MKT
Wallet

Ledger

The best chip in hardware wallets and eighth place in our rating — because the firmware is closed and the trust model, not the silicon, is the product.

Founded
2014
Registered
France

The short answer

The hardware is the best in the category — a genuine EAL6+ secure element and the most advanced clear-signing engine we tested — and it finishes eighth for reasons that have nothing to do with the silicon. The firmware is still closed as of July 2026, published in fragments under a bespoke non-OSI licence, with the secure-element firmware under NDA by Ledger’s own developer documentation. That was an abstract objection until the recovery-service announcement, when the company confirmed the architecture can extract shards of a seed under a signed firmware update.

Key facts

Secure elementA genuine EAL6+ certified secure element — the best chip in our hardware wallet ratingas of 14 Jul 2026
Clear signing7 out of 10, the most advanced engine we tested — it shows you what you are actually approvingas of 14 Jul 2026
FirmwareClosed as of July 2026. Fragments published under a bespoke non-OSI "Source Code Accessibility License"; the secure-element firmware is under NDA per Ledger’s own docs.as of 14 Jul 2026
Architecture score5 out of 10 — excellent chip, unverifiable firmwareas of 14 Jul 2026
Company and customer-data safety2 out of 10, the lowest score on the cardas of 14 Jul 2026
Assets supported9 out of 10 — the broadest coverage in the categoryas of 14 Jul 2026
Overall positionEighth in our hardware wallet ratingas of 14 Jul 2026

Is Ledger safe? The hardware and the trust model give different answers

The device is excellent and the promise behind it cannot be checked. Ledger builds on a genuine EAL6+ certified secure element, the strongest chip in this category, and pairs it with the most advanced clear-signing engine we tested — the part that tells you what a transaction will actually do before you approve it, which is where people lose money.

What you cannot verify is the firmware. As of July 2026 it remains closed: Ledger publishes fragments of its operating system under a bespoke non-OSI "Source Code Accessibility License", and its own developer documentation states that the secure-element firmware is under NDA. The central claim of a hardware wallet — that your seed never leaves the device — therefore rests on the vendor’s word rather than on inspection.

For years that was a theoretical complaint, and the recovery-service announcement turned it concrete. In confirming how the feature would work, Ledger confirmed that the architecture permits shards of a seed to be extracted under a signed firmware update. Whether or not you want that service, the disclosure settled the question of what the device is capable of, and it is not what most owners believed.

We score architecture 5 out of 10 for exactly this: the best silicon in the rating, attached to software nobody outside the company can audit. If you trust Ledger the company, the product is superb. The entire point of a hardware wallet is not having to.

Why it scores 2 out of 10 on company and customer-data safety

This is the lowest mark on the card and the single biggest reason the market leader finishes eighth. Ledger’s customer database was breached and the exposed records included home addresses — not just names and emails. Buyers of a device that advertises holding significant wealth found their physical addresses circulating, and the consequences included threats.

The comparison in our own rating makes the severity legible. Trezor also suffered a support-portal breach, in January 2024, exposing contact details for up to 66,000 people, and an attacker emailed 41 of them asking for their recovery seed. That exposure was names and email addresses. No home addresses. Materially less dangerous, and it is why Trezor scores 6 where Ledger scores 2.

The criterion exists because a hardware wallet vendor holds an unusually sensitive customer list: by definition, everyone on it owns cryptocurrency and cares enough to buy a device. Protecting that list is part of the product, not an administrative afterthought, and no chip certification compensates for losing it.

Incident record

No recorded incidents since 2014, verified 14 Jul 2026.

In our ratings

Compared with

Our coverage of Ledger

Questions people ask

Is Ledger safe to use?

The hardware is the best in the category and the firmware cannot be independently verified, which is the whole argument. Closed firmware means the core claim — that the seed never leaves the device — rests on Ledger’s word. The recovery-service announcement confirmed the architecture can extract seed shards under a signed firmware update.

Is Ledger firmware open source?

No. As of July 2026 Ledger publishes fragments under a bespoke non-OSI "Source Code Accessibility License", and its own developer docs state the secure-element firmware is under NDA. Trezor, by contrast, publishes firmware and hardware openly with reproducible builds.

What happened in the Ledger data breach?

Customer records were exposed including home addresses, not just names and emails. People who had bought a device advertising that they hold significant cryptocurrency had their physical addresses circulated, and threats followed. It is why we score company and customer-data safety 2 out of 10.

Why does Ledger rank eighth if it has the best chip?

Because the chip is not the product — the trust model is. Architecture scores 5 out of 10 for excellent silicon attached to unverifiable firmware, and company and customer-data safety scores 2. Broad asset support and strong clear signing are not enough to offset those.

Ledger or Trezor?

Ledger has the better chip, the better clear-signing engine and far broader asset support. Trezor is fully open — firmware and hardware — with reproducible builds you can verify, and a much better record on customer data. If verifiability is why you want a hardware wallet, that points one way.

What changed

  • 27 Sept 2026 — Profile published.