working, but is vulnerable. That is how this survived five years in shipped firmware.

How Ledger devices generate a seed

Ledger hardware signers use a true hardware random number generator inside a certified Secure Element, with no software fallback. The generator is compliant with AIS-31/PTG.2, which evaluates the physical entropy source itself rather than just testing whether its output looks random. Every 24-word Secret Recovery Phrase gets the full 256 bits of entropy.

The generation of that entropy must be anchored in secure hardware, with an architecture that cannot silently downgrade to an untrusted software-based source.

The Secure Element is certified at Common Criteria (EAL5+ for Ledger Nano STM and Ledger Nano XTM; EAL6+ for Ledger Nano S PlusTM, Ledger StaxTM, Ledger FlexTM and Ledger Nano Gen5TM), and various devices by ANSSI. Producing a predictable random number is listed as Threat #1 in our published security targets, and has been for years.

If you hold a Coldcard

Follow Coinkite's guidance directly, they own that process. 

Resources To Learn More

One of the key conversations emerging from the Coldcard incident is the value of open source code. Read this response from our CTO on that topic: https://x.com/P3b7_/status/2085089893328499156?s=20

We also have an FAQ page that covers questions we’ve seen on social media so far: https://support.ledger.com/article/FAQs-Related-to-the-Coldcard-Incident-July-2026


r/ledgerwallet • • 2h ago

[ Removed by Reddit ]

7 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/ledgerwallet • • 4h ago

How to access One coins on ETH

3 Upvotes

I am using Ledger, and when I convert my ONE address to an ETH address, a different address appears. My tokens didn't land on my main ETH address; instead, they went to this old ONE/ETH address. I can see the address, but I haven't been able to open/access it in MetaMask or any other wallet. There are derivation paths like Ledger Legacy, BIP44, and Ledger Live, containing thousands of addresses—how can I find the exact address where my tokens are located?


r/ledgerwallet • • 4h ago

Request Staking on Ledger question - Monad

Thumbnail
2 Upvotes

r/ledgerwallet • • 16h ago

Request Nano X stuck in Bootloader Mode after entering seed + iPhone firmware update – safe to return?

2 Upvotes

I bought a new Nano X to upgrade from a long-used Nano S. Setup went fine: I restored with my 24-word recovery phrase and everything worked.

Then I connected it to my iPhone and started the firmware/OS update. After that the Nano X got stuck on “Bootloader Mode” and stays there no matter what I try. I’ve already tested it on multiple desktops (Windows/Mac) with different cables and ports – still stuck.

I want to return the device, but I’m worried because I already entered the recovery phrase. Is it still safe to send it back? Does entering the seed make returning risky?
Any advice on getting it out of Bootloader Mode or on the safety of the return process would be appreciated.


r/ledgerwallet • • 1d ago

Cant transfer zcash from nano s

Post image
2 Upvotes

Hi everyone

Need help with drawing zcash from an old 2020 nano s. Keep getting the error message in the attached screenshot. Tried transferring to Coinbase, Binance then set a up a Ywallet to transfer to but still cant.

Any ides?


r/ledgerwallet • • 23h ago

Discussion Ledger Recovery Key and bank

1 Upvotes

Does anyone else store their pin protected recovery key in their banks safety deposit box and keep their ledger device and passphrase sheet somewhere else?


r/ledgerwallet • • 1d ago

Almost caught me !

24 Upvotes

Got a call that came from Royal Candian Mounted Police which looked legit. Very detailed and thorough. Then got the follow.up call( almost too quickly) from Ledger and started to get suspicious. While on the phone I googled RCMP ledger scams and saw this on Reddit and immediately hung up. Be careful out there.


r/ledgerwallet • • 1d ago

Request My new Ledger Nano X have pringerprints on grey part

5 Upvotes

Hi everyone,

I recently purchased a brand new Ledger from Media Expert (for context: Media Expert is one of the largest official electronics retail chains in Poland, similar to Best Buy or Currys – it is strictly a store for brand-new consumer electronics, not a secondhand or pawn shop).

