Ledger
My 24 phrase password is compromised I want to save my staked SOL any ideas the hacker has started the unstaking process
My 24 phrase password is compromised I want to save my staked SOL any ideas the hacker has started the unstaking process
Trying to work out if the nicer screen/UI really makes a difference once you’ve been using it for a while.
If you were buying a Ledger today, would you pay extra for that, or just get the simpler model? What actually made the difference for you?
Disclosure: I have a commercial interest in hardware-wallet research. No link here — just looking for real user experiences.
F. ing scammers…
I like keeping most of my crypto in self-custody, but the second you want to spend it, things get a bit annoying. Move it somewhere, wait, then spend. Would be nice if you could keep your crypto in your own wallet and still use it for normal everyday purchases.
Anyone here doing this with their Ledger?
I tried to use the NFC feature today with the Security Key app for the first time in a while and it seems to not work at all?
Made sure to uninstall and reinstall the app since I know it doesn't auto update. It's on v1.7.6 now
The phone plays the "NFC" sound and keeps trying to read but nothing happens on the wallet screen.
https://demo.yubico.com/ doesn't register anything
Stax, firmware up to date. Android 17, July security update
Any ideas? Is it working for you?
EDIT: Also if I connect with a cable, I'm randomly (not always) getting "Your security key requires a PIN" prompts with a text input field on the phone which doesn't make much sense and it also doesn't seem to work...
Android issue maybe? Rebooted both devices but no luck, so just looking for info if it's working for others
Version 4.15 of the Wallet app on Windows. Had Sync enabled for a while with no issues.
After Ledger Wallet app updated from v4.10 to v4.15, it suddenly started saying the wallet isn't synced. Seems like it keeps forgetting that it was already synced. It keeps trying to guide me from scratch and shows multiple banners to enable Sync that aren't dismissable (thanks Ledger)
I've already re-done the sync setup earlier (removed PC via phone, re-added PC via QR, re-synced, everything went correctly and the PC appeared on the sync list on the phone app), but it already "forgot" about it after the app was restarted.
Please fix this. Or if you're gonna break a feature at least let people dismiss those popups. Your app is already a UX nightmare.
Now its seems to be honest suggestion from zachxbt about hardware wallets
"Much better to have a separate iphone with its only purpose being to use as your hardware wallet"
I tried to look for the answer on this subreddit before posting myself. Many posts on here are saying that changelly, as well as others have frozen their funds for weeks or even longer. Is this still a known issue today? And if changelly isn't the right way to go about this, what is? It is a large amount i'm trying to swap, so I don't want to get ripped off on fees and I prefer no kyc. Thanks in advance!
Looking at buying a Ledger in the wake of the COLDCARD fiasco and am curious about how to verify EAL certifications. I know that it's done by 3rd parties, but assume you're now a paranoid hardware wallet shopper. How do you know that the EAL6+ certification is legitimate? With most certifications, you can go to the certifying authority and enter the name of a person or product to verify. Is there any way to do that in this situation or is it yet another kind of "trust me bro" that just sounds highly respectable?
I’ve been reading up on hardware wallets lately, and honestly, the part that gets me isn’t picking a brand — it’s all the stuff that can go wrong around it.
For people who ended up getting one, what was the thing that almost made you not buy it?
Was it the setup, recovery, trusting the company, using it with a phone, price, or just feeling like it was more hassle than it was worth?
And for anyone who decided not to get one, what made you stick with your current setup?
Genuinely curious where people get stuck before they buy.
Disclosure: I’m researching hardware-wallet buying decisions and have an interest in this product category. I’m not posting a link or asking anyone to buy anything.
I feel like the nano s plus used to hold a ton of apps now I can barely fit 15 on them. I just recently had to remove four just to do simple wallet updates. Are these updates getting uncessarily bloated ?
So I basically purchased a ledger from someone and it was sealed brand new, should I be worried in case of any bugs or can he somehow access it before I start using it?
I have set up it up already with seed
I’m looking to convert my Ethereum into Bitcoin and would like to understand the best method, as I’ve never done this before.
Why is the recovery card bundle of 3 cards not available on the official Ledger store on Amazon?
Given the recent Trezor customer data leak and Ledger’s twice customer data leak I was wondering if Ledger is planning any strategies such as Trezor is with its anonymous shipping scheme?
