Ledger Hardware Wallet Review 2026 - Is It Still Worth Buying?
A full, independent review of the Ledger hardware wallet range - how the secure element actually protects you, what the 2020 breach and Ledger Recover really changed, and who should buy which model.
Ledger is the default answer to "how do I store crypto safely," which is exactly why it deserves a sceptical review rather than a cheerful one. The company has shipped millions of devices, leaked its own customer database, launched a key-backup product that half its user base hated, and survived a supply-chain attack on its own JavaScript library. It is still, for most people, the right purchase.
This review covers the whole range - Nano S Plus, Nano X, Flex and Stax - what the hardware genuinely protects you from, what it does not, and the three situations where you should buy something else.
What a Ledger actually does#
Your crypto is not "on" the device. Coins live on their blockchains; what you own is the private key that authorises moving them. A Ledger generates that key inside a secure element, stores it there, and refuses to export it. When you want to send funds, the unsigned transaction travels into the chip, gets signed inside it, and only the signature comes back out.
That is the whole security model, and it is why a hardware wallet survives a fully compromised laptop. Malware can show you a fake balance, swap an address in your clipboard, or ask you to sign something horrible - but it cannot extract the key, and it cannot forge your button press. Which is also the first honest warning of this review: the device protects your key, not your judgement. If you approve a malicious transaction on the device screen, the Ledger signs it obediently. See Ledger scams and phishing for how people actually lose money.
The hardware: what is inside#
Every current Ledger pairs a general-purpose microcontroller (handles USB, screen, the boring stuff) with a secure element - the same category of tamper-resistant chip used in passports and bank cards, from the ST33 family, certified to Common Criteria EAL5+ on the Nano line and EAL6+ on the newer touchscreen models. The two chips run Ledger's own operating system, BOLOS, which isolates each coin app so a buggy Dogecoin app cannot reach into your Bitcoin keys.
Ledger also runs an in-house attack team, Donjon, that publicly breaks its own products and competitors'. That is a genuine differentiator: very few wallet vendors fund people whose job is to embarrass them.
The uncomfortable trade-off: BOLOS is closed source. The secure element vendor's NDA is the stated reason. Ledger Live and the individual coin apps are open, but the firmware core is not independently auditable. If that is a dealbreaker for you, it is a legitimate one, and Trezor is the honest alternative.
The range, compared#
| Model | Screen | Connectivity | Approx. price | Best for |
|---|---|---|---|---|
| Nano S Plus | Small mono OLED | USB-C only | ~$79 | Almost everyone. Buy-and-hold, desktop use |
| Nano X | Small mono OLED | USB-C + Bluetooth, battery | ~$149 | People who manage crypto from a phone |
| Flex | 2.8" E Ink touchscreen | USB-C + Bluetooth, Qi charging | ~$249 | Frequent DeFi users who want readable transactions |
| Stax | 3.7" curved E Ink touchscreen | USB-C + Bluetooth, Qi charging | ~$399 | People who want the flagship and will use the screen |
Prices move and regional VAT differs - check the current figure before you buy, and buy direct from the manufacturer, never from a marketplace reseller.
Security is identical across the range. There is no "more secure" Ledger. You are paying for screen size, Bluetooth and battery, nothing else. Anyone telling you the Stax protects your coins better than a Nano S Plus is selling something.
Where the bigger screen genuinely matters#
The one real argument for Flex or Stax is clear signing. On a tiny Nano screen, a complex smart-contract interaction is displayed as a truncated hash you cannot meaningfully verify, so people fall into "blind signing" - approving data they cannot read. On the E Ink models, a well-implemented contract shows you a human-readable summary: which contract, which token, what amount, what permission.
Ledger has pushed an open standard for this (ERC-7730 clear-signing metadata), so coverage keeps improving, but it is per-contract and still incomplete. If you interact with DeFi weekly, the larger screen buys you real risk reduction. If you buy Bitcoin twice a year and never touch a dApp, it buys you nothing.
The three controversies, fairly#
The 2020 customer data breach#
In mid-2020 an attacker reached Ledger's e-commerce database. Roughly a million email addresses and around 272,000 fuller records - names, postal addresses, phone numbers - were exfiltrated and later dumped publicly. No keys or funds were touched; the wallets were never involved. What was destroyed was customer privacy, permanently, and it kicked off a phishing and physical-intimidation campaign against buyers that has never really stopped.
The practical takeaway is behavioural: buy with an address and a burner email you would not mind seeing leaked, and treat every "Ledger" email as hostile by default.
The December 2023 Connect Kit attack#
An attacker phished a former employee's npm account and published a malicious version of Ledger's Connect Kit - a JavaScript library that many third-party dApps load. For a few hours, wallet-drainer code was served to users of other people's websites. Around $600k was stolen.
Again, no device was broken. But it demolishes the "Ledger is a security company, so their software is safe" assumption, and it is a good argument for keeping a serious cold wallet away from day-to-day dApp use entirely.
Ledger Recover#
In 2023 Ledger announced an opt-in, paid service that can back up an encrypted, split copy of your seed with identity-verified custodians. The firmware update that enabled it landed on devices that had never subscribed, and the internet, reasonably, lost its mind - because for years the marketing had implied the seed could not leave the device.