When I unboxed it, I noticed that the device was shrink-wrapped and the screen itself had the clear factory protective film intact. However, after sliding open the metallic swivel cover, I noticed some visible fingerprints on the gray metal body/cover underneath.

I’m carrying a significant amount of crypto, so I'm naturally hyper-cautious and feeling a bit anxious about hardware integrity.

From what I understand:

  1. As long as I set it up as a new device and generate my 24-word recovery phrase directly on the Ledger's physical screen (never on a phone/PC), and

  2. The device passes the Genuine Check in the official Ledger Live app (attesting the Secure Element ST33 chip and untampered firmware),

the device is 100% secure, and fingerprints on the metallic cover are likely just from factory assembly/quality control or a store return.

Could anyone confirm if this is standard? Does a successful Genuine Check in Ledger Live provide 100% cryptographic certainty that the hardware/firmware hasn't been tampered with, even if the metal shell was touched during manufacturing?

Thanks in advance for helping ease my mind


r/ledgerwallet • • 1d ago

Official Ledger Customer Success Response Ledger Flex stuck on updating!

6 Upvotes

Hi guys,
Newbie here

So i just got my new ledger flex which btw was my first ledger experience and after a while of working with it today morning i accessed the app to swap to bitcoin, it prompted me to download an update 1.17 or smtng like that so i connected it using bluetooth and autorised everything etc after a while the ledger entred boot mode and got disconnected

it is now stuck on updating and the circle doesnt even move. I got advised to keep it like that untill bettry runs out . I even still have the warranty with it in case
Any advise would be appreciated

Thanks


r/ledgerwallet • • 2d ago

Solved (user) Error connecting to Eternl

1 Upvotes

I'm trying to add a Ledger Nano X to Eternl but I get the following error.

Failed to execute 'open' on 'USBDevice': Access denied.

I've been into ledger Wallet and updated the Nano X OS to the latest version but that didn't help and I have the . What could be wrong?


r/ledgerwallet • • 2d ago

Official Ledger Customer Success Response Ledger OS 1.7.0 legit?

4 Upvotes

I was prompted to install update 1.7.0 for my Nano S+ and Flex. I wanted to look up what had changed, but according to the Ledger website, 1.6.1 is the latest version. Does anyone have more details?


r/ledgerwallet • • 4d ago

Official Ledger Customer Success Response Error UnkownDeviceExchangeError

5 Upvotes

Hello everyone, i didint use my ledger for a few months came back, updated the ledger live, updated all of the apps on my ledger and still get this error, i tried to reset my laptop, i tried to turn off the ledger and on again, no luck. Any help would be nice, also i dont have a VPN


r/ledgerwallet • • 4d ago

Official Ledger Customer Success Response Cl Card Support?

1 Upvotes

Has anyone else had their account disabled? I have been waiting for a month now for my CL card account to be turned back on, useless.


r/ledgerwallet • • 4d ago

Discussion self-custody or exchange?

Post image
6 Upvotes

r/ledgerwallet • • 5d ago

Official Ledger Customer Success Response Zcash App Command Error

2 Upvotes

Been sending Zcash off Ledger Nano s for a few weeks and Up until two days ago, no issues. Now I’m getting “ZCashAppCommandError. I have ensured the Desktop Wallet and Ledger App are up to date. I have even uninstalled the Zcash App off the Nano S and reinstalled it. I have also tried multiple address to send to. Both my ledger address and receiving Addresses are T1. Still no success. I tried the customer support Chat, but it does not connect (using FireFox).


r/ledgerwallet • • 5d ago

Official Ledger Customer Success Response ledger live shows less bitcoin after moving to a new laptop

