Ledger is the best-selling hardware wallet in the world and the most controversial. On capability it wins outright: several thousand assets, deep application support through Ledger Live, integration with essentially every software wallet, and a secure element with a strong physical security record.
The 2020 breach
An e-commerce database leak exposed the names, addresses and phone numbers of around 270,000 customers. The consequence was not stolen crypto but years of targeted phishing, extortion attempts and, in some reported cases, physical threats against people known to own hardware wallets. It remains the most damaging privacy failure in this industry.
Ledger Recover and what it revealed
In 2023 Ledger announced an optional service that shards an encrypted seed backup across custodians. The technical detail that alarmed users was that firmware could, with consent, export key material at all — contradicting years of messaging that the seed could never leave the secure element. The service is opt-in and requires identity verification, and the episode showed the limits of trusting a closed-firmware vendor's marketing over its architecture.
Assessing it fairly
No Ledger device has had its secure element defeated in the wild, and no user has lost funds to a firmware backdoor. If your threat model is physical attack and remote compromise, the hardware performs. If your threat model includes trusting the vendor's unverifiable claims, it does not.
Who should use it
Users who need coverage of chains no open-source device supports, and who accept closed firmware. Anyone who can meet their needs with a BitBox02, Trezor Safe or Keystone should — the security is comparable and the verifiability is better.