The accurate position: the service is opt-in and requires your explicit consent plus ID; if you never subscribe, nothing is shared. But the episode proved the firmware can be written to export key material under some conditions, and you are trusting Ledger's signing process not to abuse that. That is the trust assumption you accept with any closed-firmware device. It was always true; 2023 just made it visible.
Ledger Live: good, with a tax#
Ledger Live is the companion app: portfolio, install coin apps, send and receive, stake, buy and swap through integrated third parties. It is genuinely one of the better wallet apps - clean, fast enough, and it does not nag much.
Two caveats. Buy/swap partners charge visibly worse rates than a decent exchange, so use them for convenience, not for price. And you are not obliged to use Ledger Live at all: the device works with MetaMask, Rabby, Sparrow, Electrum and most serious wallets, which is the setup we prefer for anything beyond simple holding.
What we like#
- The right chip. A real certified secure element, not a general-purpose MCU with a nice case.
- Breadth. Thousands of assets across dozens of chains - see supported coins - including chains most competitors skip.
- Longevity. Devices from many years ago still get firmware. That matters for a product you hope to ignore for a decade.
- It is a BIP39 wallet. Your 24 words are a standard. If Ledger vanished tomorrow you would restore into any compatible wallet. You are not locked in.
- Donjon. Public, adversarial, in-house security research.
What we do not like#
- Closed firmware. Unavoidable given the SE vendor NDA, still a real cost.
- Blind signing on the Nano screens. The devices most people buy are the ones least able to show you what you are approving.
- A privacy track record that is genuinely bad. One leak of home addresses for crypto holders is one too many.
- Ledger Live upsell. Buy, swap, and Recover prompts in a security tool are noise you have to learn to ignore.
Who should buy something else#
- You need auditable, open firmware. Buy a Trezor Safe or a Coldcard.
- You are Bitcoin-only and want a specialist. Coldcard or Blockstream Jade fit better.
- You hold less than a few hundred dollars. A reputable mobile wallet with a written-down seed is fine. A $79 device to guard $150 is not a good trade - but revisit that the moment the number grows.
The verdict#
Buy the Nano S Plus unless you have a specific reason not to. It is the cheapest way to move your keys off an internet-connected machine, which is the single largest security upgrade available to a normal crypto holder. Step up to the Flex only if you sign contract interactions often enough that a readable screen matters. The Stax is a nice object; it is not a security upgrade.
And understand what you are actually buying: not immunity, but a hard boundary between your keys and everything that goes wrong on your computer. Your remaining job - not typing your 24 words into a website, and reading the device screen before you press both buttons - is still yours.
Rating: 4.4 / 5. Excellent hardware and ecosystem, held back by closed firmware and a company that keeps testing its users' trust.
FAQ#
Is a Ledger wallet worth it?#
Yes, if you hold more crypto than you would be relaxed about losing to a laptop infection - realistically anything from a few hundred dollars up. The device removes the single most common failure mode, which is a private key sitting on an internet-connected machine.
Can a Ledger be hacked?#
There is no public case of funds being stolen by breaking a Ledger's secure element remotely. Every large Ledger-adjacent loss has come from phishing, malicious transaction approvals, or software supply-chain attacks - not from the chip. The device is the strong link; the human is the weak one.
What happens to my crypto if Ledger goes out of business?#
Nothing. Your wallet is derived from a standard BIP39 recovery phrase, so you can restore it into Trezor, Sparrow, Electrum, BlueWallet or any compatible software. The company is a convenience, not a custodian.
Which Ledger model should I buy?#
Nano S Plus for most people, Nano X if you manage funds from a phone and want Bluetooth, Flex if you frequently sign smart-contract transactions and want a readable screen. All models are equally secure.
Is Ledger better than keeping crypto on an exchange?#
For anything you are not actively trading, yes. On an exchange you own a claim against a company; with a Ledger you own the asset. The trade-off is that you also own the responsibility - there is no password reset.
Disclosure. Some links on this site may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. It never changes our verdict — we say when a product is a bad fit. Vaultwise is an independent publication. We are not affiliated with, endorsed by, or sponsored by Ledger SAS, Trezor/SatoshiLabs, or any wallet manufacturer. Product names and trademarks belong to their respective owners.
Keep reading
Ledger Nano S Plus Review - The One Most People Should Buy
A full review of the Ledger Nano S Plus - identical security to the flagship at a third of the price, what the small screen costs you, and who genuinely needs to spend more.
Targets: ledger nano s plus review
What Is a Hardware Wallet? Cold Storage Explained Simply
A plain-English explanation of hardware wallets - what they store, why cold storage beats a hot wallet, what a secure element does, and when you actually need one.
Targets: what is a hardware wallet
Ledger Nano X Review - Is Bluetooth Worth the Extra Money?
A full review of the Ledger Nano X - what Bluetooth and the battery actually get you, whether the wireless connection is a security risk, and when the cheaper Nano S Plus is the smarter buy.
Targets: ledger nano x review
Get the self-custody checklist
One email a month: new scam patterns, firmware notes worth reading, and the mistakes that actually cost people money. No token shilling, ever.
Replace the form action with your own Formspree / ConvertKit / Buttondown endpoint in src/layout.mjs.