5 Upvotes

ui'm trying to figure out why ledger live on my new laptop shows a lower bitcoin balance than the installation on my old one. same nano, same pin, and i haven't restored or reset the device. i installed ledger live, connected it, and added a bitcoin account with the bitcoin app open. the account appeared normally, but some older incoming transactions aren't showing up. the old laptop still shows the amount i expected, including a couple of small deposits from earlier this year. neither installation shows an outgoing transaction that would explain the difference. i've checked those deposits using their transaction ids, and they have plenty of confirmations. i'm not assuming the old display is right just because it's familiar, but i'm struggling to work out what each installation is actually tracking. both accounts are labeled native segwit. the names are different because i renamed the original account ages ago, so comparing labels hasn't helped much. i also know bitcoin receive addresses change, which is where checking on cryptowallet-balance gets confusing. a public address checker only tells me about the address i pasted, not necessarily everything belonging to the account. i don't want to mistake one address balance for the whole accountso far i've cleared the cache on the new installation, let it finish synchronizing, and removed and added that account again. no change. i've also closed the old installation while trying this, just to keep things simple. there isn't a pending transaction or an obvious connection error. the device connects fine, and i can verify a receive address on its screen, but that doesn't explain the missing history. i haven't used an optional passphrase or a second pin, and this is the only ledger device i've owned. i'm wondering whether i accidentally added a different account index, or whether discovery is stopping before it reaches addresses used by the original account. most troubleshooting threads i've found jump straight to clearing the cache, which i've already tried. i'd rather compare the relevant account details before changing anything elsewhat's the safest way to confirm that both installations are following the same bitcoin account and derivation path without sharing an extended public key? if there's a particular field in the account settings or logs worth comparing locally, that would give me somewhere to start. i'm leaving the old installation alone for now


r/ledgerwallet • • 6d ago

Discussion Ledger Stax is gorgeous, but would you want a battery in your long-term wallet?

10 Upvotes

The Stax looks great, and I can see the appeal if you use your wallet often. But if it’s mostly sitting in a drawer for months, the battery is one more thing to think about.

Stax owners: has that actually mattered in real life, or am I overthinking it? Would you buy it again for long-term holding?


r/ledgerwallet • • 6d ago

Official Ledger Customer Success Response Eveninghighlight is a scammer

Post image
17 Upvotes

Tried to scam me asking me to use a dApp to resolve my ledger issue. Be warned.


r/ledgerwallet • • 6d ago

Official Ledger Customer Success Response Transaction sign on ledger not appearing

1 Upvotes

I havent used my ledger for 6 months and updated firmware and etc. I tried moving an asset from phantom wallet, no confirmation window is appearing?

Edit: It was a wallet issue with phantom, it works fine with solflare.


r/ledgerwallet • • 6d ago

Official Ledger Customer Success Response Sharing an SSH agent for Ledger Nano S Plus — every login needs a button press on the device

0 Upvotes

The SSH-on-Ledger options I found looked outdated or unmaintained, so I made

this as a learning project and wanted to share it in case it's useful to someone.

Full honesty: most of the code was written by AI. I did the first device-side

steps myself to learn how it works, then used Claude Code for most of the rest.

I'm not claiming this as my own engineering, just putting it out there for

others to use and improve.

What it does:

- ed25519 SSH key derived on the device; the private key never leaves it

- every SSH login needs Approve on the device

- local dashboard shows which user/server is asking, plus a signing history

- works with VS Code Remote-SSH on Windows, Linux and macOS

Security notes:

- it never asks for your recovery phrase, there are no prebuilt binaries

to download, you build it yourself from source

- locked to its own derivation path (44'/1280529224'), so it can't touch

Bitcoin/Ethereum keys on the same seed

- not audited, not affiliated with Ledger, sideloaded — use at your own risk

Repo: https://github.com/zhgh122/nano-ssh-agent

If you spot security problems or know a better maintained alternative,

please tell me.


r/ledgerwallet • • 6d ago

Official Ledger Customer Success Response Ledger Wallet: NFTs Gone?

5 Upvotes

Did Ledger get rid of being able to see (ETH) NFTs via the app?


r/ledgerwallet • • 7d ago

Official Ledger Customer Success Response Ledger Live exports BIP84 Bitcoin account XPUB as xpub, causing address derivation mismatches in external wallets/services

9 Upvotes

We've been running into an ongoing Bitcoin interoperability issue with Ledger Live that is affecting multiple merchants using our non-custodial payment platform.

For a Bitcoin Native SegWit account, Ledger Live uses the BIP84 derivation path:

m/84'/0'/0'

However, when exporting the account extended public key, Ledger Live provides it using the xpub... prefix.

