Ledger (Flex / Stax / Nano): hardware wallets rating breakdown
The market leader finishes eighth, and not for the reason people expect. Its chip is the best in the category — a genuine EAL6+ secure element — and its clear-signing engine is the most advanced here: where a descriptor exists, a Ledger will decode a contract call into something a human can read, which is more than Trezor does. That is real, and it matters.
The market leader finishes eighth, and not for the reason people expect. Its chip is the best in the category — a genuine EAL6+ secure element — and its clear-signing engine is the most advanced here: where a descriptor exists, a Ledger will decode a contract call into something a human can read, which is more than Trezor does.
How the score is built
Each criterion is scored 0–10 and weighted. The median column is the middle score across every entry in this ranking, so a row reads as a position rather than a number.
| Criterion | What we measured | Weight | Score | Category median | Rank | Weighted gap |
|---|---|---|---|---|---|---|
| Security architecture | NO — bespoke non-OSI licence; SE firmware under NDA firmware open source · sourced · 2026-07-14 · source | 30% | 5 | 6 | 9 of 13 | -0.30 |
| Clear signing | best in class WHERE a descriptor exists; blind-sign fallback otherwise clear signing · published · 2026-07-14 · source | 15% | 7 | 6 | 3 of 13 | +0.15 |
| Recovery and seed portability | — | 15% | 8 | 8 | 4 of 13 | 0.00 |
| Company and customer-data safety | two — 2020 and 2026 customer-data leaks · sourced · 2026-07-14 · source | 10% | 2 | 7 | 13 of 13 | -0.50 |
| Connectivity and air-gap | — | 10% | 5 | 6 | 9 of 13 | -0.10 |
| Assets and networks | — | 8% | 9 | 8 | 1 of 13 | +0.08 |
| Price and true cost | — | 7% | 4 | 6 | 10 of 13 | -0.14 |
| Maintenance | — | 5% | 8 | 7 | 3 of 13 | +0.05 |
Measured 14 July 2026 · weights and method · decided by company and customer-data safety, worth -0.50 points against the median
Security architecture: 5/10
Secure element: present or not, which chip, and the actual certification level (EAL5+, EAL6+) as published by the certifying body rather than the vendor’s marketing. Then the three questions vendors like to blur into one: is the firmware open source, is the hardware design open, and are the builds REPRODUCIBLE — can you verify that the binary on your device was built from the source you just read? Audits count only when the firm is named and the report is public.
Scored 5 of 10 against a category median of 6, which places it 9th of 13 among hardware wallets on this criterion. At a 30% weight that is 0.30 points below the median contribution of the weighted total. The best score in the category is 9, the worst 2.
Clear signing: 7/10
Its own criterion, not a footnote to UX, because this is the hole the money actually leaves through. Does the device parse and display what you are signing — the ERC-20 approval amount, the swap destination, the EIP-712 payload — or does it show you a hash and ask you to trust the computer it is plugged into? Read from vendor documentation and firmware source. NOT hands-on: we have not bought these devices, and we say so rather than implying we pressed the buttons.
Scored 7 of 10 against a category median of 6, which places it 3rd of 13 among hardware wallets on this criterion. At a 15% weight that is 0.15 points above the median contribution of the weighted total. The best score in the category is 10, the worst 0.
Recovery and seed portability: 8/10
BIP39, SLIP39/Shamir, passphrase support. The decisive question: can the seed be restored into a DIFFERENT vendor’s wallet? If it cannot, that is vendor lock-in, and it loses points — the entire premise of self-custody is that you can walk away from the company that sold you the device.
Scored 8 of 10 against a category median of 8, which places it 4th of 13 among hardware wallets on this criterion. At a 15% weight that is exactly level with the median of the weighted total. The best score in the category is 9, the worst 5.
Company and customer-data safety: 2/10
Jurisdiction, ownership, and the history of customer-data leaks. This carries more weight than it looks: when the buyer list of a hardware wallet leaks, it publishes the names, home addresses and phone numbers of people known to hold crypto. That is a physical-safety event, not a privacy inconvenience, and it is scored as one.
Scored 2 of 10 against a category median of 7, which places it 13th of 13 among hardware wallets on this criterion. At a 10% weight that is 0.50 points below the median contribution of the weighted total. The best score in the category is 9, the worst 2.
Connectivity and air-gap: 5/10
Is the device fully air-gapped (QR or SD only), or does it require USB or Bluetooth? Which software wallets it interoperates with, from vendor documentation.
Scored 5 of 10 against a category median of 6, which places it 9th of 13 among hardware wallets on this criterion. At a 10% weight that is 0.10 points below the median contribution of the weighted total. The best score in the category is 10, the worst 2.
Assets and networks: 9/10
What the official support list actually contains, and — importantly — whether support is native on the device or delegated to third-party software with caveats. This is the vendor’s own claim; we mark it as such, because verifying it properly means buying the device and trying ten coins, which is Level C and which we have not done.
Scored 9 of 10 against a category median of 8, which places it 1st of 13 among hardware wallets on this criterion. At a 8% weight that is 0.08 points above the median contribution of the weighted total. The best score in the category is 9, the worst 3.
Price and true cost: 4/10
Vendor store price, plus any accessory the device genuinely needs to be usable. A cheap device that requires a paid dongle is not a cheap device.
Scored 4 of 10 against a category median of 6, which places it 10th of 13 among hardware wallets on this criterion. At a 7% weight that is 0.14 points below the median contribution of the weighted total. The best score in the category is 9, the worst 2.
Maintenance: 8/10
Firmware release cadence and how long old models keep receiving updates — counted from the public repository’s release history, not from a promise on the website.
Scored 8 of 10 against a category median of 7, which places it 3rd of 13 among hardware wallets on this criterion. At a 5% weight that is 0.05 points above the median contribution of the weighted total. The best score in the category is 9, the worst 2.
Other measurements
Its nearest neighbours in this ranking
| # | Entry | Company and customer-data safety | How it differs |
|---|---|---|---|
| 6 | Trezor Safe 3 | 6 | Ahead by 4 on company and customer-data safety. |
| 7 | OneKey Pro | 5 | Ahead by 3 on company and customer-data safety. |
| 9 | Cypherock X1 | 7 | Ahead by 5 on company and customer-data safety. |
| 10 | SafePal S1 | 6 | Ahead by 4 on company and customer-data safety. |
Incidents priced into this score
- 2020-07 — E-commerce database breach. ~272,000 customers had name, postal address and phone number publicly dumped. Produced sustained phishing, extortion emails and physical threat letters against known crypto holders. [users made whole: no] [source]
- 2023-12-14 — Ledger Connect Kit supply-chain attack: a phished ex-employee's npm account was used to publish a wallet drainer that loaded inside many dApps. Roughly $600,000 taken. Ledger reimbursed affected users. [users made whole: confirmed] [source]
- 2026-01-05 — Second customer-data exposure, via third-party e-commerce provider Global-e. Names and contact details. Number affected not disclosed. [users made whole: n/a] [source]
Questions about this score
What was the Ledger Recover controversy?
+
Ledger announced a service that could back up shards of a user's seed, and in doing so confirmed that a signed firmware update could make the seed leave the device — something many users believed was architecturally impossible. The controversy was not the service; it was the realisation of what closed firmware had always meant.