Security model

What protects your crypto, and what your habits must cover

Hardware wallets eliminate the largest technical attack surface — the internet-connected device holding your keys. But they shift the risk to physical security. Understanding both sides keeps you safe.

Handled by the hardware

  • Malware on a connected computer. Keys never leave the Secure Element. A keylogger, screen scraper, or transaction hijacker on the PC cannot extract the private key — only a signed transaction emerges from the chip.
  • Address substitution by malware. The device screen shows the actual destination address. If malware swaps the address on-screen, the device screen still shows the real one. Always verify on the device.
  • Remote attacks on Ledger Wallet’s servers. No private key data is stored on Ledger Wallet’s servers. A server breach cannot drain wallets.
  • Phishing for software wallet seed phrases. The Ledger Wallet setup process never asks for a phrase via software. Only the physical device screen shows recovery phrase words during setup.
  • Identity linkage at the protocol level. No KYC, no account, no email links your identity to addresses generated by the device.

Still your responsibility

  • Physical device theft (no PIN). A stolen device with the PIN unknown provides minimal risk because of the PIN lockout. A PIN the thief already knows is a vulnerability. Never use a guessable PIN.
  • The 24-word recovery phrase. Anyone with the phrase can import your wallet on any BIP-39 compatible device. If it is found, photographed, or sent digitally, your funds are at risk regardless of the physical device.
  • Phishing for the phrase online. No website, app, or support agent legitimately needs your 24-word phrase. Any request is theft. Ledger Wallet support will never ask for it.
  • Buying from unofficial sources. Pre-tampered devices from resellers have been reported. Only buy from ledger.com or an officially listed authorised reseller.
  • Blind signing. On older devices without clear signing, you confirm a hash, not readable details. Always cross-reference Ledger Live’s display with the transaction you intended.

Threat model

The scenarios hardware wallets defend against — and the ones they don’t.

Compromised computer

Malware intercepts unsigned transactions and proposes altered ones. Defence: every transaction is signed inside the Secure Element and shown on the device screen. The computer never sees the key, only the signed output.

Supply chain attack

A tampered device shipped with pre-generated keys. Defence: buy only from ledger.com or authorised resellers; check the anti-tamper seal; verify the device generates its own phrase during first setup. A genuine device never ships with a pre-set recovery phrase.

Social engineering for the phrase

An attacker poses as Ledger Wallet support and requests the 24-word phrase to “verify” the wallet. Not a hardware defence — only your knowledge that no one ever legitimately needs this phrase protects you.

Physical theft with known PIN

Device stolen and PIN is guessable or known. Defence: use a non-trivial PIN and optionally activate a BIP-39 passphrase (25th word) that adds a separate layer the device cannot see and the thief cannot brute-force.

Five habits that stop most losses

  1. Store the 24-word recovery phrase on paper in a secure offline location. Make at least two copies in different places. Consider a metal backup for fireproofing.
  2. Never type, photograph, or digitally transmit the recovery phrase. Do not enter it on any website, software form, or chat — under any circumstances.
  3. Verify the destination address on the device screen, not on the computer screen, before every significant transaction. Trust the device; the computer can be compromised.
  4. Buy only from ledger.com or authorised resellers. Inspect the anti-tamper seal before use. If the device shows a pre-set recovery phrase, do not use it.
  5. Use a strong, non-guessable PIN. Consider enabling the BIP-39 passphrase feature (25th word) for holdings you rarely need to move.

Put these principles into practice

The setup guide covers where each habit applies during your first Ledger Wallet setup.

Open setup guide