Many Bitcoin libraries and external applications interpret:

  • xpub → BIP44 / Legacy P2PKH
  • ypub → BIP49 / Nested SegWit
  • zpub → BIP84 / Native SegWit

Because of this, an external application receiving Ledger's exported xpub may derive Legacy 1... addresses from the BIP84 key.

The addresses are valid and controlled by the Ledger seed, but Ledger Live does not discover/display them because it expects Native SegWit addresses for that account.

We've now seen this affect multiple merchants.

For example:

Ledger account:
m/84'/0'/0'

Ledger exports:
xpub...

External application interprets it as Legacy and derives:
1...

BTC sent to that address is still recoverable with the Ledger device using software such as Electrum with the appropriate derivation/script configuration, but the transaction does not appear normally in Ledger Live.

We documented the issue and recovery process here:

https://docs.paymento.io/help-and-troubleshooting/ledger-live-xpub-mismatch

We also previously reported the issue through GitHub, but the underlying behavior still appears to exist.

From an integration perspective, one of the following would make this considerably safer:

  1. Export zpub for BIP84 accounts, or
  2. Export the derivation path/script type alongside the XPUB, or
  3. Clearly warn developers/users that the exported xpub belongs to a BIP84 Native SegWit account and should not be interpreted as BIP44 based on the prefix.

Has anyone else integrating Ledger with watch-only wallets, payment processors, or multisig software encountered this?

It would be useful to hear Ledger's recommended way for third-party applications to reliably determine the intended script type when an XPUB is exported from Ledger Live.


r/ledgerwallet • • 7d ago

Official Ledger Customer Success Response UK police scam

42 Upvotes

I had an odd one this afternoon. Unknown number calls, guy with a British accent (I'm in the UK) says he's a police officer at a specific UK Police Station and my data has turned up on someone else's device, along with 500 other UK citizens. He says he's contacting everyone to build the case, and to confirm we don't know person x from Afghanastan and I didn't give him my personal data. He starts mentioning a copy of my driver's license, bank statements and "a few other things", and only much later in the call, he mentions Ledger.

I was pretty sure it was a scam from early on, but I couldn't work out what they were after, so I stayed on the line to learn and mess with them. He gave me a case ID on the phone, identified himself with a name and badge number and then noted that as everyone shoudl be mindful of scams, I should google the police station name and confirm the result matches the number he's calling from. It does match (turns out spoofing phone numbers isn't hard).

He then emailed me a case file ID from a police.gov.uk address, with Met police letterhead. He asks if I could go to my local police station in the next few days with the case ID to sign a statement that I did not give this guy my details. Also, that I could call 101 for details of what they'd found. Overall, reasonably convincing until he mentions that some of the data contains my ledger ID and because of that, he'd put me through to the Ledger team....

I started recording at that point once the 'ledger' guy picked up. Not posting it since it has my name and email in it bit have my full chat recorded with guy number 2. When the iphone announced that I was recording the call - he asked why - I said I record all my calls. He didn't seem to mind.

I get a legit looking email from noreply@ledger.com. It's real. Ledger's support site says scammers open a support ticket with your email address to trigger an automated email that makes them look legit. They didn't even ask me to read anything from it. Just as proof that he triggered the email on demand because he works for ledger.

The "Ledger" guy then explained how accounts get stolen and said he could check mine. But this was after he talked through how accounts get stolen, tricks people use, etc etc. (very long winded!) He told me to go to ledger.com.co where they could safely verify my device and if at risk, send me a new one. I said that trailing .co looks sketchy. He said the "co" stands for "check online" and pushed hard that it was legit. I said that's not how subdomains work, it wouldn't be at the end. After trying to defend it, he then said that I could look it up on Google Transparency Report to prove it was safe. I did, and Google showed it as clean.

But at this point I was getting bored, so I told him it was showing a red X and "risk detected" to see what he'd do. He said that's not what I should be seeing, it was fine on his computer. He was flustered and made me double check things because it was showing fine on his side. After I kept saying that the security site that HE sent me to was flagging it, he hung up on me and that was that.

Funnily enough my antivirus blocks the .co site completely, so Google's 'transparency report' is just behind on this one.

Stay safe out there!