Costs, licensing, consumer protection Privacy, self-custody, censorship resistance

Ledger Flex

A plan byLedger

4.5/5 4.4/5 · Data verified on

Ledger is the world's most popular hardware wallet maker: cold-storage devices with a certified secure element (EAL5+/EAL6+) where private keys never leave the chip. The range spans the Nano S Plus (€49), the Bluetooth Nano X (€99), the E Ink touchscreen Nano Gen5 with NFC (€179), up to Flex (€249) and Stax (€399), all managed through the Ledger Wallet app (formerly Ledger Live), which claims 15,000+ assets across 100+ blockchains. A contentious point for the cypherpunk community: firmware and secure element are closed-source, and in 2023 the optional Ledger Recover service raised concerns about seed extraction.

Flex

Price
€249

What's included

  • 2.8" E Ink touchscreen (Gorilla Glass)
  • Bluetooth + NFC
  • Battery up to ~10 hours of use
Self-custody
Custody
Partly open-source
Source code
100+
Chains
€49
Price
75
Transparency: High
75/100 · see methodology
75
Data exposure: High
75/100 · lower is better for sovereignty · methodology

Data & conditions

Fund custody Self-custody (funds in your control)
Type Hardware (cold storage)
Source code Partly open-source
Recovery Seed phrase 24 parole (BIP-39); opz. Ledger Recover (Shamir)
Bitcoin-only No
Supported chains Bitcoin, Ethereum, Solana, Polkadot, Cardano, Cosmos
Price €49
Secure element Yes
Air-gapped No
Connectivity USB-C, Bluetooth, NFC
Companion app Ledger Wallet (ex Ledger Live)
Built-in swap Yes
Built-in staking Yes
Built-in fiat on-ramp Yes
Security audits ANSSI (CSPN), Donjon (internal red team)
Segment B2C
MiCA / License status Nessuna (hardware wallet self-custody)

Strengths

  • Certified secure element (EAL5+/EAL6+); support for thousands of assets; range from €49 to €399; mature Ledger Wallet app.
  • Self-custody: funds stay in your wallet — the platform cannot touch them.
  • No KYC: usable without identity verification.
  • Self-hostable: you can run your own instance or node.
  • Public security audits.

Weaknesses

  • Closed-source firmware and secure element; Ledger Recover controversy (2023); USB/Bluetooth connection, not air-gapped.
  • No notable sovereignty drawback documented.

Verdict

S A ★ 4.5/5 ★ 4.4/5

Score 4.5/5, outstanding profile. In its favour: certified secure element (EAL5+/EAL6+); support for thousands of assets; range from €49 to €399; mature Ledger Wallet app. The trade-off to weigh: closed-source firmware and secure element; Ledger Recover controversy (2023); USB/Bluetooth connection, not air-gapped.

On the Sovereignty lens the score is 4.4/5 (very strong): the strength is fund control (5.0/5), while trustless / auditability (3.8/5) is the weak link.

Privacy & anonymity 30% 4.3
Fund control 20% 5.0
Censorship resistance 20% 4.8
Trustless / auditability 20% 3.8

Promp's editorial rating based on real fees and net annual cost. Promp reviews third-party products independently.

"Sovereignty" rating: score computed on privacy/anonymity (30%), fund control (20%), censorship resistance (20%), trustless/auditability (20%) and costs (10%). Same data, different weights.

Reputation

What happened to people who used Ledger, and what users say. External signals: they do not feed the promp.it rating.

Incidents & regulatory actions

Notable incidents

Documented events with consequences still open. Each entry carries a source and a date.

  1. Data breach Severe ✓ resolved

    New customer data leak via partner Global-e

    Unauthorised access to the cloud systems of Global-e, a third-party provider acting as merchant of record for part of the international orders on Ledger.com, exposed Ledger customers' names and contact details. No payment data, credentials, seed phrases or balances were involved: Ledger states its own systems, hardware and software were not breached. The number of affected customers was not disclosed. Ledger is not the only brand affected.

    ↗ source
  2. Hack / funds theft Severe $484K ✓ resolved

    Supply-chain attack: Ledger Connect Kit library compromised, wallets drained on dApps

    A former employee's NPM account was phished despite 2FA: the attacker published three versions of Ledger Connect Kit carrying a drainer, hitting dApps that loaded the library for about five hours. Root cause stated by Ledger: access to external tools was not automatically revoked at offboarding. Ledger committed to reimbursing all victims, including non-customers. The $484,000 figure is CoinDesk's estimate: the official technical report gives no total.

    ↗ source
  3. Data breach Severe ✓ resolved

    E-commerce database breach: about 1 million emails and 272,000 physical addresses leaked

    Unauthorised access via an API key on 25 June 2020, found on 14 July through the bug bounty and disclosed on 29 July. In December 2020 the dump was published on a hacking forum: about 272,000 records with name, postal address and phone. Email and SMS phishing campaigns followed, along with physical-safety concerns since shipping addresses were exposed. No payment data, passwords, seed phrases or funds were compromised: the device itself was not breached. Ledger hired a CISO and expanded its bug bounty and continuous testing.