I was one of the customers affected by Ledger’s 2020 customer data leak.
Here are the facts, because I think people have forgotten how serious this breach actually was.
Ledger says its e-commerce/marketing database was exploited on June 25, 2020. Ledger was notified of the breach on July 14, 2020.
Then, on December 20, 2020, the stolen database was publicly dumped online.
The full scope turned out to be much worse than initially reported: around 272,000 customer records containing names, postal addresses and phone numbers, plus more than 1 million email addresses.
This wasn't just an email leak.
It created a database identifying people as crypto/hardware-wallet owners and connecting many of them to their real names, phone numbers and physical home addresses.
And unlike a password, you cannot simply reset your home address after it has been copied and distributed.
In 2020, much of the discussion was about phishing.
Six years later, the physical-security implications look much less theoretical.
In early July 2026, French Interior Minister Laurent Nuñez said authorities had already recorded 77 crypto-related cases involving kidnapping, unlawful detention, extortion or attempted crimes since the beginning of 2026.
According to Chainalysis:
In January 2025, Ledger co-founder David Balland and his partner were kidnapped from their home in France for a crypto ransom. Balland's hand was mutilated during the kidnapping.
In another French crypto kidnapping in May 2025, the father of a crypto entrepreneur was abducted, bound, beaten and held for more than two days. His kidnappers eventually cut off part of his finger while trying to obtain a ransom.
French prosecutors said in April 2026 that more than 135 crypto-related kidnapping/extortion cases had been recorded since 2023, and described evidence of structured criminal networks. Two separate victims in 2025 had fingers cut off during ransom attacks.
The point is that violent attacks against identified crypto holders are real. Once someone's identity and home address become permanently associated with cryptocurrency ownership, the consequences of a data breach are fundamentally different from somebody leaking a normal retail mailing list.
So I wanted to know: What did Ledger actually change after 2020?
To Ledger's credit, they did change some things.
Ledger says customer order data is moved into a more restricted/segregated environment after three months. They reassessed third-party providers, introduced data-access/deletion requests, and say they now use encryption, role-based access controls, 2FA, security testing and audits.
But then I read Ledger's current 2026 Privacy Policy.
Ledger still collects:
And Ledger says:
“We keep your data for 10 years to comply with our legal obligations. Your data is archived 3 months after completion of the order.”
That deserves an explanation.
Which of those fields are actually legally required for ten years?
Does Ledger genuinely need to retain a customer's phone number and shipping address for ten years?
If not, are those fields deleted independently of the accounting information that actually has to be retained?
And there is another uncomfortable detail.
In January 2026, Ledger customers were affected by another data-security incident — this time through Ledger's e-commerce partner Global-e. Unauthorized access exposed customer order-related personal data including names/contact information and order details.
So six years after Ledger promised to aggressively minimize third-party exposure, customer information was again exposed through an e-commerce partner.
I'm not interested in hearing that private keys and seed phrases weren't leaked. I know that.
This is about physical security.
Ledger sold people a product whose entire purpose was protecting valuable assets, while a database connected the buyers of those products to their identities and homes.
For customers affected in 2020, that information cannot be recalled.
It may circulate forever.
So these are the questions I would genuinely like Ledger to answer:
1. Exactly which customer fields are retained for ten years today?
2. Are shipping addresses and telephone numbers actually retained for the full ten years, or are they deleted earlier?
3. If I request deletion today, exactly what information about my historical purchase will Ledger still retain?
4. Which third parties currently receive customers' names, phone numbers and physical addresses, and how quickly are those parties contractually required to delete them?
5. After the Global-e incident in January 2026, what specifically changed in Ledger's third-party data-handling requirements?
6. Why doesn't Ledger offer an anonymous/privacy-preserving direct delivery option by default?
7. And what, if anything, does Ledger offer the people whose home addresses it already allowed to become permanently public in 2020?
I don't expect Ledger to somehow erase a database that criminals may already have copied.
But I do expect a company whose entire brand is built around security to treat leaking a crypto owner's physical address as something vastly more serious than an ordinary e-commerce privacy incident.
Because today we know what physical attacks against crypto holders can actually look like.
I would really like someone from Ledger to give concrete answers rather than “your private keys were not affected.”
Can anyone tell me why the ICON (ICX) app is available for the Nano S and X devices but not for the Gen 5? When I go to install it, it doesn't even show up.