Ledger
Self-custody hardware signers with human-approved transactions.
ledger.com
- Zero KYC
- FR
- Evidence and facts →
Self-custody hardware signers with human-approved transactions.
Evidence and facts
Evidence and facts
resolved · critical · since 2023-12-14
A phished former employee's NPMJS access was used to publish malicious Ledger Connect Kit versions 1.1.5-1.1.7. DApps dynamically loaded the package and users who approved malicious EVM transactions suffered asset drains. Ledger's report says the attacker did not access Ledger infrastructure, code repositories or the DApps; this was not a compromise of hardware-wallet private-key or recovery-phrase storage. Ledger estimated active draining lasted less than two hours and complete resolution took about five hours. Ledger Security Incident Report (2023-12-20)
resolved · high · since 2020-06-25
Initial 2020-07-29 disclosure: approximately 1 million email addresses and, within that population, a subset of approximately 9,500 customers with detailed contact/order data were exposed. Separately, Ledger's 2020-12-21 update said the public dump showed approximately 272,000 detailed records. The initial disclosure excluded payment information/passwords and Ledger stated there was no hardware-wallet, Ledger Live or crypto-asset impact; leaked contact data created continuing phishing and physical-targeting risk. Ledger initial disclosure (2020-07-29), Ledger later public-dump update (2020-12-21)
Specs
Review analysis, source material, related services, and history
Spend controls and data exposure
Current v1 tooling supports read-only agent actions and transaction preparation, but every signing step requires affirmative physical confirmation. This is human-approved execution, not unattended autonomy; Ledger labels bounded autonomy and policy features as coming soon.
The signer remains self-custodial, but Ledger Wallet and integrated third parties may process equipment IDs, wallet addresses, on-chain/transaction data and provider-required identity data as described in the privacy policy.
- 1Agent prepares or queries
- 2Ledger Wallet CLI
- 3Ledger signer trusted display
- 4Human physical approval
- 5Blockchain
About
Ledger sells self-custody hardware signers and provides the Ledger Wallet desktop/mobile application. Private keys remain under user control on the signer; buying, selling, swapping and some staking functions route through separate providers with their own terms, fees, availability and KYC/KYT rules.
Corporate identity
Registry-sourced, not audited. The facts below come from cited web research rather than a direct registry query. Each claim links its own source.
- LEGAL ENTITY
- Ledger SASsource ↗
- REGISTRATION NO.
- 529 991 119source ↗
- INCORPORATED IN
- Francesource ↗
- REGISTERED ADDRESS
- 106 rue du Temple, 75003 Paris, Francesource ↗
Frequently Asked Questions
Is identity verification required?
No identity verification is recorded for typical use. A standard hardware order requires contact, billing/shipping and payment/order data, and is screened for fraud and sanctions. The current sales terms do not state a routine identity-document requirement, but Global-e may request additional verification. Buy, sell, swap and similar Ledger Wallet integrations are third-party services and may apply KYC/KYT.
Which payment methods are accepted?
Accepted payment methods: BTC, ETH, BNB, XRP, SOL, TRX.
Where is it available?
Recorded availability: GLOBAL.
Is the operator based in a Five Eyes country?
No. The recorded jurisdiction is FR, which is not a Five Eyes country. This is jurisdiction context and does not by itself establish that a service is safer or less safe.
How are identity, operator, and evidence fields reported?
Identity exposure is level 2 of 4. A hosted operator is recorded. Jurisdiction is shown as context, not a safety verdict. Source coverage is verified evidence, last reviewed 2026-08-26, and recorded risk is caution.
Which payment networks are supported?
Accepted networks: BTC, ETH, BNB, XRP, SOL, TRX.
Sources and history
Terms and privacy policy
No changes to the documents we watch since we started checking on 26 Aug 2026. Last checked 26 Aug 2026.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.