    ↗ source
  4. Fine Moderate ✓ resolved

    CNIL fine of EUR 750,000 over the 2020 data breaches

    France's data protection authority fined Ledger for GDPR breaches tied to the 2020 data breaches: inadequate security, retaining data longer than necessary and insufficient transparency on its use. CNIL did not publish the decision and the amount surfaced through the press: the date shown is the date of the report, not necessarily of the ruling. Separately, around 50 victims brought civil claims in Paris.

    ↗ source
  5. Class action Moderate ● open

    US class action over the 2020 data breach, still open

    Filed in the Northern District of California on behalf of over 270,000 customers, alleging negligence and downplaying the breach's scope. Dismissed in November 2021 for lack of jurisdiction, it was reversed on appeal by the Ninth Circuit on 1 December 2022, which found California jurisdiction based on about 70,000 wallets sold in the state. The case appears still pending and no settlement is on record.

    ↗ source

verified on

Public reviews

4.6/5 50,649 reviews
  • Google Play ↗ 4.5/5 ~ 35,600 reviews

    Count rounded by Google Play (35.6K). It refers to the Ledger Live app, not to the device.

  • App Store ↗ 4.8/5 15,049 reviews

    US storefront for Ledger Live. App Store scores vary by country: the Italian one was not verified. Trustpilot is not included because the page blocks automated reading.

Weighted average across 2 public review platforms (50,649 reviews in total), weighted by volume. This is not our rating: it is those platforms’ average.

Community signal

not verified by us

Public opinions collected from third parties, not verified by us. Online reviews can be manipulated: read them as a hint, not as data. The promp.it verdict remains the one above, based solely on official documents.

Mixed negativepositive
  • 45 mentions analysed
  • last 6 months
  • Reddit
  • verified on

What users praise

  • The device itself has never been hacked: the leaks concerned commercial data, not private keys
  • Seen as solid by long-time users, including for large holdings
  • Ledger support is visibly active and responsive on public threads
  • Good experience replacing and upgrading older devices

What users criticise

  • Ongoing phishing and scams, including paper letters with QR codes, seen as a direct consequence of the leaks
  • The January 2026 Global-e leak reopened the 2020 wound and eroded trust
  • Closed-source firmware and the Ledger Recover hangover: you must trust the company rather than verify the code
  • Blind signing flagged as the real weak link: the device screen is useless if you cannot decode the transaction
  • Updates breaking features, battery and connectivity issues

The service’s own official accounts are excluded from the count. Sample collected on Reddit only (r/ledgerwallet, r/CryptoCurrency, r/Bitcoin), reading 5 threads and their top comments directly, January-July 2026 window. Comments from Ledger staff or moderation are excluded. X and dedicated forums were not analysed. The sample leans towards r/ledgerwallet, the official product subreddit and therefore likely more favourable: treat as indicative, not statistical.

Voices from the community

  • Everyone who buys hardware wallets gets their info leaked immediately. I was never targeted for crypto scams until I bought one: they started before my device even shipped.
    Reddit ↗ critical Distrust of how purchase data is handled
  • Ledger has never been hacked. Their database of customer info has. But so have other industries including government and the credit bureaus themselves. People are their own worst enemy when it comes to self custody: they will forever blame the wallet.
    Reddit ↗ positive Data breach is not device security
  • The hardware itself is solid, but the weak point is always the interaction layer, blind signing. If you are signing transactions you can't decode, the Ledger screen is just a fancy way to approve your own draining.
    Reddit ↗ neutral Blind signing as the real weak link

Every quote links to its original source: check for yourself, don’t trust the summary.

FAQ

How much does a Ledger cost?

The entry-level Nano S Plus costs €49. The Bluetooth Nano X €99, the E Ink touchscreen Nano Gen5 with NFC €179, the Flex €249 and the flagship Stax €399 (official shop prices, July 2026).

Is Ledger open source?

Only partly: the apps and part of the software stack are public, but the firmware and the secure element are closed-source. That's why we classify it as partially open-source.

Can private keys ever leave a Ledger device?

Under normal use no: they stay inside the secure element. The optional Ledger Recover service, introduced in 2023 and off by default, can export an encrypted, split version of the seed to third-party providers, which is what drew criticism.

Sources

Update history

  1. reputazione Not affected by the 30 Jul 2026 Coldcard exploit: Ledger stated funds are safe (different RNG design). Note: Ledger's Donjon research team is the same one that in June 2026 found and responsibly disclosed the lab vulnerabilities in Trezor Safe devices.

🔔 Notify me of changes

← All Ledger plans